Tech Stack
CloudJavaJavaScriptPythonSDLC
About the role
- Work closely with engineering teams to secure Pluralsight platform and identify security threats and vulnerabilities.
- Provide recommendations to engineering teams on how to address the vulnerabilities.
- Support and enable engineering teams when performing and maintaining threat models and provide mentorship and guidance to engineers.
- Use knowledge of common risks and vulnerabilities to guide engineering teams in building products.
- Use and maintain security tooling and processes, such as SAST/DAST tools and vulnerability reporting.
- Promote and develop a security aware mind set among teams.
- Record and communicate vulnerability findings and keep records up to date.
- Implement automated DevSecOps security checkpoints.
- Collaborate with engineers through all phases of the SDLC.
Requirements
- 3+ years of professional experience in product security, working with SaaS application & Cloud security.
- An engineering graduate with computer science or information technology background.
- Strong analytical and problem-solving skills
- Good understanding of software development concepts and technologies
- Knowledge of programming languages such as JavaScript, Java, C#, and Python
- Experience with security tools and technologies such as Web Application Firewall, SAST, and DAST
- Experience in performing Penetration testing in identifying security vulnerabilities
- Knowledge on OWASP Top 10/ SANS Top 25 vulnerabilities
- Experience communicating security threats and application vulnerabilities to technical and non-technical team members
- Any Security Certifications like CEH, OSCP will be a plus.
- Understanding of AI and LLM models is preferred.
- An individual with an aptitude to learn and grow.