Lead Product Security Engineer

6 Months ago • 10 Years + • Cyber Security

Job Summary

Job Description

Lead Product Security Engineer responsible for leading and executing the Secure Software Development Lifecycle (SSDLC) for Cloud Software Group's on-premise and cloud products. This involves providing security guidance to product development teams, conducting manual source code reviews (C and C++), crash exploitability analysis, penetration testing, and identifying opportunities to prevent security problems at scale. The role requires expertise in Unix systems, networking, cryptography, and strong C/C++ skills. Responsibilities include design review, threat modeling, vulnerability identification, and root cause analysis. Experience writing exploits is a plus.
Must have:
  • 10+ years software security experience
  • Expert in Unix System, Network, or Cryptography
  • Strong C, C++ skills and Linux knowledge
  • Experience in Threat Modelling, Source Code Review, Penetration Testing
  • OWASP Top 10 vulnerability remediation
  • Root cause analysis and exploit writing
Good to have:
  • OSCP, OSCE, GPEN, CRTP certifications
  • Crash Exploitability Analysis using gdb
  • Fuzzing using AFL, Peach
  • Reverse Engineering

Job Details

About the job

About This Team

YOU as a Lead Product Security Engineer will have the opportunity to collaborate with the brightest engineering minds and work on innovative product security areas.

Job Description

You are/have worked on Threat Modelling, Source Code Review, Penetration Testing and performing security analysis on existing or new products. Provide security guidance and input to product engineers. You have worked on problems of varied scope independently and able to drive strategy for Product Security in the limited scope of work and provide general guidance and/or direction on routine work to achieve overall program performance, schedule, and quality standards

Position Overview

Lead Product Security Engineer is responsible for leading and executing the Security Development Lifecycle (SDL) for Cloud Software Group On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness and drive and execute SDL best practices

Duties and Responsibilities

  • You will be responsible for leading and executing the Secure Software Development Lifecycle (SSDLC) for Cloud Software Group On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness.
  • You will provide guidance to product development teams on design changes as per security requirements.
  • Manual Source Code Review primarily C and C++ programming languages
  • Crash Exploitability Analysis - Analyze Crashes to Find Security Vulnerabilities using tools such as gdb (Good to have)
  • Execute the penetration tests internally to identify security vulnerabilities
  • Identify opportunities to prevent security problems at scale, Develop prototypes to prevent these security problems.

Basic Qualifications

  • 10+ years of experience in a software security role such as blue team
  • You have a Full-time degree in Engineering (Preferably Computer Science related)
  • You are an expert in at least one of these areas in security – Unix System, Network, Cryptography
  • Strong C, C++ skills , Linux - Linux knowledge (low level preferred).
  • Good knowledge of Networking (TCP/IP) and other protocols like HTTP/S, DNS, et.al.
  • Basic understanding of File system concepts.
  • Experience with object-oriented design concepts.
  • Debugging Skills like GDB, core dump analysis and understanding Makefile concepts.
  • Extensive knowledge of common vulnerabilities - able to explain and remediate the OWASP Top 10 vulnerabilities across multiple programming languages
  • Reverse Engineering (Good to have)
  • Fuzzing using tools such as AFL, Peach (Good to have)
  • Deep understanding of application architecture and design principles
  • Experience in design review and threat modelling activities
  • You are capable of writing exploits for vulnerabilities identified in those respective areas.
  • Have excellent capabilities to identify security vulnerabilities and perform root cause analysis.
  • Good to have certifications such as OSCP, OSCE, GPEN, CRTP etc.

About Us:

Citrix and TIBCO recently merged to create Cloud Software Group, now one of the world’s largest cloud solution providers, serving more than 100 million users around the globe. When you join Cloud Software Group, you are making a difference for real people, each of whom count on our suite of cloud-based products to get work done — from anywhere. Members of our team will tell you that we value diverse lived experiences, passion for technology, and the courage to take risks. Everyone is empowered to learn, dream, and build the future of work. We are on the brink of another Cambrian leap -- a moment of immense evolution and growth. And we need your expertise and experience to do it. Now is the perfect time to move your skills to the cloud.

Cloud Software Group is firmly committed to Equal Employment Opportunity (EEO) and to compliance with all federal, state and local laws that prohibit employment discrimination. All qualified applicants will receive consideration for employment without regard to age, race, color, creed, sex or gender, sexual orientation, gender identity, gender expression, ethnicity, national origin, ancestry, citizenship, religion, genetic carrier status, disability, pregnancy, childbirth or related medical conditions (including lactation status), marital status, military service, protected veteran status, political activity or affiliation, taking or requesting statutorily protected leave and other protected classifications.

If you need a reasonable accommodation due to a disability during any part of the application process, please contact us at (800) 424-8749 or email us at AskHR@cloud.com for assistance.

Similar Jobs

SiftHub - Senior Frontend Engineer

SiftHub

Maharashtra, India (On-Site)
7 Months ago
Kefir games - Team-lead Technical Artist

Kefir games

Cyprus (On-Site)
7 Months ago
Landor - Type Designer

Landor

Milan, Lombardy, Italy (Hybrid)
5 Days ago
CD PROJEKT RED - Senior Gameplay Animator

CD PROJEKT RED

Boston, Massachusetts, United States (Hybrid)
1 Month ago
Google - Staff Interaction Designer, Google Ads

Google

San Francisco, California, United States (On-Site)
1 Month ago
NVIDIA - GPU Firmware Engineer (RDSS Intern)

NVIDIA

Taipei City, Taiwan (On-Site)
4 Months ago
Appirits - Security Engineer

Appirits

Shibuya, Tokyo, Japan (Hybrid)
2 Months ago
PwC - Cloud Security | Manager | Cyber Security | Technology Consulting

PwC

Dublin, County Dublin, Ireland (On-Site)
8 Months ago
PwC - Salesforce Technical Lead (Manager)

PwC

Makati, Metro Manila, Philippines (Hybrid)
8 Months ago
GLG - Senior Security Operations Engineer

GLG

Gurugram, Haryana, India (Remote)
7 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Sailpoint - Senior Golang Developer

Sailpoint

Pune, Maharashtra, India (On-Site)
2 Weeks ago
Ion - Product Designer - Graduate Development Program, Italy

Ion

Milan, Lombardy, Italy (Hybrid)
2 Months ago
Creasaur - Game Developer

Creasaur

Ankara, Ankara, Türkiye (On-Site)
3 Weeks ago
Expression games  - UI/UX Artist

Expression games

(Remote)
1 Month ago
Light Speed Studios - フロントエンドエンジニア|Frontend Engineer

Light Speed Studios

Tokyo, Japan (On-Site)
5 Months ago
Playstation - Principal UX Designer

Playstation

Liverpool, England, United Kingdom (Hybrid)
3 Weeks ago
appier - Senior LLM Scientist

appier

Taipei City, Taiwan (On-Site)
2 Weeks ago
Globalization Partners - Principal Software Engineer

Globalization Partners

Northern Ireland, United Kingdom (Remote)
1 Week ago
Coupa - Director, User Experience Design

Coupa

Pune, Maharashtra, India (Remote)
1 Month ago
Zinnia - Product Manager I

Zinnia

Bridgewater, New Jersey, United States (Hybrid)
1 Month ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Axi - Office & Talent Coordinator

Axi

Bengaluru, Karnataka, India (On-Site)
2 Weeks ago
Likewise - Solarwinds Tools Expert

Likewise

Chennai, Tamil Nadu, India (On-Site)
1 Month ago
Take-Two Interactive - Site Reliability Engineer I

Take-Two Interactive

Bengaluru, Karnataka, India (Hybrid)
2 Weeks ago
commerce iq - Software Development Engineer I

commerce iq

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Capgemini - Model based developer

Capgemini

Bengaluru, Karnataka, India (On-Site)
1 Week ago
PwC - Associate - App Tech - GDC

PwC

Kolkata, West Bengal, India (On-Site)
8 Months ago
INKPPT  - Presentation Specialist

INKPPT

Gurugram, Haryana, India (On-Site)
8 Months ago
Qualcomm - Engineer - Power Analysis & Optimization

Qualcomm

Hyderabad, Telangana, India (On-Site)
1 Month ago
luxsoft - Telecommunication Consultant

luxsoft

India (Remote)
3 Weeks ago
matchgroup - Regional Product Marketing Manager

matchgroup

Gurugram, Haryana, India (Hybrid)
2 Weeks ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - Senior Consultant - RDC TC MSOFT

PwC

Kolkata, West Bengal, India (On-Site)
8 Months ago
Varonis  - Cloud Security Architect

Varonis

United States (Remote)
3 Months ago
PwC - Manager / Senior Manager Cyber Technology and Transformation

PwC

Zürich, Zurich, Switzerland (On-Site)
8 Months ago
bytedance - Senior Security Tech Lead Manager - Security Engineering

bytedance

San Jose, California, United States (On-Site)
3 Months ago
PwC - Risk Services - Change Management Specialist

PwC

Singapore (On-Site)
8 Months ago
bytedance - Technical Account Manager (Edge Cloud)

bytedance

Boston, Massachusetts, United States (On-Site)
2 Months ago
Netflix - Security Engineer L5, Incident Response

Netflix

Poland (Remote)
1 Month ago
Varonis  - Technical Support Engineer L2

Varonis

Sydney, New South Wales, Australia (Remote)
2 Months ago
PwC - ETIC, Cybersecurity Risk Technology Associate

PwC

Cairo, Cairo Governorate, Egypt (On-Site)
8 Months ago
bytedance - Technical Account Manager (Edge Cloud)

bytedance

San Jose, California, United States (On-Site)
1 Month ago

Get notifed when new similar jobs are uploaded