S&P Global - Eufaula, AL

posted 2 months ago

Full-time - Senior
Eufaula, AL
10,001+ employees
Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services

About the position

The S&P Ratings Security team is dedicated to protecting clients and users from modern security threats. The mission of this team is to safeguard systems and data by developing innovative solutions to address significant security challenges. We are seeking a Senior Application Security Engineer/Director who will be responsible for the development and implementation of security architecture and engineering best practices across S&P Ratings technology platforms. This role will provide security engineering and architecture consultation to enhance security in S&P Ratings Applications and Services, including Generative AI applications. As a Director-level individual contributor, this position will collaborate with Security, software development, Data science/LLM, QA, and Operations teams to identify technical risks at both component and system levels. The successful candidate will evaluate critical failure points, determine technical security controls to mitigate risks, prioritize and schedule these controls in alignment with application development timelines, and work with cross-functional teams to implement necessary remediations. The role will drive the Secure SDLC roadmap, GenAI security strategy, and Cloud security architecture. It will also assist in maturing the security engineering program, develop security tooling, mentor team members, and partner closely with development teams to deliver innovative and secure applications. Key responsibilities include developing and maintaining application security and GenAI security strategies, providing architectural guidance on security best practices, performing threat modeling and secure code reviews, and assisting developers in remediating vulnerabilities. The candidate will also consult on security incident response processes and guide teams in building secure Cloud Native applications by incorporating best practices and industry standards.

Responsibilities

  • Develop, implement and maintain Application security and GenAI security strategy
  • Provide architectural guidance on best practices regarding security in software development
  • Drive and guide the specification and realization of a security architecture
  • Perform threat modeling, secure code reviews, and secure design reviews for high-risk applications
  • Perform vulnerability research and serve as a technical security/risk advisor
  • Determine testing requirements and develop strategies to automate security testing
  • Assist developers in remediating vulnerability findings
  • Coach development teams on security disciplines and provide training
  • Maintain knowledge of current and emerging technologies related to security architectural solutions
  • Develop repeatable application security patterns
  • Consult and assist with security incident response process
  • Consult on Application Penetration tests to identify and mitigate security gaps
  • Guide development and SRE teams in building secure Cloud Native applications

Requirements

  • Bachelor's degree in Computer Science or related field, or relevant work experience
  • 12 or more years of progressive related experience in Security engineering roles
  • Demonstrated subject matter expertise in Application Security, Web services security, GenAI/LLM security
  • Programming expertise in Java, Python, and Agile SDLC processes
  • Experience with threat modeling, design reviews, risk analysis, and control design
  • Experience architecting and leading security for Cloud native applications
  • In-depth knowledge of network security, authentication, and authorization
  • Advanced understanding of vulnerability exploitation chaining and remediation
  • Demonstrated expertise in product/application security architecture
  • Security audit, Vulnerability assessment, and packet analysis skills
  • Knowledge of TCP/IP stack, Encryption, TLS, DTLS, ECC, PKI/Certificates
  • Experience with Identity & Access Management: AD/LDAP

Nice-to-haves

  • Experience with AI technologies and services (e.g., OpenAI, Bedrock)
  • Expertise in the security of Gen AI models, including multi-modal models
  • Experience with automation tools associated with DevOps and CI/CD pipelines
  • Familiarity with SAST/DAST/SCA tools like Fortify, Whitesource
  • Database knowledge - Postgres, Oracle, Databricks, Snowflake
  • Familiarity with Secure SDLC frameworks such as NIST SSDF, OpenSAMM, BSIMM
  • Security Forensic analysis skills

Benefits

  • Health care coverage designed for the mind and body
  • Generous time off to keep you energized
  • Access to resources for career growth and learning
  • Competitive pay and retirement planning
  • Company-matched student loan contribution
  • Best-in-class benefits for families
  • Retail discounts and referral incentive awards
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service