Lead Product Security Engineer

3 Months ago • 10 Years + • Cyber Security

Job Summary

Job Description

Lead Product Security Engineer responsible for leading and executing the Secure Software Development Lifecycle (SSDLC) for Cloud Software Group's on-premise and cloud products. This involves providing security guidance to product development teams, conducting manual source code reviews (C and C++), crash exploitability analysis, penetration testing, and identifying opportunities to prevent security problems at scale. The role requires expertise in Unix systems, networking, cryptography, and strong C/C++ skills. Responsibilities include design review, threat modeling, vulnerability identification, and root cause analysis. Experience writing exploits is a plus.
Must have:
  • 10+ years software security experience
  • Expert in Unix System, Network, or Cryptography
  • Strong C, C++ skills and Linux knowledge
  • Experience in Threat Modelling, Source Code Review, Penetration Testing
  • OWASP Top 10 vulnerability remediation
  • Root cause analysis and exploit writing
Good to have:
  • OSCP, OSCE, GPEN, CRTP certifications
  • Crash Exploitability Analysis using gdb
  • Fuzzing using AFL, Peach
  • Reverse Engineering

Job Details

About the job

About This Team

YOU as a Lead Product Security Engineer will have the opportunity to collaborate with the brightest engineering minds and work on innovative product security areas.

Job Description

You are/have worked on Threat Modelling, Source Code Review, Penetration Testing and performing security analysis on existing or new products. Provide security guidance and input to product engineers. You have worked on problems of varied scope independently and able to drive strategy for Product Security in the limited scope of work and provide general guidance and/or direction on routine work to achieve overall program performance, schedule, and quality standards

Position Overview

Lead Product Security Engineer is responsible for leading and executing the Security Development Lifecycle (SDL) for Cloud Software Group On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness and drive and execute SDL best practices

Duties and Responsibilities

  • You will be responsible for leading and executing the Secure Software Development Lifecycle (SSDLC) for Cloud Software Group On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness.
  • You will provide guidance to product development teams on design changes as per security requirements.
  • Manual Source Code Review primarily C and C++ programming languages
  • Crash Exploitability Analysis - Analyze Crashes to Find Security Vulnerabilities using tools such as gdb (Good to have)
  • Execute the penetration tests internally to identify security vulnerabilities
  • Identify opportunities to prevent security problems at scale, Develop prototypes to prevent these security problems.

Basic Qualifications

  • 10+ years of experience in a software security role such as blue team
  • You have a Full-time degree in Engineering (Preferably Computer Science related)
  • You are an expert in at least one of these areas in security – Unix System, Network, Cryptography
  • Strong C, C++ skills , Linux - Linux knowledge (low level preferred).
  • Good knowledge of Networking (TCP/IP) and other protocols like HTTP/S, DNS, et.al.
  • Basic understanding of File system concepts.
  • Experience with object-oriented design concepts.
  • Debugging Skills like GDB, core dump analysis and understanding Makefile concepts.
  • Extensive knowledge of common vulnerabilities - able to explain and remediate the OWASP Top 10 vulnerabilities across multiple programming languages
  • Reverse Engineering (Good to have)
  • Fuzzing using tools such as AFL, Peach (Good to have)
  • Deep understanding of application architecture and design principles
  • Experience in design review and threat modelling activities
  • You are capable of writing exploits for vulnerabilities identified in those respective areas.
  • Have excellent capabilities to identify security vulnerabilities and perform root cause analysis.
  • Good to have certifications such as OSCP, OSCE, GPEN, CRTP etc.

About Us:

Citrix and TIBCO recently merged to create Cloud Software Group, now one of the world’s largest cloud solution providers, serving more than 100 million users around the globe. When you join Cloud Software Group, you are making a difference for real people, each of whom count on our suite of cloud-based products to get work done — from anywhere. Members of our team will tell you that we value diverse lived experiences, passion for technology, and the courage to take risks. Everyone is empowered to learn, dream, and build the future of work. We are on the brink of another Cambrian leap -- a moment of immense evolution and growth. And we need your expertise and experience to do it. Now is the perfect time to move your skills to the cloud.

Cloud Software Group is firmly committed to Equal Employment Opportunity (EEO) and to compliance with all federal, state and local laws that prohibit employment discrimination. All qualified applicants will receive consideration for employment without regard to age, race, color, creed, sex or gender, sexual orientation, gender identity, gender expression, ethnicity, national origin, ancestry, citizenship, religion, genetic carrier status, disability, pregnancy, childbirth or related medical conditions (including lactation status), marital status, military service, protected veteran status, political activity or affiliation, taking or requesting statutorily protected leave and other protected classifications.

If you need a reasonable accommodation due to a disability during any part of the application process, please contact us at (800) 424-8749 or email us at AskHR@cloud.com for assistance.

Similar Jobs

Electronic Arts - Senior Rendering Engineer (C++) - American Football

Electronic Arts

Madrid, Community Of Madrid, Spain (On-Site)
4 Months ago
NVIDIA - Android Software Engineer (RDSS Intern)

NVIDIA

Taipei City, Taiwan (On-Site)
1 Month ago
Playrix - Senior C++ Software Engineer (Gameplay)

Playrix

Serbia (Remote)
4 Months ago
Wargaming - Game Developer (World of Tanks)

Wargaming

Prague, Prague, Czechia (Hybrid)
3 Months ago
Activision - Senior Technical Artist

Activision

Warsaw, Masovian Voivodeship, Poland (On-Site)
2 Months ago
Assystems - Informaticien Cybersécurité Réseau Industriel H/F

Assystems

Cherbourg-en-Cotentin, Normandy, France (On-Site)
3 Months ago
PwC - IN-Specialist 3_Internal Audit_Internal Services_Advisory_Gurgaon

PwC

Gurugram, Haryana, India (On-Site)
3 Months ago
CloudLinux - Middle/Senior Python Developer with Security Expertise (worldwide remote)

CloudLinux

İstanbul, İstanbul, Türkiye (Remote)
3 Months ago
PwC - IN_Senior Associate_ServiceNow Developer _IN-IT Services Co_IFS_PAN INDIA

PwC

Bengaluru, Karnataka, India (On-Site)
2 Months ago
Saviynt - Lead Security Engineer, Information Security

Saviynt

Bengaluru, Karnataka, India (Hybrid)
4 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Techland - Lead Game Programmer

Techland

Poland (On-Site)
9 Months ago
The Walt Disney Company - Manager, Software Engineer - Video Playback

The Walt Disney Company

New York, New York, United States (On-Site)
1 Month ago
Unity - Junior Software Engineer

Unity

Tokyo, Japan (On-Site)
3 Months ago
Luxoft - Android Framework Developer

Luxoft

Poland, Ohio, United States (Remote)
2 Months ago
Zoox - Calibration, Localization, and Mapping Internship/Co-op

Zoox

Foster City, California, United States (On-Site)
4 Months ago
Epic Games - Rendering Programmer

Epic Games

(On-Site)
1 Month ago
ION - Lead Software Engineer, Italy

ION

Turin, Piedmont, Italy (On-Site)
4 Months ago
QUANTIC DREAM - UI Developer – Star Wars Eclipse

QUANTIC DREAM

Paris, Île-de-France, France (Hybrid)
2 Weeks ago
Unity - Gestionnaire sénior, Paie Amérique | Senior Manager, Payroll Americas

Unity

Bellevue, Washington, United States (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Saviynt - Sr Engineer, Field Engineering

Saviynt

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Luxoft - Senior QA Analyst - AML & FinCrime

Luxoft

Chennai, Tamil Nadu, India (On-Site)
3 Months ago
PwC - IN_Senior Associate_Research and Insights Hub_Markets_IFS_Mumbai/Gurgaon

PwC

Mumbai, Maharashtra, India (On-Site)
4 Months ago
PwC - IN-Senior Associate_Tech Lead Payments _FS tech_Advisory_Mumbai

PwC

Mumbai, Maharashtra, India (On-Site)
4 Months ago
CleverTap - Product Manager (Technical)

CleverTap

Mumbai, Maharashtra, India (Hybrid)
4 Months ago
Luxoft - Technical Business Analyst

Luxoft

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Assystems - Sr. Architect

Assystems

Navi Mumbai, Maharashtra, India (On-Site)
3 Months ago
NVIDIA - Verification Engineer

NVIDIA

Bengaluru, Karnataka, India (On-Site)
1 Month ago
Outscal - Video Editor

Outscal

Delhi, India (On-Site)
2 Months ago
UST - System Engineer

UST

Bengaluru, Karnataka, India (Hybrid)
4 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Paytm - Internal Audit ( IT Security)  Assistant  Manager

Paytm

Noida, Uttar Pradesh, India (On-Site)
4 Months ago
PwC - IN-Senior Associate__SAP GRC_ITRA_Advisory_  Gurgaon/Mumbai/Bangalore

PwC

Gurugram, Haryana, India (On-Site)
4 Months ago
ION - Network Security Engineer

ION

Rome, Lazio, Italy (Hybrid)
4 Months ago
Thumbtack - Director, Cybersecurity

Thumbtack

Ontario, Canada (Remote)
1 Week ago
The Walt Disney Company - Security Specialist, Corrective Action

The Walt Disney Company

Orlando, Florida, United States (On-Site)
5 Days ago
Duolingo - Senior Security Engineer

Duolingo

Pittsburgh, Pennsylvania, United States (On-Site)
4 Months ago
Intel Corporation - Network Security Engineer (DevSecOps)

Intel Corporation

Hillsboro, Oregon, United States (On-Site)
3 Months ago
Marvell India - Security Vulnerability Management Professional

Marvell India

Bengaluru, Karnataka, India (On-Site)
5 Months ago
PwC - Assurance- Senior Manager

PwC

Galway, County Galway, Ireland (On-Site)
4 Months ago
Infoblox - Staff Software Engineer

Infoblox

Washington, United States (Hybrid)
2 Months ago

Get notifed when new similar jobs are uploaded