Bertelsmannposted 24 days ago
$100,000 - $135,000/Yr
Full-time • Mid Level
Remote • New York, NY
Broadcasting and Content Providers

About the position

Penguin Random House is seeking an Application Security Engineer to join the IT Security team. This position will be responsible for advancing Secure Software Development Life Cycle (SDLC) practices and incorporating Application Security services and technologies to achieve a security-first design in all of Penguin Random House's applications. In addition, the individual will be expected to contribute to and help deliver services and projects across various aspects of information security. The individual will collaborate with developers and business stakeholders from relevant technical teams to evaluate the security architecture of new products and features through application security assessments. They will prioritize and provide guidance on mitigating identified weaknesses and vulnerabilities while working with development teams to define and promote security best practices.

Responsibilities

  • Develop and refine our core infrastructure architecture to minimize the vulnerability of essential services and reduce the impact of potential security exploits.
  • Strategize and implement application security architectures that are in line with the company's business objectives, ensuring adherence to privacy standards and compliance requirements.
  • Utilize scripting languages (Python, Ruby, Bash, etc.) to build automation tools as needed.
  • Create and deliver presentations and documentation to educate developers and operations teams on application security best practices and secure coding techniques.
  • Identify and assess threats, vulnerabilities and potential exploits through architecture design reviews, threat modeling, code reviews, SCA/SAST/DAST assessments and collaborate with developers/engineers to remediate issues.
  • Formulate and establish application security policies, standards and guidelines to support the secure development of products and services.
  • Collaborate with the DevOps team to enhance Application Security, integrating security tools into the CI/CD pipeline, including container security, SCA/SAST, DAST, IAST, and third-party vulnerability Scanning.
  • Partner with security stakeholders across the organization to assist delivery teams in conceptualizing and implementing security-focused projects and initiatives.

Requirements

  • Experience in at least one of the following areas: securing workflows in AWS and Azure, proficiency in SecDevOps and automation, familiarity with secure coding practices, or a background in application development with a desire to move into application security.
  • Bachelor's degree in computer science or a related field, supplemented by a minimum of five years of professional experience encompassing a robust technical understanding and practical involvement in secure software development, security engineering, DevOps, application penetration testing, and/or negative QA testing.
  • Proficient in effective communication, interpersonal relations, and organizational management.
  • Experience with application security tools such as SCA, SAST, DAST, Penetration testing, and Fuzzing.
  • Comprehensive knowledge of prevalent software and web application security vulnerabilities, including OWASP Top 10 and SANS/CWE Top 25.
  • Expertise in conducting security assessments for web and mobile applications based on OWASP ASVS/M-ASVS and other testing guidelines.
  • DevOps experience with building and deploying applications/infrastructure with the following technologies: GitLab/GitHub, Ansible, Jenkins, etc.
  • Advanced understanding and experience with web architectures, web applications, APIs, mobile applications, desktop applications, Unified Communications (including VoIP and SMS), and the underlying technology of cloud infrastructure.
  • Experience securing DevOps, including continuous integration, configuration management, and continuous deployment.
  • Demonstrated ability in leading code reviews, executing threat modeling, and conducting penetration tests.
  • Industry-recognized certification in security is a plus (e.g., CISSP, CISA, CISM, CRISC, CEH, etc.)

Benefits

  • Medical/Prescription drug insurance
  • Dental
  • Vision
  • Health Care/Dependent Care Flexible Spending Account
  • Health Savings Account
  • Pre-Tax and Roth 401(k)
  • Short and Long-Term Disability Insurance
  • Life/AD&D Insurance
  • Commuter Benefits
  • Student Loan Repayment Program
  • Educational Assistance
  • Generous paid time off

Job Keywords

Hard Skills
  • Ansible
  • Bash
  • Github
  • Gitlab
  • Jenkins
  • 0ZVPtXmulhC 1lN3z7xAwRy
  • 3oDruwnjGHW6 OzD74CFpYIgX
  • 5dHEAfeloUKkrX jvyITDQ3XZVcP5O
  • 5iU0 sQSGygIW7ald I74SacJng
  • 5T6 dLpgCDZch k0sRdqYmtO6Ua
  • 61fPH AWExHzmi
  • 6NCv0rlkj wov7dK
  • 6Oo7Ncd3v XRFWgintUk1Z
  • 6QCnRrf
  • 8inIAc21 DdP2ESyiNLuZ
  • 8oGJgjezQ NXTbshdP1VH
  • 97hxnZzPG 1YOo9UsPR
  • c7m utZzL56Iie8Tw cbS2FUs
  • cNswjIlLpGz MKbv8BURLQaq6
  • G3WV2wj slMrHBzp3
  • GBxNvq yhO8GktRK7qSQxf
  • gcGyXRtxa TSVivl8DRNaHgUk
  • gNFDbGzaAXRT TurylH1F9
  • iafEXeQ3PNK1 BpwbsQk8h
  • Ietbdh
  • Ihb VB1TSeQlA MYsEqXe4l8Btw
  • iqHhvcWkU02 xwL8hzslXBgO
  • JfoUR9qw XADdtnZ1hW40UHE
  • kdDIKCzbLH2wQc qlF5oe0Ok
  • KT6uSzY 2dxK0eQ 2XZWg XVZdmFOLla
  • Mdu4Yw1 JvPiUBZ7fgb
  • mrXzO q6oW2JU
  • MWkaVnAQ2yh8 KdD4u1SQ
  • N9VLFZhPEBOu S6pHCPexz
  • nafYlBqKbIQ7 8gEmQkDX
  • p3vljX W6NYmRLST3E
  • P7MRLlA pVba9DF
  • qJvXwBjUt U4B2fmrtN
  • QnKFB5SXAiDlo4 euqSj2iWaYg
  • rkQpBaMOs 6K3IRLsw
  • sbXFUaPgQh 21MtmBPVT
  • udo6v
  • yDfjNXYvs uZMB8m
  • yNuQCvFfr vSNy6A5ht
  • YrGmobD7lFEIayU ElA8G4zm0ZBCr
Build your resume with AI

A Smarter and Faster Way to Build Your Resume

Go to AI Resume Builder
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service