Who you are:We are always looking for amazing talent who can contribute to our growth and deliver results! Geotab is seeking a Product Security Specialist who will perform security reviews ranging from individual static and dynamic scanner vulnerabilities to complex product architectural reviews on both internal and external products. If you love technology, and are keen to join an industry leader - we would love to hear from you!
What you'll do:As a Product Security Specialist your key area of responsibility will be performing security evaluations, tracing source code for vulnerabilities, writing scripts to increase scanning automation, and simulating cyber attacks to identify product security risks. You will need to work closely with development teams, security operations, and global stakeholders to integrate robust security practices throughout the product lifecycle. To be successful in this role you will be a meticulous, highly organized team player with excellent verbal and written communication skills who thrives under fast-changing priorities. In addition, the successful candidate will have strong analytical problem-solving skills, deep technical proficiency across multiple programming languages, and the ability to explain risk assessments to both technical and non-technical audiences.
How you'll make an impact:- Review existing/new/proposed products with a variety of source code, dynamic and dependency scanners, manual code reviews and security-based architecture reviews as required.
- Manually validate scanner findings by tracing source code for a variety of code bases (C#, .net, Java, js/ts/html, swift, kotlin, python, C, firmware as applicable) and provide developer level suggestions for code remediation.
- Explain risk assessments at both the developer (technical) and management (non technical) levels.
- Write and maintain scripts/code (bash and python) to generate scan input packages, automate security scanner execution and integrate scanners with CI pipelines and Google Cloud storage and reporting mechanisms.
- Manage and update scanning scripts quickly, and refactor as needed.
- Contribute to secure coding standards (involves developing secure coding training for current and future developers).
- Perform technical writing of assessment reports and vulnerability descriptions for product owners and developers.
- Support with the design and implementation of secure architectures for products, ensuring robust security controls and compliance with industry standards.
- Conduct security testing, including vulnerability assessments, penetration testing and code reviews. Provide recommendations for improving product security.
- Perform threat modeling to identify potential security risks and vulnerabilities in products.
- Contribute to and sometimes lead initiatives to improve the overall security posture of our products.
- Assess and question whether the coverage is sufficient, and if not make recommendations to address coverage gaps.
- Ensure thorough follow-up to prevent oversights, prioritize tasks that contribute to team objectives, and escalate issues promptly when necessary.
- Monitor and respond to emerging security threats and vulnerabilities relevant to our products.
- Develop and maintain security automation scripts and tools to streamline security processes.
- Collaborate closely with development teams to integrate robust security practices throughout the product lifecycle, ensuring security-by-design principles are adhered to.
- Utilize technical proficiency alongside strong communication skills to efficiently handle time-sensitive and confidential product vulnerability reports.
- Support Geotab global strategic initiatives.
What you'll bring to the role:- 5 - 8 years of required previous experience in security evaluation/analysis, security code reviews, or relevant development experience.
- Bachelor's degree in Computer Science, Information Management, Engineering, or a related field (or equivalent combination of education and work experience).
- Experience using source code, dynamic, and dependency scanners (e.g., Veracode, Fortify, Sentinel, OWASP dependency, NetSparker, Qualys).
- Knowledge of programming languages (C, C#, .NET, Python, JavaScript/TypeScript), web service technologies (XML, JSON, SOAP, REST), and dependency package managers (npm, nuget).
- Competency with Linux, Windows, GCE, Bash, and Python, along with proficiency in rapidly acquiring new programming languages.
- Exceptional communication skills, high accuracy, meticulous attention to detail, and the ability to manage multiple tasks and projects simultaneously.
- Security certifications and experience working within a technical or engineering high-technology industry are considered an asset.
If you got this far, we hope you're feeling excited about this role! Even if you don't feel you meet every single requirement, we still encourage you to apply.
Please note: Geotab does not accept agency resumes and is not responsible for any fees related to unsolicited resumes. Please do not forward resumes to Geotab employees.Why job seekers choose Geotab:Flex working arrangements
Home office reimbursement program
Baby bonus & parental leave top up program
Online learning and networking opportunities
Electric vehicle purchase incentive program
Competitive medical and dental benefits
Retirement savings program
*The above are offered to full-time permanent employees onlyHow we work:At Geotab, we have adopted a flexible hybrid working model in that we have systems, functions, programs and policies in place to support both in-person and virtual work. However, you are welcomed and encouraged to come into our beautiful, safe, clean offices as often as you like. When working from home, you are required to have a reliable internet connection with at least 50mb DL/10mb UL. Virtual work is supported with cloud-based applications, collaboration tools and asynchronous working. The health and safety of employees are a top priority. We encourage work-life balance and keep the Geotab culture going strong with online social events, chat rooms and gatherings. Join us and help reshape the future of technology!