Description:
Responsibilities and Impact
This is a Director-level individual contributor role that will work across Security, software development, Data science/LLM, QA, and Operations teams to identify component and system level technical risks, identify and evaluate critical failure points, determine technical security controls to mitigate risks, prioritize and schedule controls with application development timelines, and work with cross functional teams to implement remediations.
This role will drive the Secure SDLC roadmap, GenAI security strategy, and Cloud security architecture, assist with maturing the security engineering program, develop security tooling, mentor others and be hands-on partner to our development teams to deliver innovative and secure applications.
A successful candidate for this position will:
Develop, implement and maintain Application security and GenAI security strategy
Provide architectural guidance on best practices regarding security in software development, shared services, user interface design frameworks, high performance messaging solutions, server-side development, integrations, tools and technologies
Drive and guide the specification and realization of a security architecture, with decisions driven by balancing security risks faced by the business along with customer or market requirements
Perform threat modeling, secure code reviews, and secure design reviews for high-risk applications, evaluate new technology stacks and frameworks
Perform vulnerability research, serve as technical security/risk advisor for new technology/applications developed by S&P Ratings
Determine testing requirements and develop strategies to automate security testing using a variety of scripting and open source tools
Assist developers in remediating vulnerability findings by providing line-by-line guidance
Coach development teams on security disciplines like Threat modeling, Security code reviews, provide training and education to developers on software security best practices
Maintain knowledge of current and emerging technologies / products / trends related to security architectural solutions
Develop repeatable application security patterns to ensure that systems are placed within the relevant security zones based on the data they house and their purpose
Consult and assist with security incident response process
Consult on efforts to work with internal and external teams to effectively scope and drive Application Penetration tests that help identify and mitigate gaps in security controls
Guide development and SRE teams in building secure Cloud Native applications by incorporating Cloud and Microservices Security best practices and industry standards
Organization | S&P Global |
Industry | IT / Telecom / Software Jobs |
Occupational Category | Senior GenAI Application Security Engineer |
Job Location | Toronto,Canada |
Shift Type | Morning |
Job Type | Full Time |
Gender | No Preference |
Career Level | Intermediate |
Experience | 2 Years |
Posted at | 2024-08-18 5:31 pm |
Expires on | 2025-01-22 |