Principal Product Security Engineer

Aspen TechnologyBedford, MA

About The Position

This role, under the direction of the VP of Product Security, is a key member for day-to-day operations of Product Security at Aspen Technology. The Principal Product Security Engineer will protect clients, enable secure development teams, and prepare for future security needs. This thought leader will drive risk mitigation through developing Threat Models, conducting Risk Assessments, reviewing standard control alignment, overseeing vulnerability tracking, and ensuring security documentation and compliance with security lifecycle activities for product releases. This includes supporting compliance documents, secure patch releases, security incidents, security communications, the security champion program, and product security verification/validation. The role involves close collaboration with development teams, senior leaders, and other organizational teams to mitigate risks, protect customers and assets, and enable secure activities. The Principal Security Engineer will also support the development and execution of product security strategic efforts to meet business and technology objectives, continuously improving product security policies, procedures, tools, guidelines, and security awareness, while maintaining vigilance on industry threats, standards, regulations, and best practices.

Requirements

  • Bachelor’s degree (B.A./B.S.) or equivalent in computer science or technical equivalent discipline from an accredited college or university.
  • 5+ years of experience in an information security role or experience with security and development teams.
  • Experience with Application/Product Security, Risk Assessment, Threat Models, Secure Architecture/Design, Security Scanning.
  • Demonstrated ability to plan, design, develop, deploy, and maintain application security best practices.
  • Knowledge of information security regulatory requirements for privacy, secure by design, and defense in depth.
  • Maintains broad understanding of information security including ISO27002, NIST and other information security frameworks and regulations.
  • Experience with cloud solutions such as Azure and AWS.
  • Experience with security policy, procedures, tools, services, and cloud security models.
  • Ability to assume high levels of responsibility and to work with a minimum of day-to-day supervision.
  • Ability to cooperatively and effectively work with people from all organizational levels and build consensus through negotiation and diplomacy.

Nice To Haves

  • Exposure to automation and AI.
  • Exposure to IEC 62443-4-1, IEC 62443-4-2, NIST 800-53, ISO 27001, ISO 27002, Cloud Security Alliance (CSA), Cybersecurity and Infrastructure Security Agency (CISA), SANS, OWASP, CWE 25, ethical hacking, and AI Security best practices.
  • Domain knowledge and/or certification: CISSP, CISA, CCSP, CSSLP, CEH, SANS GIAC, security certification from AWS or Azure.
  • Knowledge of Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA).
  • Experience with Application Security Best Practices such as web security, cloud security, pen testing, fuzz testing, security coding guidelines, security architecture/design principles, CVSS, STRIDE, DREAD.
  • Experience with Application development technologies, processes, and best practices, for example: Agile, RUP, CICD, DevSecOps.

Responsibilities

  • Supporting the design, implementation, and oversight of Product Secure Development Lifecycle, including aspects such as security requirements, secure architecture/design, risk assessment, threat models, security scanning, triage and vulnerability management, and product security validation/verification.
  • Driving Product Security efforts to resolve challenges, enable automation, and impact organization security culture.
  • Administering product security practices to product teams, technology, and security champions across the organization.
  • Monitoring information security best practices, standards, regulations, industry threats and risks for improvements to product security practices.
  • Maintaining a deep understanding of current issues in the realm of information security.
  • Subscribing to major industry newsgroups and mailing lists and assessing the impact of all emerging issues on systems and practices at Aspen Technology.
  • Monitoring security bulletins and alerts from all Aspen Technology’s information system vendors.
  • Evaluating vulnerability impact and formulating and executing risk mitigation plans for product security.
  • Serving as a member of the AspenTech Security Emergency Response Team (ASERT) providing expert analysis of security customer reported security incidents.
  • Working with information resource owners during and after security incidents; working with product teams for analysis; recommending best practices and solutions.
  • Working with product teams, technology teams, client support and customer contacts where appropriate.

Benefits

  • Comprehensive benefits package
  • Paid time off
  • Charitable giveback day
  • Medical/dental/vision insurance
  • Retirement benefits
  • Bonus or variable incentive pay
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service