Job Description

Summary

SingleStore is a cutting edge business leading a wave of disruption in the database space focused on delivering a single platform for all data intensive applications. We believe in building secure by design solutions for cloud and on-premises deployments without compromising performance. 

At SingleStore we are making security part of the entire software development lifecycle, from design to development, through testing and operations. To meet the needs of our rapidly growing business we are seeking an experienced and highly motivated Security Engineer to help us deliver products and services that meet customer security requirements and provide the highest levels of security assurance.

 

Job Responsibilities

  1. Drive and support secure software development lifecycle activities and practices across SingleStore (e.g., Security Architecture, Threat Modeling, Secure Coding, Ethical Hacking, Incident Response).
  2. Stay abreast of emerging security threats and vulnerabilities to ensure the appropriate security controls and mitigations are built into SingleStore products and services. 
  3. Research and evaluate evolving software security standards, best-practices and guidelines to ensure alignment and coverage within upcoming product releases. 
  4. Provide re-usable solutions to identified software vulnerabilities from internal and external penetration tests. 
  5. Collaborate with the larger engineering division by providing role based training and guidance for software security.
  6. Understand customer and partner software security requirements and interpret them to both technical and management audiences.
  7. Work closely with Product Management to develop security requirements and acceptance criteria that clearly describe customer requested security features, capabilities and opportunities for growth initiatives.
  8. Support the sales and marketing organization to ensure consistent and clear external messaging is presented describing the security posture of SingleStore products and services.
  9. Help present software security initiatives to customers, partners and external stakeholders.
  10. Assist with and support internal and external software security reviews and assessments.
  11. Collaborate with the Information Security team on enterprise security projects and initiatives that require software engineering support.

Basic Qualifications

  1. 2+ years experience in software development.
  2. 2+ years experience in software security.
  3. Strong understanding of security requirements, guidelines and best practices for building highly resilient hardened software systems (e.g. such as those from NIST, CIS, OWASP)
  4. Understanding of cloud-native and container technologies, as well as the security risks and countermeasures to secure them.
  5. Comfortable with programming and/or scripting languages (preferred: Golang, C/C++, Python, shell/bash).
  6. Well-versed in supporting the design and implementation of secure software services and secure APIs, with a clear understanding of what a Secure Software Development LifeCycle (SSDLC) entails.
  7. Understanding of encryption and key management systems.
  8. Comprehensive knowledge in assessing vulnerabilities identified by security scanning tools and third party penetration testing engagements. 

Preferred Qualifications

  1. Familiar and hands-on experience with security scanning tools (e.g., SAST, DAST, IAST, SCA)
  2. Experience in managed services security issues and architecture.
  3. Demonstrable testing competency with a focus on penetration testing and ethical hacking.
  4. Certifications in one or more of the following areas: CISSP, CCSP, CSSLP, OSCP, CEH
  5. Bachelors in Computer Science or Software Engineering.
  6.  
  7. Experience in working, presenting and communicating effectively with engineering, sales, marketing and product management in all aspects security-related, regardless of whether it’s a technical, management or executive audience.
  8. Familiarity with Kubernetes and understanding of containerized/microservices-oriented architecture.

Optional Qualifications

  1. Experience developing software security features and product capabilities (e.g., SSO, key management, data masking, access control)
  2. Familiarity with data security frameworks and regulatory standards, including PCI DSS, GDPR and/or CCPA/CPRA, or/and FedRAMP.

Skills
  • C++
  • Development
  • Python
  • Software Architecture
  • Software Engineering
  • Team Collaboration
© 2024 cryptojobs.com. All right reserved.