Senior Application Security Engineer - NetSuite Trust Services
Company: Oracle
Location: Quincy
Posted on: April 10, 2021
|
|
Job Description:
Responsible for the planning, design and build of security
architectures; oversees the implementation of network and computer
security and ensures compliance with corporate security policies
and procedures. Responsible for basic planning, design and build of
security systems, applications, environments and architectures;
oversees the implementation of security systems, applications,
environments and architectures and ensures compliance with
information security standards and corporate security policies and
procedures. Assist in development of incident response
capabilities, training, and tool validation. May research,
evaluate, track, and manage information security threats and
vulnerabilities in situations where analysis of well-understood
information is required and where computer programming/scripting
knowledge is required. May participate in an incident management
team, responding to security events in line with Oracle incident
response playbooks. Investigates purported intrusions and breaches,
and oversees root cause analysis. Coordinates incidents with other
business units and may assist the Incident Commander during serious
incidents. Participates in developing new methods, and playbooks,
as well as basic scripts, applications, and tools. Research
industry trends and constantly assess current controls and threat
posture of new and existing products and services. Recommend and
implement new security controls across Oracle s line of business
(LOB). Improve current processes and workflows to minimize manual
efforts. Minimum of 5 years related experience in an information
security role, supporting security programs and security
engineering/architecture in complex enterprise environments. Hands
on experience with enterprise security architecture, engineering
and implementation required. Knowledge of compliance program
security controls, like ISO 27001, SOC 2, HITRUST, and FedRAMP, as
applied to cloud SaaS, PaaS and IaaS operations. Familiarity with
SDLC principles and scripting & programming languages (such as
Terraform, Python, Ruby, etc.). Preferred but not required
qualifications include: Bachelor-level university degree in a
relevant field from an accredited university, or equivalent.
Experience in developing secure, scalable cloud architectures and
distributed systems. Experience with high-level software design and
development and the design, use, and deployment of automation and
orchestration frameworks. Demonstrable scripting or programming
experience. *This is a remote/office based position which may be
performed anywhere in the United States except for within the state
of Colorado.* *Oracle is an Affirmative Action-Equal Employment
Opportunity Employer. All qualified applicants will receive
consideration for employment without regard to race, color,
religion, sex, national origin, sexual orientation, gender
identity, disability, protected veterans status, age, or any other
characteristic protected by law.* *About the job* Want to take your
career to the next level while having fun and working in a small,
agile, and smart team? Do you like breaking and securing code? We
are the product security team,protectmultiple Oracle cloud
services, and build a secure ecosystem where developers can build
secure services. As a senior application security engineer,you will
focus on *ensuring the security of**multiple services** *by working
directly with our security teams, collaborating with our
engineering teams, and promoting gooddevelopmentsecurity practices
throughoutOracle. This is a job where details matter, and there are
a lot of details, including all of web security, mobile security,
cloud security and software security. You must be able to tell the
difference between a big problem, a minor weakness, and a false
positive. You will *help developers understand security concepts
and security practices*. You will help the security team remain a
trusted partner of the development organization by being friendly
but uncompromising when it comes to getting security right. * *
*Responsibilities:* * Conduct security design and code reviews *
Implement appropriate security protections to solve both individual
vulnerabilities and entire vulnerability classes * Build and manage
tools to help identify issues, both in the IDE and in CI/CD to
scale out the team through automation * Build libraries that
prevent security issues by design * Identify areas where our
processes can be improved, and where possible implement those
improvements * Identify, reproduce, and report security issues *
Collaborate with software engineers to make our software better,
helping them balance product and security risk decisions * Work
together to educate engineers and product teams on the importance
of security * Perform proactive research to stay current on
security issues, and share that knowledge with the rest of the
security and engineering teams * Collaborate with application
security management on program direction, team growth, and on
addressing systemic security issues *Minimum Qualifications:* *
Programming experience with one or more languages - Python is
preferred (Java, JavaScript, Python, PHP, Perl, Ruby, Kotlin,
Scala, C#, Golang, bash/zsh, C/C ). We're primarily a Java shop,
but we work with multiple programming languages daily. * 4 years in
the field of software developmentor security engineering * Existing
application security knowledge and/or desire to learn * Strong
ethics and understanding of ethics in information security *
Capable of working independently while supporting a team
environment * Ability to efficiently manage multiple tasks * Strong
communication skills in English Bonus: * B.S. in Computer Science,
Computer Engineering, or related field, or commensurate experience
* Experience in Docker, Terraform, Kubernetes. * Experience working
in an Agile development environment. * Familiarity with application
security projects (e.g. OWASP Top 10), tools (e.g. ZAP, Burp), and
how to build safer software. * Recognized industry certification
and/or continuing education programs are a major plus. * Experience
or familiarity with threat modeling, pen-testing, bug bounties,
code review, capture the flag, or other AppSec activities. *
Contributions to open-source projects. #LI-BI1 **Job:**
**Information Security Engineering* **Organization:** **Oracle*
**Title:** *Senior Application Security Engineer - NetSuite Trust
Services* **Location:** *United States* **Requisition ID:**
*2100042C*
Keywords: Oracle, Quincy , Senior Application Security Engineer - NetSuite Trust Services, Engineering , Quincy, Massachusetts
Click
here to apply!
|
Didn't find what you're looking for? Search again!
Other Engineering JobsDesktop Support Technician Description: Description: We are seeking a Help Desk Analyst to join our Woburn, MA team The applicant needs to have both technical knowledge and people skills to do the job well. This individual will apply proven (more...) Company: TEKsystems Location: Woburn Posted on: 04/18/2021 Front-End Engineer - Remote Description: Join Hired and find your dream job as a Front-End Engineer at one of 10,000 companies looking for candidates just like you.Companies on Hired apply to you, not the other way around. You'll receive salary (more...) Company: Hired Location: Melrose Posted on: 04/18/2021 Advanced Statistician / Machine Learning Engineer Description: ADVANCED STATISTICIAN/ MACHINE LEARNING ENGINEER WITH FAST-GROWING START-UP br Who we areWe are a fast-growing start-up technology and advisory firm disrupting the strategic consulting space through (more...) Company: ClearPrism Location: Boston Posted on: 04/18/2021 Backend Engineer Description: Join Hired and find your dream job as a Backend Software Engineer at one of 10,000 companies looking for candidates just like you.Companies on Hired apply to you, not the other way around. You'll receive (more...) Company: Hired Location: Boston Posted on: 04/18/2021 FPGA Design Engineer - Security Detection Description: Description br br Job Description: br br If you are an experienced, motivated and talented FPGA Design Engineer - we want to speak with you Leidos' Security and Detection Engineering's team in (more...) Company: Leidos Location: Tewksbury Posted on: 04/18/2021 Test Engineer I / Test Engineer II - 3rd Shift Description: Job Title: Test Engineer I / Test Engineer II Job Description: Test Engineering provides technical expertise to numerous manufacturing and development Programs within the Raytheon Missiles and Defense (more...) Company: RTX Location: Andover Posted on: 04/18/2021 Full Stack Engineer Description: Full-stack .NET Engineer with our confidential client in the sports and mobile technology field Location Boston, MA remote to start then on-site once it's safe to do so Direct-hire Company: The Agency Worx Location: Boston Posted on: 04/18/2021 Backend Engineer Description: Join Hired and find your dream job as a Backend Software Engineer at one of 10,000 companies looking for candidates just like you.Companies on Hired apply to you, not the other way around. You'll receive (more...) Company: Hired Location: Belmont Posted on: 04/18/2021 New Grad - Advanced Technology Group - HPC Performance Engineer with ML Description: Business SummaryThe High Performance Computing/Machine Learning team within the Office of the CTO's Advanced Technology Group is looking for a performance engineer who is passionate about HPC and ML. (more...) Company: Dell Location: East Walpole Posted on: 04/18/2021 HVAC Mechanic Description: HVAC Mechanic Our agency is partnered with a state-run facility that is looking for multiple HVAC Mechanics that can start on an immediate basis. Ideal candidates will be living in the Greater Boston (more...) Company: Professional Staffing Group Location: Braintree Posted on: 04/18/2021 |