Base Career helps you apply smarter for this job.
Key skills for this role
Own and execute product-security engineering work for Cortenic connectivity solutions, including security debt reduction, remediation SLAs, operating dashboards and continuous improvement of inherited security gaps.
Design, maintain and improve central GitHub security pipelines and standard caller workflows across connectivity repositories, including dependency, secret, code-quality, artifact, container and cloud-security scans.
Onboard repositories and projects to standard security workflows, map branches and environments, validate secrets versus variables, and ensure the correct image and configuration are used across release stages.
Review cloud, Kubernetes, Artifact Registry and IAM configurations; identify misconfigurations, over-permissive access, registry exposure, data-classification gaps and monitoring/logging coverage issues.
Identify, triage, prioritize and drive closure of findings from Dependabot, Xray, SonarQube, Orca, Tanium, CrowdStrike, Burp Suite and Secret Scanning, including re-scans and evidence-based verification.
Partner with development teams during sprints to interpret scan reports, fix findings before PR merge or release, remediate High/Critical dependency and container vulnerabilities, and validate fixes through pipeline re-runs.
Configure and maintain security quality gates, generate SBOMs for production releases, prepare release security reports, assess gate exceptions and provide evidence for Quality, audit and release sign-off.
Create and maintain security runbooks, repository onboarding checklists, branch/environment/secrets guides, audit-ready evidence packs and technical reference material for reviews, approvals and stakeholder briefings.
Support penetration testing by defining scope, preparing architecture/access/environment details, reviewing reports, creating remediation plans with development teams and providing closure evidence.
Respond to cybersecurity incidents, customer/security-contract questions, Cyber Central requests and newly disclosed vulnerabilities with impact assessments, approved evidence, clear documentation and timely follow-through.
Support compliance and certification readiness by providing scan artifacts, risk and vulnerability evidence, control implementation inputs and audit support in partnership with Global Cybersecurity and Quality.
Required Bachelor's degree in Computer Science, Information Security, Cybersecurity, Software Engineering, or a related field. 7+ years of hands-on cybersecurity, product security, cloud security or DevSecOps experience in software/product engineering environments.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Oakland, USA
Hawthorn East, AUS
Oakland, USA
Chesterfield, USA
Muscatine, USA
Whippany, USA
, USA
Muscatine, USA
Tulsa, USA
Strong experience with GCP preferred and at least one additional cloud platform such as AWS or Azure.
Practical experience with CI/CD security, GitHub workflows, vulnerability scanning, dependency scanning, container/image scanning, secret scanning and release security gates.
with tools such as Dependabot, SonarQube, JFrog Xray, Orca, Tanium, CrowdStrike, Burp Suite, SAST/DAST tools, SIEM/logging platforms or equivalent technologies. Ability to translate scan findings into prioritized remediation plans, work with engineering teams to close findings, and produce audit-ready evidence. Working knowledge of ISO 27001, SOC 2, NIST, GDPR, HIPAA, GxP, SaMD, medical device cybersecurity or other regulated product-security expectations is preferred. Strong analytical, documentation, stakeholder-management and communication skills, with the ability to support developers, Quality, Global Cybersecurity and leadership stakeholders. Cloud Security: Google Cloud Platform preferred, plus AWS or Azure; cloud, Kubernetes, Artifact Registry, IAM, workload identity, secrets, variables and registry exposure reviews DevSecOps & Security Tooling: GitHub security pipelines, Dependabot, Secret Scanning, SonarQube, JFrog Xray, Orca, Tanium, CrowdStrike, Burp Suite, SAST/DAST and CI/CD security gates Vulnerability & Remediation Management: severity and exploitability-based prioritization, High/Critical dependency and container fixes, patch verification, re-scans and closure evidence Release Assurance: security quality gates, SBOM generation, release security reports, exception assessments, control checklists and evidence for Quality/release sign-off Monitoring & Incident Response: cybersecurity signal triage, SIEM/log-source coverage, incident support, newly disclosed CVE impact assessment and escalation handling Security Documentation & Evidence: runbooks, onboarding checklists, branch/environment/secrets guides, audit-ready evidence packs and technical reference material Penetration Testing Support: scope definition, architecture/access/environment readiness, report review, remediation planning and closure evidence Regulated Product Security: healthcare or SaMD product security, ISO 27001, SOC 2, NIST, HIPAA, GDPR, GxP/release audit support and security-risk evidence Agile & Collaboration: Jira, Confluence, Scrum practices, developer enablement, stakeholder Q&A, sprint backlog integration and clear communication with cross-functional teams Experience working in enterprise/global cybersecurity teams on cybersecurity management plans, cyber test reports, security requirements, release security reviews, risk assessments and risk-management reporting. Familiarity with global cybersecurity governance activities such as policy and procedure creation, security-gate design, centralized control checklists, threat modeling and cybersecurity control ownership mapping. Understanding of regulated product-security deliverables, including Cybersecurity Management Plans, Cyber Test Reports, Security Risk Management Plans/Reports, Threat Modeling Reports, residual-risk decisions and release-security evidence packs. Ability to support global teams with incident response, customer escalations, external disclosures, newly disclosed vulnerability assessments and documented impact/risk decisions. Exposure to certification and compliance readiness work with Quality, including ISO certification scope, certification strategy, control evidence, submission support and audit-ready security-risk documentation.
Full-time
Senior
Apply faster on company sites with our extension.