ARM
Principal Product Security Engineer
We are at the forefront of technological innovation, delivering cutting-edge products and services to meet the demands of a rapidly evolving digital landscape. Our commitment to security and excellence drives us to develop robust solutions that inspire confidence and trust. We are seeking a skilled Principal Product Security Engineer to lead the charge in ensuring the security and resilience of our products throughout their lifecycle.
Role Overview
As a Principal Product Security Engineer, you will lead the design, implementation, and management of security measures across our product portfolio. You will collaborate with cross-functional teams to embed security best practices, proactively address vulnerabilities, and ensure our products meet the highest security standards.
Key Responsibilities:
- Develop and oversee security strategies for products, ensuring robust protection against evolving threats.
- Conduct risk assessments, threat modeling, and vulnerability analyses during product development.
- Partner with development and engineering teams to integrate security protocols into the software development lifecycle (SDLC).
- Implement and maintain security controls, including encryption, authentication, and secure configurations.
- Monitor and respond to emerging threats, ensuring products remain secure against new vulnerabilities.
- Lead security audits and ensure compliance with industry standards and regulations such as ISO 27001 and GDPR.
- Provide technical leadership and mentorship to the engineering team, fostering a culture of security awareness.
- Advocate for the adoption of advanced security tools and technologies to enhance the security posture.
- Prepare documentation and reports on security strategies, compliance, and risk management activities.
Requirements:
- Extensive experience in product security engineering, with a strong understanding of secure software development.
- Expertise in threat modeling, vulnerability assessment, and penetration testing.
- Familiarity with security frameworks and standards such as OWASP, NIST, and CIS benchmarks.
- Proficiency in cloud security, containerization technologies (e.g., Docker, Kubernetes), and microservices architecture.
- Hands-on experience with tools such as static and dynamic analysis tools, vulnerability scanners, and penetration testing frameworks.
- Strong problem-solving skills and attention to detail, with the ability to address complex security challenges.
- Effective communication and collaboration skills, capable of engaging with technical and non-technical stakeholders.
- Relevant certifications such as CISSP, CISM, or CEH are highly desirable.
- Degree in Cybersecurity, Computer Science, or a related field, or equivalent practical experience.
What We Offer:
- Competitive salary and benefits package.
- Opportunities to work on high-impact projects in a collaborative and forward-thinking environment.
- A workplace culture that values innovation, growth, and teamwork.
- Access to training and professional development to stay ahead in the cybersecurity domain.
Application Process:
If you are passionate about cybersecurity and have the expertise to lead product security initiatives, we encourage you to apply. Join us as a Principal Product Security Engineer and make a significant impact in protecting the future of technology.