Senior product security engineer

2 Months ago • 6 Years + • Cyber Security • Undisclosed

About the job

Job Description

The Senior Product Security Engineer leads and executes the Security Development Lifecycle (SDL) for Citrix on-prem and cloud products, ensuring software meets security robustness expectations. Responsibilities include leading a security engineering team, driving SDL best practices integration with CI/CD, Agile, and Waterfall models, creating security training, guiding product development teams on security requirements, performing code reviews, communicating technical issues, negotiating security interests, reviewing security fixes, conducting penetration tests, and validating defensive mechanisms. The role requires expertise in web, network, cloud, or cryptography; experience in application architecture, design review, threat modeling, vulnerability analysis, and root cause analysis; proficiency in programming languages (C++, C#, .NET); and understanding of browser security mechanisms and cryptographic schemes.
Must have:
  • 6+ years Security Engineering experience
  • Expert in 3+ security areas (Web, Network, Cloud, Cryptography)
  • Experience in design review and threat modeling
  • Proficiency in C++, C#, .NET
  • Strong understanding of software vulnerabilities and secure coding practices
Good to have:
  • OSCP, OSCE, GPEN, CRTP certifications
  • Experience analyzing security mechanisms of browsers and extensions
  • Proficiency in Windows system internals

About the job

The Senior product security engineer is responsible for leading and executing the Security Development Lifecycle (SDL) for Citrix On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness, as well as drive and execute SDL best practices and its integration with the CI/CD, Agile and Waterfall development models

Duties And Responsibilities

  • You will be responsible for leading and executing the Security Development Lifecycle (SDL) for Citrix On-Prem and Cloud products to ensure that our software meets the customer expectation of security robustness
  • You will lead a team of security engineers for diverse types of product security related projects and workstreams
  • You will drive and execute SDL best practices and its integration with the CI/CD, Agile and Waterfall development models
  • You will create and deliver advanced security training and guidance to product engineers
  • You will guide product development teams on design changes as per security requirements
  • You will perform manual code review activities
  • You will communicate technical issues within scope of assignment
  • You will drive negotiation in the interest of security.
  • You will conduct comprehensive reviews of specific security fixes, as necessary.
  • You will conduct product penetration test in a non-disruptive way for IT/Cloud deployments, including exploit creation to demonstrate a proof of concept.
  • You will validate the efficacy of defensive mechanisms, as well as the engineering adherence to security policies

Basic Qualifications

  • Have at least 6 years of experience in Security Engineering
  • You have a Full-time degree in Engineering (Preferably Computer Science related)
  • Must have good verbal and written communication skills; ability to communicate optimally and clearly with different stakeholders in engineering teams
  • You are an expert in at least three of these areas in security –Web, Network, Cloud, Cryptography
  • You are capable of writing exploits for vulnerabilities identified in those respective areas
  • Deep understanding of application architecture and design principles
  • Experience in design review and threat modelling activities
  • Enthusiasm for staying up to date with the latest updates about security threats and solutions
  • You have solid understanding of most common software vulnerabilities and standard secure coding practices
  • Have excellent capabilities to identify security vulnerabilities and root cause analysis
  • Have proficiency in programming language(s) like C++, C#, .NET
  • Have experience in analysing security mechanisms of browser and associated extensions
  • Have working knowledge wrt different cryptographic schemes including but not limited to key generation , rotation , revocation,etc
  • You also have proficiency in windows system Internals
  • You have demonstrated understanding of Computer Science fundamentals (OS, Networks).
  • Good to have certifications such as OSCP, OSCE, GPEN, CRTP etc

About Us:

Citrix and TIBCO recently merged to create Cloud Software Group, now one of the world’s largest cloud solution providers, serving more than 100 million users around the globe. When you join Cloud Software Group, you are making a difference for real people, each of whom count on our suite of cloud-based products to get work done — from anywhere. Members of our team will tell you that we value diverse lived experiences, passion for technology, and the courage to take risks. Everyone is empowered to learn, dream, and build the future of work. We are on the brink of another Cambrian leap -- a moment of immense evolution and growth. And we need your expertise and experience to do it. Now is the perfect time to move your skills to the cloud.

Cloud Software Group is firmly committed to Equal Employment Opportunity (EEO) and to compliance with all federal, state and local laws that prohibit employment discrimination. All qualified applicants will receive consideration for employment without regard to age, race, color, creed, sex or gender, sexual orientation, gender identity, gender expression, ethnicity, national origin, ancestry, citizenship, religion, genetic carrier status, disability, pregnancy, childbirth or related medical conditions (including lactation status), marital status, military service, protected veteran status, political activity or affiliation, taking or requesting statutorily protected leave and other protected classifications.

If you need a reasonable accommodation due to a disability during any part of the application process, please contact us at (800) 424-8749 or email us at AskHR@cloud.com for assistance.

View Full Job Description

Add your resume

80%

Upload your resume, increase your shortlisting chances by 80%

About The Company

Bengaluru, Karnataka, India (On-Site)

Karnataka, India (On-Site)

View All Jobs

Get notified when new jobs are added by Cloud Software Group

Similar Jobs

ION - Senior C++ Developer, Italy

ION, Italy (On-Site)

CD PROJEKT RED - Senior / Principal Network Engineer

CD PROJEKT RED, United States (Hybrid)

Meta - ML Silicon Performance Architect

Meta, United States (On-Site)

Sonar Source - Security Engineer

Sonar Source, United States (On-Site)

ION - Senior Security Architect

ION, United Kingdom (On-Site)

ION - Senior Security Architect

ION, United Kingdom (On-Site)

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

Activision - Associate Dev Support Engineer

Activision, (Hybrid)

Nintendo - Senior Data Scientist

Nintendo, United States (On-Site)

Google - Software Engineer, Mobile, Android

Google, India (On-Site)

 Sagecor Solutions - Cloud Software Engineer 1 (FST - 005)

Sagecor Solutions, United States (On-Site)

Regent Craft - Flight Controls Engineering Intern

Regent Craft, United States (On-Site)

IO Interactive - Senior Audio Programmer

IO Interactive, Denmark (Hybrid)

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

Armada - Senior Data Engineer

Armada, India (On-Site)

Assystems - Structure Engineer

Assystems, India (On-Site)

Reliance Industries  - Lead Reservoir Engineer ( 81732533 )

Reliance Industries , India (On-Site)

Entrata - Sr. Product Designer

Entrata, India (Hybrid)

Flexera - Senior UI Engineer

Flexera, India (Hybrid)

Netomi - Software Engineer II - Python

Netomi, India (Hybrid)

Logitech - Market Development Representative

Logitech, India (On-Site)

Ethernovia - GUI Tools Software Development

Ethernovia, India (Remote)

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - IT Project Management

PwC, Portugal (On-Site)

ION - Platform Security Analyst

ION, Italy (On-Site)

Notion - Application Security Engineer

Notion, United States (On-Site)

Trend Micro - Sales Engineer

Trend Micro, Netherlands (On-Site)

PwC - Forensic Manager

PwC, Canada (On-Site)

Fanatics - Offensive Security Engineer III

Fanatics, India (Hybrid)

Reversing Labs - Security Solutions Architect (DACH Region)

Reversing Labs, Germany (Remote)

Globalization Partners - Information Security Analyst - GRC

Globalization Partners, United States (Remote)

Get notifed when new similar jobs are uploaded