Search by job, company or skills

Product Security Engineer

Product Security Engineer

SailPoint Technologies
3-5 Years
Not Disclosed
Quick Apply
  • Posted a month ago
  • Over 100 applicants have applied

Job Description

  • Participate in expanding and maturing the SailPoint Secure Software Development Lifecycle (S-SDLC) program.
  • Perform proactive scanning and auditing during early SSDLC phases and reactive scanning in later phases; triage and communicate findings to development teams.
  • Configure, maintain, and tune pipeline and traditional product/application security technologies.
  • Reduce false positives through repeatable suppression methods to ensure adoption of security tools.
  • Assist tech leads and developers with remediation strategies for security issues.
  • Support automation and tooling of security technologies for development teams.
  • Develop custom software quality tests and Security-as-Code solutions.
  • Review application designs for security defects, perform threat modeling, and identify remediation solutions.
  • Provide training, guidance, and assistance to development teams early in the SSDLC.
  • Cultivate security ownership among product teams and integrate new security services.
  • Manage product/application vulnerabilities consistently, prioritize remediation, and validate fixes.
  • Provide input to security risk impact assessments.
  • Collaborate with engineering to sustain security processes and automate pipeline activities.
  • Participate in the Product Security Incident Response Team (PSIRT) as needed.

More Info

Job Type:
Function:
Employment Type:

About Company

SailPoint is the Worldwide Leader for Enterprise-Class Identity GovernanceWe minimize risk and maximize business growth by managing access to data and resources across your enterprise. We do it effectively and securely for every person who interacts with your organizationany user, on any device, anywhere in the world.We were first to recognize that companies could benefit from an approach to identity that addresses both IT and business priorities. We developed a unique risk-based model and leveraged that approach for everything from compliance to user provisioning. Then we followed that with the industrys first solution for truly extending enterprise identity management to applications in the cloud