The Principal Security Engineer is a member of Axway's world-class security team, the Product Security Group (PSG). PSG is a global team in the Axway R&D Department, a global group that focuses on supporting the delivery of secure products and services in cloud-native and on-premise applications that serve the most security-conscious numerous industries worldwide.
Axway utilizes a structured approach for reviewing and validating the security of Axway products and cloud services with a mix of the following tools and processes: vulnerability monitoring, vulnerability management, static source code analysis, threat modeling, manual penetration testing, automated penetration testing, automated vulnerability scanning, third-party penetration testing, developer training in secure coding practices, and development/management of Axway security frameworks.
The Security Engineer is a member of the Product Security Group (PSG) in the R&D Department, a global group that focuses on supporting the delivery of secure products and services in cloud-native and on-premise applications that serve numerous industries worldwide.
The Security Engineer provides support to Axway Software Engineers. R&D Organization in the application of the Secure Development Lifecycle (SDLC) for Axway products and cloud services. This position will have primary responsibility for driving and continuously improving the SDLC, the designing and supporting of security controls, optimizing our use of security testing suites, providing training in secure coding, and evangelizing security best practices within Axway. This position will also have has a role in performing vulnerability assessments, security penetration testing (Red Team), and guidance on the remediation and mitigation of security findings.
Helpful Skills to Support the Responsibilities:
- Technical leadership skills, coupled with strong communication skills;
- Securing applications and infrastructure in Cloud environments such as AWS;
- Java, JVM, JCA/JCE experience, Crypto Library JDK’s;
- C/C++ coding or analysis experience;
- Static analysis (SAST) tool experience such as Fortify, Checkmarx, Coverity;
- Attack surface tool experience such as InsightVM, Qualys, Nessus;
- Vulnerability scanning and mitigation;
- Dynamic application security testing (DAST) tool experience with tools such as AppSpider, Zap;
- Opensource composition analysis using tools such as Dependency-Check, WhiteSource, Snyk;
- TLS, SSL, PKI, and certificate management experience;
- Layer 3 thru 7 network security experience;
- Vulnerability management procedures;
- Penetration Testing and Fuzzing (files, functions);
- Authentication and Authorization mechanics and protocols;
- Understanding and experience in IH/IR;
- Secure system configuration and deployment of infrastructure;
- Experience with Infrastructure as Code such as Terraform, Ansible;
- Experience with security best practices orchestration platforms such as Docker, Kubernetes, EKS;
- Ability to learn new products and technical concepts quickly;
- Successfully manage time and technical responsibilities, set accurate expectations and meet deliverable deadlines while working in a team environment;
- Comfortable working on both Linux-based and MS Windows-based system platforms with a strong technical understanding and aptitude for analytical problem-solving;
- Strong understanding of application-level security issues;
- Understanding of enterprise computing environments, distributed applications, and a strong understanding of TCP/IP networks;
- Understanding of the system hardening processes, tools, guidelines and benchmarks;
- Strong understanding of encryption technologies, Java/Linux and Microsoft implementations;
- Experience with SAST, DAST and vulnerability management platforms can be a plus/
These essential functions are representative of those that must be met by an employee to successfully perform the job. Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions. Position may be required to perform other duties as required. Travel requirements may be up to 15% and include international travel destinations.
- Bachelor’s degree in Computer Science, Information Technology or related field. Master’s preferred;
- A minimum of 7-10 years of product development experience; at least 5 of those years focused on product security;
- Experience using Microsoft Office suite tools to create documents, presentations, and detailed drawings;
- Superior technical writing, documentation, and communication skills are required;
- Several years of hands-on experience with AWS Platform and AWS Security and nice-to-have AWS certifications;
- Has achieved an information security certification such as CSSLP, GWAPT, GPEN, OSCP, AWAE, CCSP or similar, or ability to obtain within 18 months of hire.
Employee career development is one of Axway’s major company values; and we are deeply committed to helping them leverage the promotion and job mobility opportunities that are right for them.
This is what our candidates can expect from us if they choose to join our team:
- A personal development plan (technical, product & functional) in order to insure your integration and your performance
- Competitive remuneration package and real benefits (meal tickets, medical and dental insurance, gym access, Bookster, Amazon E-library, Safari, team-buildings, Christmas Party, Fun Day, Ice-cream Day etc)
- French classes to improve your language skills
- Flexible working hours when need
- Work from home policy – 5 days/month
- Extra paid vacation days - 25 days/year
- Potential for growth in an international company
- Friendly working environment with experienced professionals
- Open games area – table tennis, drums, sports and more!
In addition, Axway’s global presence creates opportunities for geographical mobility both within Axway subsidiaries.