ABOUT THE ROLE
Are you passionate about application security and ready to serve as a subject matter expert in both application security and securing the software development lifecycle? In this role, you’ll be instrumental in protecting our low-latency processing systems and trading platforms across diverse environments. Reporting directly to the Director of Application Security, you will work collaboratively with development, infrastructure, and operations teams to embed security into every phase of our process and in the company culture.
Overview & Key Responsibilities:
- Serve as the internal point of reference and Subject Matter Expert on application security and software factory security.
- Design, implement, and maintain the essential tools to ensure secure CI/CD pipelines with robust security controls including automated testing, secrets detection, compliance checks, software composition analysis, and vulnerability management.
- Support our development teams in addressing identified findings, ensuring compliance with secure coding practices to align with industry standards for both cloud and on-premises environments, and promote a culture of ongoing security enhancement.
- Participate in design reviews, threat modeling, and architecture assessments to proactively identify and mitigate security risks in new and existing solutions.
- Work with our Core and Architecture team to establish and enforce solutions for encryption, authentication (both human and machine), access control (role- and attribute-based), secret management, and secure configurations in cloud (AWS, GCP, or Azure) as well as on-premises environments.
- Develop, monitor, and report indicators to track security performance and drive continuous improvement.