Qlik - Waltham, MA

posted 2 months ago

Full-time - Mid Level
Waltham, MA
10,001+ employees
Administrative and Support Services

About the position

The Application Security Engineer / Penetration Tester position at Qlik is designed for experienced penetration testers with a strong background in software engineering. In this role, you will be an integral part of our Security team, responsible for independently planning, executing, and thoroughly documenting penetration tests in accordance with industry best practices. Your expertise will be crucial in delivering the status of features and products, ensuring that security is prioritized throughout the development process. You will have the autonomy to identify vulnerabilities and provide effective solutions, making a significant impact on the overall security posture of our applications. As a champion of security best practices, you will inspire and promote software security guidelines, contributing to a culture of security awareness within the organization. Collaboration is key in this role, as you will work closely with stakeholders to assist in the design, development, and testing of features, ensuring that security considerations are at the forefront. Additionally, you will be responsible for producing comprehensive threat models for proposed features, offering valuable insights and suggesting defensive countermeasures to mitigate potential risks. Your contributions will include resolving vulnerabilities by working with third parties to replicate reported security issues and collaborating with R&D teams to develop and implement effective fixes. You will also verify results from automated vulnerability assessment tools, ensuring accurate identification of vulnerabilities while minimizing false positives. Manual penetration testing will be a significant part of your responsibilities, utilizing both manual methods and automated tools to conduct thorough security evaluations. Furthermore, you will play a vital role in coaching and training developers on best security practices, creating and delivering engaging training content as needed.

Responsibilities

  • Independently plan, execute, and document penetration tests adhering to industry best practices.
  • Promote and inspire software security best practices and guidelines.
  • Collaborate with stakeholders in the design, development, and testing of features with a focus on software security.
  • Produce comprehensive threat models for proposed features, offering insights and suggesting defensive countermeasures.
  • Work with third parties to replicate reported security vulnerabilities and collaborate with R&D teams to implement fixes.
  • Verify results from automated vulnerability assessment tools to ensure accurate identification of vulnerabilities.
  • Perform manual penetration tests using a combination of manual methods and automated tools.
  • Coach and train developers on best security practices, creating and delivering engaging training content.

Requirements

  • 3+ years of application penetration experience and software engineering skills, ideally with enterprise software/systems using languages such as C#, Java, Ruby, Go, Python, etc.
  • Proven experience in creating detailed penetration test reports tailored for both company executives and developers, including prioritization and mitigation advice.
  • Strong experience with the OWASP testing guide, showcasing proficiency in understanding and implementing industry-standard security practices.
  • Familiarity with multiple web frameworks and technologies, including JavaScript, XML, SOAP, and JSON.

Benefits

  • Genuine career progression pathways and mentoring programs
  • Culture of innovation, technology, collaboration, and openness
  • Flexible, diverse, and international work environment
  • Participation in Corporate Responsibility Employee Programs
  • Extra change the world day plus another for personal development
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service