Senior Software Security Engineer
Motorola Solutions · Vancouver, Canada
About The Role
Join our team as a Senior Software Security Engineer, where you will be responsible for analyzing software designs and implementations from a security perspective, identifying and proposing remediations to security issues throughout the software development lifecycle (SDLC). You will perform threat modeling, risk assessments, and architecture reviews, support engineering teams on detailed security requirements, and conduct security code reviews. Additionally, you will define and oversee the deployment of security testing tools, manage vulnerability findings, and establish secure coding standards. You will also support incident response processes, ensure compliance with security standards, and monitor emerging security threats.
- Analyser les conceptions et les mises en œuvre logicielles du point de vue de la sécurité, identifier et proposer des remédiations aux problèmes de sécurité tout au long du cycle de vie du développement logiciel (SDLC).
- Effectuer des modélisations de menaces, des évaluations des risques et des examens d'architecture pour identifier et atténuer les risques, et soutenir les équipes d'ingénierie sur les exigences de sécurité.
- Définir et superviser le déploiement d'outils d'analyse de composition logicielle (SCA) pour compiler des SBOMs de composants logiciels, aider à identifier les vulnérabilités connues et les violations de conformité.
- Bachelor’s degree in Computer Science, Information Security, or a related technical field
- 7+ years of experience in Security Engineering with a focus on product security and/or application security
- Familiarity with industry-standard security frameworks such as OWASP and NIST
- Significant software development experience. Experience in Go (our main backend language), Typescript/Javascript, C/C++, Python and Bash is desirable
- Strong knowledge of security principles, best practices, and industry standards, such as NIST, ISO 27001, and CIS Critical Security Controls, OWASP ASVS and Testing Guides
- Exceptional analytical and investigative skills, with hands-on experience in root cause analysis
- In-depth knowledge of Linux and Docker container-based infrastructures, including their orchestration (e.g. Kubernetes)
- Working knowledge of web-related protocols and technologies (HTTP, REST APIs, DOM, CSP), networking protocols (IP, TCP, UDP), and security protocols (TLS)
- Knowledge of current and emerging threats and techniques for exploiting security vulnerabilities
- Experience in performing threat modeling, with a good grasp of common threat vectors and frameworks
- Experience with cloud-based infrastructure (AWS, Azure, or Google Cloud), and on best practices on how to secure cloud environments
- Working knowledge of techniques, standards, and state-of-the-art authentication and authorization technologies, applied cryptography, security vulnerabilities and remediations
- Experience with security tools such as SAST, DAST, IAST, and SCA
- Experience with CI/CD pipeline, security tools integration, and secure SDLC
- Familiarity with security considerations for AI/ML systems is desirable
- Understanding of distributed systems design, implementation and operation
- Understanding of privacy threats and controls, including on how to adapt generic best practices to specific scenarios in the product by providing detailed specifications to stakeholders
- Exploit development experience, and good understanding of the necessary conditions to trigger different vulnerability types, and the maximum impact achievable
- Experience with enterprise log collection and analysis platforms (e.g., Splunk, OSQuery)
- Master's degree or equivalent experience preferred
- Security certifications are a plus, including OSCP, OSEE, SANS/GIAC, CCSP, and CISSP
- Bachelors Degree
- Excellent verbal and written communication, with the ability to translate complex security concepts to technical and non-technical stakeholders
- Ability to remain calm under pressure, especially during incidents or audits
- Experience in a high-growth technology environment or SaaS business
- Demonstrated ability to design, document, and implement new security processes
- 5+ year of experience in security Engineering
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring