Sr. Software Security Engineer

3 Months ago • 3-5 Years • Cyber Security

Job Summary

Job Description

The Sr. Software Security Engineer role at Cadence focuses on cloud and on-premise software security controls, including WAF and CDN tools. The role involves integrating security tools at the source code repo, build environment, and artifactory levels. Responsibilities include developing and supporting the secure software development lifecycle, including DAST, SAST, SCA, penetration testing, and attack surface management. This position requires direct interaction with development teams and exposure to incident response, vulnerability management, and deployment of security solutions. The ideal candidate will have a strong background in Application Development, Configuration Management/DevOps, and experience building software security within CI/CD. The role will include operational support for AWS and Azure WAF configurations, automating DAST in CI/CD pipelines, and performing manual penetration tests on web applications.
Must have:
  • Experience with AWS WAF and Azure WAF configurations.
  • Experience with Dynamic Application Security Testing (DAST).
  • Experience with GitHub, Perforce, and GitLab.
  • Strong understanding of application security concepts and tools.
  • Experience in OWASP Top 10 and common AppSec tools.
Good to have:
  • Experience with SonaType, JFrog.
  • Working knowledge of scripting languages like Python and PowerShell.
  • Experience with Linux/UNIX and Windows based operating systems.
  • Experience with common security libraries and controls.
  • CISSP or SANS GIAC certifications.

Job Details

At Cadence, we hire and develop leaders and innovators who want to make an impact on the world of technology.

Cadence’s Information Security team is seeking a Sr. Software Security Engineer. This role will focus on Cloud and on-premise Software Security controls including WAF and CDN tools.  This is a Security Development Operations role that will ensure security tool integration at the source code repo (Perforce, Github etc.), build environment, and artifactory level.  As a member of the Information Security team, this role will develop and support the secure software develop life cycle, including DAST, SAST, SCA, penetration testing, and attack surface management.  

This role will interface directly with development teams. Of course, there is broad exposure to other aspects of information security related tasks such as incident response, vulnerability management, and deployment of security solutions. The successful candidate for this position is a highly motivated individual with a strong Application Development and Configuration Management/DevOps background with hands-on experience in building software security within CI/CD.

Key Deliverables and Responsibilities (include but are not limited to the following):

Perform operational support for AWS WAF configurations – updating whitelists and creating security automation web ACLs to protect Internet facing endpoints and applications.

Perform operational support for Azure WAF configurations

Automate Dynamic Application Security Testing (DAST) in the CI/CD pipeline. 

Perform manual penetration tests on web applications

Maintain Cloudflare DDOS protections and WAF configurations.

Attend enterprise architecture reviews to standardize and secure new deployments

Qualifications and Special Skills Required

Bachelor’s degree in computer science or engineering field or equivalent combination of education and relevant 3 – 5 years of experience

A passion to learn and educate others on how to build secure software.

Ability to work in a group setting and independently

Experience with Jira IT ticketing systems.

Experience with GitHub, Perforce, GitLab

Experience with SonaType, JFrog

Good working knowledge in scripting language, Python, PowerShell, etc.

Strong understanding of Linux/UNIX and Windows based operating systems and networks.

Strong working knowledge of Application security concepts and technologies such as:

Experience in OWASP Top 10 and usage of common AppSec testing tools.

Experience of Secure by Design concepts and threat modeling

Knowledge of common security libraries, security controls, and common security flaws.

Experience in application penetration testing techniques and tools

Knowledge of application technologies including Web applications, Web services, XML, SOA, AJAX, JSON, and Web scanning tools

Open Source Security (OSS) - Software Composition Analysis (SCA)

Static Application Security Testing (SAST)

Dynamic Application Security Testing (DAST)

Security Architecture Review - Threat Modeling

AWS and Azure WAF Configuration and whitelisting

Cloudflare DDOS configuration and operation

Manual Penetration Testing

Penetration testing with 3rd party vendors

Host level vulnerability Scanning

Web application security training course development and delivery

Preferred Certifications:

Certified Information Systems Security Professional (CISSP)

SANS GIAC certifications

Amazon Web Services, Azure, Google Cloud Platform

We’re doing work that matters. Help us solve what others can’t.

Similar Jobs

Progress - Software Engineer II (Windows Application Developer)

Progress

Bengaluru, Karnataka, India (Hybrid)
2 Months ago
Morning Star - Technical Manager (.NET Lead)

Morning Star

Bucharest, Bucharest, Romania (Hybrid)
2 Months ago
Microsoft - Senior Applied Researcher

Microsoft

Redmond, Washington, United States (On-Site)
3 Months ago
Ion - Technical Consultant - Wallstreet Suite

Ion

Noida, Uttar Pradesh, India (On-Site)
1 Year ago
bounteous - MxML Developer (Murex Back Office)

bounteous

Mexico City, Mexico (On-Site)
2 Months ago
Roblox - Senior Security Software Engineer, Network Security

Roblox

San Mateo, California, United States (On-Site)
1 Month ago
Veeam Software - Cloud Application Security Engineer (Middle/Senior)

Veeam Software

Prague, Czechia (On-Site)
1 Month ago
Rockstar Games - Senior Security Engineer (C++)

Rockstar Games

Edinburgh, Scotland, United Kingdom (On-Site)
1 Month ago
Jam City - Corporate IT Security Engineer

Jam City

Montevideo, Montevideo Department, Uruguay (Remote)
1 Month ago
Alpha Sense - Senior Cloud Security Engineer

Alpha Sense

India (On-Site)
2 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

BetterMe - Senior Backend (Node.js) Engineer (Web)

BetterMe

Kyiv, Kyiv City, Ukraine (Remote)
3 Months ago
Ajmera Infotech - Senior Data Analytics Engineer - Databricks - Power BI

Ajmera Infotech

Austin, Texas, United States (On-Site)
1 Month ago
Roof Stacks - Software Developer

Roof Stacks

Istanbul, İstanbul, Türkiye (On-Site)
4 Months ago
Cognite - Senior Data Engineer

Cognite

Pau, Nouvelle-Aquitaine, France (Hybrid)
3 Months ago
ness digital  - Big Data Engineer

ness digital

Timișoara, Timiș, Romania (Remote)
6 Months ago
Adtran - Sr. DevOps Software Engineer

Adtran

Huntsville, Alabama, United States (On-Site)
2 Months ago
The Walt Disney Company - Senior, Software Engineer

The Walt Disney Company

Buenos Aires, Buenos Aires, Argentina (Hybrid)
3 Weeks ago
HP - Principal Software Engineer

HP

Spring, Texas, United States (On-Site)
2 Weeks ago
Matellio - Technology Lead - PHP

Matellio

Jaipur, Rajasthan, India (On-Site)
3 Months ago
Scanline VFX - Senior Pipeline Developer (Houdini)

Scanline VFX

Toronto, Ontario, Canada (Remote)
10 Months ago

Get notifed when new similar jobs are uploaded

Jobs in San Jose, California, United States

Blinkhealth - Supervisor, Pharmacy Operations (Claims and Patient Outreach)

Blinkhealth

Chesterfield, Missouri, United States (On-Site)
3 Months ago
Coupa - Account Executive - Mid Market

Coupa

Los Angeles, California, United States (Remote)
1 Month ago
Apple - Manager, NPI CapEx Engineering Program Manager

Apple

Cupertino, California, United States (On-Site)
3 Months ago
Roblox - Machine Learning Engineering Manager – Economy ML

Roblox

San Mateo, California, United States (On-Site)
3 Weeks ago
Xsolla - Senior Product Manager - Xsolla Advertising & Rewards

Xsolla

Los Angeles, California, United States (Remote)
2 Weeks ago
Scale AI - Security Engineer (Infrastructure)

Scale AI

Washington, District Of Columbia, United States (On-Site)
3 Months ago
C3 IoT - Pre-Sales AI Director – Generative AI

C3 IoT

Atlanta, Georgia, United States (On-Site)
1 Month ago
HHA Exchange - Principal Software Engineer

HHA Exchange

New York, New York, United States (Hybrid)
4 Weeks ago
undefined - Software Engineer, Edge

Canada, Kentucky, United States (Remote)
10 Months ago
Nice - Technical Account Manager

Nice

Atlanta, Georgia, United States (Hybrid)
1 Month ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

Unisys - Cybersecurity Consultant

Unisys

Bogotá, Bogota, Colombia (On-Site)
3 Weeks ago
Apple - Security Embedded Software Engineer

Apple

Sunnyvale, California, United States (On-Site)
2 Months ago
CAE - Vulnerability & DevOps Analyst

CAE

Montreal, Quebec, Canada (Hybrid)
1 Year ago
binance - DevSecOps Engineer, Infrastructure Security

binance

Taipei City, Taiwan (Remote)
1 Year ago
bytedance - Backend Engineer(Distributed System) - Network Security - San Jose

bytedance

San Jose, California, United States (On-Site)
9 Months ago
Take-Two Interactive - Information Security Operations Analyst

Take-Two Interactive

Austin, Texas, United States (On-Site)
4 Weeks ago
Epic Games - Security Engineer - Backend (Asset Integrity)

Epic Games

Porto Alegre, State Of Rio Grande Do Sul, Brazil (On-Site)
4 Months ago
Glocomms - Senior Cybersecurity Engineer

Glocomms

Boston, Massachusetts, United States (On-Site)
2 Months ago
DataVisor - Security Engineer

DataVisor

Austin, Texas, United States (Remote)
1 Month ago
Guardian - Senior Lead Engineer - Network Security

Guardian

Gurugram, Haryana, India (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded

About The Company

Cadence plays a critical role in creating the technologies that modern life depends on. We are a global electronic design automation company, providing software, hardware, and intellectual property to design advanced semiconductor chips that enable our customers create revolutionary products and experiences. Thanks to the outstanding caliber of the Cadence team and the empowering culture that we have cultivated for over 25 years, Cadence continues to be recognized by Fortune Magazine as one of the 100 Best Companies to Work For. Our shared passion for solving the world’s toughest technical challenges, our dedication to pushing the limits of the industry, and our drive to do meaningful work differentiates the people of Cadence.

San Jose, California, United States (On-Site)

Hsinchu, Hsinchu City, Taiwan (On-Site)

Zhubei, Hsinchu County, Taiwan (On-Site)

Shanghai, China (On-Site)

Hsinchu, Hsinchu City, Taiwan (On-Site)

Shanghai, China (On-Site)

Yokohama, Kanagawa, Japan (On-Site)

Hyderabad, Telangana, India (On-Site)

Montreal, Quebec, Canada (On-Site)

Shanghai, China (On-Site)

View All Jobs

Get notified when new jobs are added by Cadence

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug