Home
/
Software Engineering
/
Senior Security Engineer
Senior Security Engineer-September 2024
Krakow
Sep 20, 2024
About Senior Security Engineer

  Come and join our Guidewire PSIRT (Product Security Incident Response Team) and be a part of a high-powered and high-performing team that regularly works across the entire organization, with everyone from product teams to executives. Urgent escalations from enterprise customers, investigating reported vulnerabilities, performing root cause analysis and working with security researchers.

  Guidewire PSIRT (Product Security Incident Response Team) is responsible for: Guidewire product vulnerability management process for all Guidewire applications. Coordination of customer/external product security incidents and reported security issues affecting various Guidewire products and applications. Working cross-functionally with all business units, sustaining engineers, product security team members, customer support, legal and external security researchers to ensure timely resolution of security incidents and events. Development, maintenance and continuous improvement of the product security incident monitoring, detection and response tools and process, including all required supporting materials. Pen testing Guidewire applications to ensure timely discovery of the vulnerabilities. Security Review and Code Review of Guidewire applications

  We are looking for a new team member who will be responsible to perform following activities (but not limited to):Ensure proper execution of PSIRT Process - triage security related issues (external / internal), verify those on different versions, products. Perform root cause analysis to ensure validity of reported issues. Triage code defect based issues, quantitatively evaluate risk and provide guidance to engineering teams regarding the impact of security issues using industry standard metrics such as CVSS. Work closely with project management, product management, engineering and sustaining teams to drive issues to closure. Cultivate strong working relationships with external researchers, reporting organizations and customers to ensure effective collaboration. Work with customer facing and internal teams to continually improve processes used to identify and fix product security issues Enhance existing product security incident response program Coordinate with internal product development teams in accomplishing regular security reviews and penetration testing assessments. Execute the penetration tests internally to identify critical vulnerabilities. Perform security-focused code reviews Support the preparation of security releases. Develop security tooling and automation Assist teams in reproducing, triaging, and addressing application security vulnerabilities. Validate findings from security scanning tools and ideate data-driven enhancement strategies for dynamic (DAST), static (SAST), open-source application security testing (SCA) and container security scanning including troubleshooting, and continuous process improvement 

  RequirementsBachelor's/master’s in computer science or equivalent Industry related certifications are preferred (E.g. CSSLP, CISSP, GIAC, OSCP, etc.) Minimum 7-10 years of relevant Application Security Experience At least 2-5 years of experience with Penetration testing Solid understanding of OWASP Top 10, common classes of product security vulnerabilities and attack/defense methodologies. Strong written and verbal communications skills Proven ability to build relationships and influence individuals at all levels, as well as external security researchers, vendors and service providers Experience with various application security tools - Static code analysis, dynamic code analysis, vulnerability scanning, pen testing AWS/Cloud Experience a strong plus Bug bounty program participation a plus Knowledge of the security research community is a strong plus Scripting skills (i.e. Python/Perl/Ruby, shell scripting) or development experience (Java/C++/Python) is a significant plus!

  #LI-CE1

  About Guidewire

  Guidewire is the platform P&C insurers trust to engage, innovate, and grow efficiently. We combine digital, core, analytics, and AI to deliver our platform as a cloud service. More than 540+ insurers in 40 countries, from new ventures to the largest and most complex in the world, run on Guidewire.

  As a partner to our customers, we continually evolve to enable their success. We are proud of our unparalleled implementation track record with 1600+ successful projects, supported by the largest R&D team and partner ecosystem in the industry. Our Marketplace provides hundreds of applications that accelerate integration, localization, and innovation.

  For more information, please visit www.guidewire.com and follow us on Twitter: @Guidewire_PandC.

  Guidewire Software Inc. provides equal employment opportunities to all applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. All offers are contingent upon passing a criminal history and other background checks where it's applicable to the position.

  We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation. 

  CONSENT and ACKNOWLEDGEMENT 

  By clicking the submitting your application on the following page:

  1. You consent to Guidewire collecting, retaining, disclosing and using your Personal Data as outlined above, and to its transfer of your Personal Data outside the country where you live or work, and/or to third parties for the above purposes.

  2. In the event that you submit any Sensitive Personal Data, you explicitly consent to Guidewire collecting, retaining, disclosing and transferring your Sensitive Personal Data on the terms and for the same purposes as described above in relation to Personal Data.

  3. You acknowledge that you have the right to access your Personal Data and Sensitive Personal Data at any time and have the right to correct any errors.

  4. You acknowledge that your Personal Data will be retained for up to 24 months.

Comments
Welcome to zdrecruit comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
SIMILAR JOBS
Senior Network Engineer - Remote
Opportunities with Optum in the Tri-State region (formerly CareMount Medical, ProHEALTH New York and Riverside Medical Group). Come make a difference in the lives of people who turn to us for care at
Analista Planejamento Produção
Job Description Summary Job Description Que tal atuar em uma empresa líder global em tecnologia médica que impulsiona o mundo da saúde? Seja parte de algo grandioso! A BD é uma das maiores empresas d
Software Quality Engineer 2
Our Company Changing the world through digital experiences is what Adobe's all about. We give everyone-from emerging artists to global brands-everything they need to design and deliver exceptional di
Sr. Application Analyst
Company Description Visa is a world leader in digital payments, facilitating more than 215 billion payments transactions between consumers, merchants, financial institutions and government entities a
Senior Production Manager
Every great story has a new beginning, and yours starts here. Welcome to Warner Bros. Discovery... the stuff dreams are made of. Who We Are... When we say, the stuff dreams are made of, we're not jus
Técnico(a) de Enfermagem - Central de Material e Esterilização - Fortaleza, CE
Somos a Amil, fazemos parte do UnitedHealth Group, uma empresa norte-americana que se dedica a atividades variadas no setor de saúde e bem-estar e, por meio de mais de 285 mil colaboradores no mundo
Técnico de Servicios - Cobertura zona Norte
Job Description Summary Job Description BD es una compañía global de dispositivos médicos que promueve la atención médica al mejorar la investigación, el diagnóstico y la enfermería. BD emplea a más
Systems Administrator (Senior)
Job Description BAE Systems, a top-ten prime contractor to the U.S. Department of Defense, enables the U.S. government to transform data into intelligence and provides engineering, integration and su
Utilities Operator Trainee
Job Description BAE Systems, Inc. is currently recruiting for a Utilities Operator Trainee for the Radford Army Ammunition Plant in Radford, VA. In this role, you will perform checks of pump stations
Staff Software Engineer - Java Platform Development
Company Description Visa is a world leader in digital payments, facilitating more than 215 billion payments transactions between consumers, merchants, financial institutions and government entities a
Copyright 2023-2024 - www.zdrecruit.com All Rights Reserved