Principal Application Security Specialist

16 Hours ago • 7 Years + • Cyber Security

Job Summary

Job Description

The Principal Application Security Specialist at Barracuda Networks ensures the security of Barracuda's software and services. Responsibilities include source code review (Python, PHP, Go), manual application security assessments, integrating automated security assessment solutions, architecture reviews, and providing expert advice on security trends and best practices. The role involves identifying and mitigating vulnerabilities, collaborating with development teams, and participating in incident response. A deep understanding of software security best practices and OWASP Top 10 is crucial. The specialist will also manage bug bounty programs and evaluate new security technologies.
Must have:
  • Source code review (Python, PHP, Go)
  • Manual application penetration testing
  • Vulnerability assessment and remediation
  • Collaboration with development teams
  • 7+ years of experience
Good to have:
  • Solutions architecture review
  • Threat modeling
  • Fuzzing
  • SAST/DAST/SCA experience
  • Understanding of IaC and cloud security (Azure, AWS)
  • Bug bounty program management
Perks:
  • Equity (non-qualifying options)
  • Internal mobility opportunities

Job Details

Job ID 25 - 618 (2)

Come join our passionate team! Barracuda is a leading cybersecurity company providing complete protection against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR service, to strengthen cyber resilience. Hundreds of thousands of IT professionals and managed service providers worldwide trust us to protect and support them with solutions that are easy to buy, deploy, and use.
We know a diverse workforce adds to our collective value and strength as an organization. Barracuda Networks is proud to be an Equal Opportunity Employer, committed to equal employment opportunity and equitable compensation regardless of race, gender, religion, sex, sexual orientation, national origin, or disability.

Envision yourself at Barracuda
The Principal Application Security  Specialist assures the safety and security of Barracuda Networks software and services through source code review, manual application security assessment, operation and integration of automated security assessment solutions, architecture review, and expert advice regarding software security trends, threats, best practices and incidents. Through assuring the safety and security of Barracuda Networks software and services, the Application Security Specialist helps to keep our customers and their data safe and secure. 
 
Tech Stack Exposure
  • A deep understanding of software security best practices and vulnerabilities, especially as they relate to web applications (e.g. OWASP Top 10) 
  • Experience identifying vulnerabilities in software and SaaS services 
  • Experience in source code review, preferably for Python, PHP and Go 
  • Experience in scoping and performing manual application penetration testing 
  • Experience in assessing the risk of identified vulnerabilities, and providing correct, robust and actionable recommendations to mitigate and/or resolve the vulnerabilities 
  • Experience in understanding software vulnerabilities, in finding other instances of the vulnerability across codebases, and in identifying collateral/related vulnerabilities. 
  • Experience in assessing the implemented resolution of a vulnerability for completeness and accuracy, and identifying bypasses for the implemented resolution 
  • Experience in working collaboratively with software development teams to identify vulnerabilities in all stages of software development 
  • Experience in communicating effectively with people of varying security proficiency and interest (fellow security professionals, engineering, and management) 
  • The ability to coordinate and participate in wide-scale Software Incident Security Response exercises such as the log4j response, understanding and unpacking information as incidents unfold, and in working across the organization to deliver a comprehensive "Identify, Resolve, Validate" solution 
  • Basic programming experience in at least one language, preferably Python or Go, and experience in automating routine tasks such as searching source code and manipulating data. 
What you’ll be working on
  • Ensure the secure delivery of software from design through to implementation 
  • Maintain awareness of software security trends, incidents, and best practices, and provide expert advice and guidance to engineering teams regarding secure development and vulnerability remediation. 
  • Manage Barracuda’s bug bounty programs 
  • Work collaboratively with the organization, including with Security, Compliance and Engineering, to understand and remediate computer and software security incidents 
  • Evaluate new and emerging security technologies, features, and products. 
What you bring to the role
  • 7+ years of experience 
  • The ability to perform source code review in new and unfamiliar languages using knowledge of security best practices and a willingness to read documentation 
  • Solutions architecture review experience, and the ability to identify opportunities and vulnerabilities early in the specification and development of software 
  • Threat modelling experience 
  • Fuzzing experience 
  • Experience using and integrating automated software security scanners such as SAST/DAST/SCA 
  • An understanding of Infrastructure as Code and cloud platform security (preferably Azure and AWS) 
  • An understanding of identity, authentication and authorization protocols including OAuth/OpenID Connect and SAML 
  • Published examples of work such as original research, vulnerability advisories, conference talks, bug bounty writeups or CTF writeups 
  • The ability to identify opportunities for process improvement, including automation and the authorship of software (scanners, fuzzers, helper utilities etc.) 
  • Experience participating in and/or managing bug bounty programs 
  • Experience with and/or a willingness to collaborate with other security functions such as compliance and policy, network/corporate security, security monitoring and incident response 
 
What you’ll get from us 
A team where you can voice your opinion, make an impact, and where you and your experience are valued. Internal mobility – there are opportunities for cross training and the ability to attain your next career step within Barracuda. In addition, you will receive equity, in the form of non-qualifying options. 
The anticipated on-target earnings range for this role is 146,000 to 167,000 CAD. Actual compensation offered will be dependent upon the individual's skills, experience, and qualifications as they directly relate to the requirements of the position, the budget for the position, and applicable employment laws.
#LI-remote

Similar Jobs

Socialpoint - Senior Software Engineer (Full Stack Engineer)

Socialpoint

Barcelona, Catalonia, Spain (Hybrid)
1 Week ago
CloudHire - Full Stack Web Developer

CloudHire

Bengaluru, Karnataka, India (Remote)
1 Week ago
Technorizen Software Solutions - Urgent opening for Exp. IOS Developer

Technorizen Software Solutions

Indore, Madhya Pradesh, India (On-Site)
8 Months ago
Qingci Games - Urgent Platform Backend Development Engineer

Qingci Games

(On-Site)
2 Months ago
Meta - Production Engineering

Meta

New York, New York, United States (On-Site)
5 Months ago
Barracuda Networks  Inc  - Security Automation Engineer

Barracuda Networks Inc

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Dream Games - Workplace Security Manager

Dream Games

İstanbul, Türkiye (On-Site)
1 Month ago
Meta - Product Security Engineer

Meta

New York, New York, United States (On-Site)
5 Months ago
Tesla - EMEA Security Systems Engineer

Tesla

Berlin, Berlin, Germany (On-Site)
1 Month ago
Rockstar Games - Director, Security Operations

Rockstar Games

New York, New York, United States (On-Site)
5 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Evolution - Senior Backend Game Developer

Evolution

Sofia, Sofia City Province, Bulgaria (On-Site)
2 Months ago
Nagarro - Associate Staff Engineer, PHP

Nagarro

Philippines (Remote)
5 Months ago
Cadence - Lead FrontEnd Methodology Engineer

Cadence

Bengaluru, Karnataka, India (On-Site)
6 Months ago
Airlab Inc  - Jr Programmer Artificial Intelligence

Airlab Inc

Montreal, Quebec, Canada (On-Site)
10 Months ago
ByteDance - Senior Software Engineer, Multi Cloud CDN - San Jose / Seattle / Boston

ByteDance

Seattle, Washington, United States (On-Site)
3 Months ago
Nagarro - Staff Engineer, PHP- DRUPAL

Nagarro

Sri Lanka (Remote)
5 Months ago
Enphase Energy - Senior Front-end Design (Drupal)

Enphase Energy

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Passion Gaming - Back End Engineer PHP

Passion Gaming

Gurugram, Haryana, India (On-Site)
7 Months ago
Nagarro - Principal Engineer -- PHP Developer

Nagarro

New Jersey, United States (Remote)
5 Months ago
Technorizen Software Solutions - Exp. PHP Developer

Technorizen Software Solutions

Indore, Madhya Pradesh, India (On-Site)
8 Months ago

Get notifed when new similar jobs are uploaded

Jobs in Ontario, Canada

Epic Games - Level Designer

Epic Games

Vancouver, British Columbia, Canada (On-Site)
3 Months ago
Epic Games - Artiste sénior, interface utilisateur (IU)

Epic Games

Montreal, Quebec, Canada (On-Site)
3 Months ago
TiMi Studio Group - Technical Artist Intern

TiMi Studio Group

Quebec, Canada (On-Site)
3 Weeks ago
Rockstar Games - Senior Workplace Coordinator

Rockstar Games

Oakville, Ontario, Canada (On-Site)
1 Day ago
NVIDIA - Senior Digital Circuit Design Engineer

NVIDIA

Canada (On-Site)
1 Month ago
Ubisoft - Team Lead - Character Modelling

Ubisoft

Toronto, Ontario, Canada (On-Site)
20 Hours ago
Activate Games - Game Facilitator (Store Associate)

Activate Games

Mississauga, Ontario, Canada (On-Site)
1 Week ago
NVIDIA - Senior Silicon Product Definition Engineer

NVIDIA

Canada (Hybrid)
1 Month ago
Behaviour Interactive - Senior Gameplay Programmer - Dead by Daylight | Senior Programmeur·se jouabilité - Dead by Daylight

Behaviour Interactive

Montreal, Quebec, Canada (On-Site)
8 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Infoblox - Staff Software Engineer

Infoblox

Burnaby, British Columbia, Canada (Hybrid)
5 Months ago
Netflix - Site Reliability Engineer (L5) - Security Engineering

Netflix

United States (Remote)
5 Months ago
Magna International - Sr. Penetration Test Engineer

Magna International

Bengaluru, Karnataka, India (On-Site)
6 Months ago
ION - Markets Governance, Risk and Controls Manager

ION

India (On-Site)
5 Months ago
Plume Design,  Inc  - Senior Security Engineer

Plume Design, Inc

Hyderabad, Telangana, India (On-Site)
5 Months ago
Varonis  - Technical Support Engineer L2

Varonis

New Delhi, Delhi, India (Remote)
1 Day ago
Forescout Technologies  Inc  - Professional Services Engineer

Forescout Technologies Inc

United States (Hybrid)
4 Months ago
PwC - Azure Senior Cloud Architect | Alliances, Technology Consulting

PwC

Dublin, County Dublin, Ireland (On-Site)
5 Months ago
Inworld AI - IT Security & Compliance Lead

Inworld AI

Mountain View, California, United States (Hybrid)
1 Week ago
ByteDance - Senior Technology Internal Auditor (Global Technology Audit)

ByteDance

Singapore (Hybrid)
1 Week ago

Get notifed when new similar jobs are uploaded

About The Company

Delhi, India (On-Site)

Atlanta, Georgia, United States (Hybrid)

Philadelphia, Pennsylvania, United States (Remote)

Colorado, United States (Remote)

Missouri, United States (Remote)

View All Jobs

Get notified when new jobs are added by Barracuda Networks Inc

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug