Overview
This is a hybrid role, and will be required to work in-office at our Plano, TX office at least 3 days per week. Candidates must be located within reasonable commuting distance of this office and be willing to work in-office on a regular basis.
Applicants must be currently authorized to work in the United States on a full-time basis and must not require sponsorship for employment visa status now or in the future.
A DAY IN THE LIFE
In this role, you will...
• Develop security documentation, training, and guidance for internal infrastructure and engineering teams
• Consult with internal teams and assist with architecture, threat modeling, and reviewing systems and infrastructure to identify vulnerabilities and weaknesses in architecture, make appropriate recommendations, and drive teams to implement those recommendations
• Perform penetration testing to examine target systems in detail, looking for vulnerabilities and weaknesses
• Conduct vulnerability research and analysis into emerging threats to include proactive security research on the technologies that we use
• Identify and implement security technical and process improvements
• Define and own metrics to determine effectiveness of security controls
WHO YOU ARE
You possess ...
• Bachelor of Science in Computer Science, Mathematics, Engineering or equivalent experience or education
• 5+ years of experience in a hands-on security role with a demonstrated mastery of multiple classes of security defects
• Demonstrated coding skills in one or more popular languages and platforms including C#, SQL, Python, and others
• Experience with the .NET Core framework
• Understanding of cloud computing platforms and cloud-based infrastructure design and operation
• Understanding of container technologies, security, and tooling (such as Docker, Kubernetes, Helm)
• Understanding of networking, routing, and web related protocols
Responsibilities
• Develop security documentation, training, and guidance for internal infrastructure and engineering teams
• Consult with internal teams and assist with architecture, threat modeling, and reviewing systems and infrastructure to identify vulnerabilities and weaknesses in architecture, make appropriate recommendations, and drive teams to implement those recommendations
• Perform penetration testing to examine target systems in detail, looking for vulnerabilities and weaknesses
• Conduct vulnerability research and analysis into emerging threats to include proactive security research on the technologies that we use
• Identify and implement security technical and process improvements
• Define and own metrics to determine effectiveness of security controls
• Apply comprehensive hardening to infrastructure platforms, deployment code, and images
• Architect, build, automate, and operate automated security controls/tools and review capabilities to detect vulnerabilities across all applications and services
• Be a champion for security culture and excellence, exercise risk-based judgement and prioritize remediation work
• Other duties as assigned
Qualifications
• Bachelor of Science in Computer Science, Mathematics, Engineering or equivalent experience or education
• 5+ years of experience in a hands-on security role with a demonstrated mastery of multiple classes of security defects
• Demonstrated coding skills in one or more popular languages and platforms including C#, SQL, Python, and others
• Experience with the .NET Core framework
• Understanding of cloud computing platforms and cloud-based infrastructure design and operation
• Understanding of container technologies, security, and tooling (such as Docker, Kubernetes, Helm)
• Understanding of networking, routing, and web related protocols
Preferred Qualifications:
• Experience with Microsoft Azure
• Experience with Container security platforms
• Continuous integration and delivery tooling (CI/CD)
• Current security certification (e.g. OSCP, OSEE) is a PLUS