Job Application for Product Security Engineer at Navan{"@context":"schema.org","@type":"JobPosting","hiringOrganization":{"@type":"Organization","name":"Navan"},"title":"Product Security Engineer","datePosted":"2024-09-10","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Palo Alto, California, United States","addressRegion":"CA","addressCountry":null,"postalCode":null}},"description":"\u003cp\u003eThe \u003cstrong\u003eProduct Security Engineer\u003c/strong\u003e will be responsible for securing Navan products, by identifying risks early in the SDLC and developing application security tooling \u0026amp; processes to promote a ‘shift left’ security culture. You will be responsible for integrating security in the application development process, conducting security-related research and assessments, performing feature penetration testing, and providing security analysis/design/training to the organization.\u003c/p\u003e\n\u003cp\u003eReporting to the \u003cstrong\u003eDirector of Product Security and Research\u003c/strong\u003e, you will contribute significantly to building and scaling an application security program. This position requires both advanced technical skills, strong communication skills, and the ability to influence people. You will be responsible for ensuring the continuous security of Navan customer-facing products and internal tools. You will focus on proactively discovering security vulnerabilities, driving and advising risk remediation based on research, and developing strong partnerships with engineering and product teams to accelerate the release of the software with security by design.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eWhat You’ll Do:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentifying security issues within the product.\u003c/li\u003e\n\u003cli\u003eDesign and develop security tools and processes to be leveraged by development teams.\u003c/li\u003e\n\u003cli\u003eWork closely with engineering to sustain processes and/or convert manual integrations to automated pipeline activities.\u003c/li\u003e\n\u003cli\u003eAssist in developing custom Security as Code solutions.\u003c/li\u003e\n\u003cli\u003eParticipate in expanding/maturing the Navan S-SDLC program.\u003c/li\u003e\n\u003cli\u003eReview product designs for security defects, perform threat modeling and recommend remediations.\u0026nbsp;\u003c/li\u003e\n\u003cli\u003eProvide training, guidance, and assistance to development teams early in the SSDLC.\u003c/li\u003e\n\u003cli\u003eCultivate security ownership in the product teams.\u003c/li\u003e\n\u003cli\u003eBring visibility to product/application vulnerabilities in a consistent manner to enable appropriate prioritization and remediation.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eWhat We’re Looking For:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eExperience performing threat modeling and architecture reviews for complex applications.\u003c/li\u003e\n\u003cli\u003eProven experience performing application, cloud and mobile penetration testing in high risk environments like financial or healthcare companies.\u003c/li\u003e\n\u003cli\u003e2-4 years of Technical Product Security related experience around SSDLC tooling, automation, remediation advisory, security testing, threat modeling/attack surface analysis.\u003c/li\u003e\n\u003cli\u003eAbility to execute in multifaceted and highly technical organizations.\u003c/li\u003e\n\u003cli\u003eAbility to provide pragmatic security advice for web applications, mobile applications, and cloud software.\u003c/li\u003e\n\u003cli\u003eExperience working in Agile development with experience in technologies such as:\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eApplication security testing tools (SAST, DAST, IAST, SCA, or similar.)\u003c/li\u003e\n\u003cli\u003eInfrastructure as code (Terraform, or similar)\u003c/li\u003e\n\u003cli\u003eJava Spring Framework (3+ years),\u0026nbsp; Hibernate or similar ORM technologies, JavaScript/CSS, and Angular\u003c/li\u003e\n\u003cli\u003eContainers (Docker, Kubernetes, or similar)\u003c/li\u003e\n\u003cli\u003eContinuous integration (Jenkins, Github Actions or similar)\u003c/li\u003e\n\u003cli\u003eIntegration of Security testing tools into CI pipelines\u003c/li\u003e\n\u003cli\u003eDefect tracking (Jira,or similar.)\u003c/li\u003e\n\u003cli\u003eSource code management (GitHub, or similar.)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cli\u003eIn-depth knowledge of common application \u0026amp; network protocols, cryptographic primitives, authentication \u0026amp; authorization protocols, and common securit
See more jobs at TripActions
Apply for this job