Cybersecurity Engineer 2

$95,900 - $159,900/Yr

Dexcom

posted 5 months ago

Full-time - Mid Level
Remote
5,001-10,000 employees
Miscellaneous Manufacturing

About the position

As a Cybersecurity Engineer 2 at Dexcom Corporation, you will play a pivotal role in ensuring the security and integrity of our innovative continuous glucose monitoring (CGM) devices. This position is part of the Product Security team, which is dedicated to safeguarding our technology and the sensitive health data it manages. You will collaborate with various cross-functional teams to integrate security practices throughout the software development lifecycle, from continuous integration and continuous deployment (CI/CD) to production. Your expertise will be crucial in driving the automation of security processes, ensuring that security measures are seamlessly integrated with application teams. In this role, you will be responsible for interpreting, prioritizing, and driving the remediation of findings from various security tools, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Interactive Application Security Testing (IAST), Software Composition Analysis (SCA), Software Bill of Materials (SBOM), and container scanning. You will also design and implement security guardrails within development processes to proactively detect and prevent vulnerabilities, ensuring that our software is developed securely. Your success in this position will be supported by your deep understanding of the OWASP Top 10 vulnerabilities and mitigation strategies, as well as your proficiency in securing cloud-based and mobile applications. You will have the opportunity to work with a variety of DevSecOps tools and will be expected to develop and manage systems for the creation, delivery, and lifecycle management of SBOMs across diverse platforms and products. This role offers a unique chance to contribute to life-changing technology while being part of a passionate team committed to improving health outcomes globally.

Responsibilities

  • Integrate security tooling across all phases of the software development lifecycle, from CI/CD to production.
  • Drive the automation of security processes, ensuring efficient and seamless integration with application teams.
  • Collaborate with application teams to interpret, prioritize, and drive remediation of findings from security tools.
  • Design and implement security guardrails within development processes to proactively detect and prevent vulnerabilities.
  • Develop and manage systems for the creation, delivery, and lifecycle management of Software Bill of Materials (SBOMs) across diverse platforms and products.

Requirements

  • Typically requires a Bachelor's degree in a technical discipline, and a minimum of 2-5 years related experience or Master's degree and 0-2 years' equivalent experience.
  • Deep understanding of the OWASP Top 10 vulnerabilities and mitigation strategies.
  • Proficiency in securing cloud-based and mobile applications, with a strong emphasis on cloud security architectures.
  • Experience writing and reviewing code in at least 1 of the following languages: Java, Scala, C# or similar.
  • Experience with DevOps practices and the secure software development lifecycle.
  • Working knowledge of compliance frameworks and regulated environments (ISO 27001, NIST 800-171, NIST 800-53, etc.).

Nice-to-haves

  • Experience with a variety of DevSecOps tools of the types mentioned above.
  • A proactive, inquisitive nature, constantly seeking out opportunities for improvement.

Benefits

  • A full and comprehensive benefits program.
  • Growth opportunities on a global scale.
  • Access to career development through in-house learning programs and/or qualified tuition reimbursement.
  • An exciting and innovative, industry-leading organization committed to our employees, customers, and the communities we serve.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service