Navy Federal Credit Union

Senior Product Security Engineer

Navy Federal Credit Union

full-time

Posted on:

Origin:  • 🇺🇸 United States • Florida, Virginia

Visit company website
AI Apply
Manual Apply

Salary

💰 $131,700 - $206,450 per year

Job Level

Senior

Tech Stack

CloudJavaMicroservicesPythonSDLC

About the role

  • To embed security seamlessly into the product development lifecycle.
  • Work with development and engineering teams across the enterprise to enhance the security of our applications through automation, security reviews, and DevSecOps best practices.
  • Collaborate with NFCU teams and vendors to determine security requirements and support or automate security across all phases of product integration, operations, and maintenance to ensure a secure Navy Federal environment.
  • Work under minimal supervision and use complete understanding of business needs and objectives to support projects that have impact on the achievement of operational goals.
  • Advanced skill set and proficiency with procedures and techniques

Requirements

  • Bachelor’s Degree in Computer Science or the equivalent combination of education, training or experience
  • 5-7 years of experience in security engineering
  • Complete knowledge and understanding of business area/specialization
  • Advanced skill with application security and software development in one or more programming languages such as C#, Java, Python, etc.
  • Experience with security tools such as SAST, DAST, IAST, SCA and other security tools
  • Advanced knowledge of industry-standard security frameworks such as OWASP, NIST, BSIMM etc.
  • Experience with CICD pipeline, security tools integration and secure SDLC
  • Experience collaborating with cross functional engineering and product teams to scale secure SDLC
  • Advanced knowledge of secure architecture and design patterns for Web, Mobile and Microservices
  • Advanced knowledge of current and emerging threats and techniques for exploiting security vulnerabilities
  • Advanced skill using methodologies and security testing tools for threat analysis of complex applications and services including threat modeling, software fuzzing, static and dynamic analysis