Software Security Engineer

3 days ago


Shanghai, Shanghai, China Thermo Fisher Scientific Full time

Job Description

What we do

The Product Security team is a group of Builders, Breakers, and Fixers that specialize in collaborative security engagement. The goal of the Software Security (DevSecOps) team is to provide self-service security and to that end, the team is focused on enabling the 3 Ways of DevOps: Fast Flow, Rapid Feedback, and Continuous Learning. As the business moves through its digital transformation, the DevSecOps team is a vanguard for promoting and enabling DevOps practices across the organization. We aim to integrate and enhance current processes, remove bottlenecks, and enable safe experimentation whenever possible.

Job Description

We are seeking a highly skilled and experienced Software Security Engineer to join our Product Security team. The successful candidate will be responsible for ensuring the security of Software Development Life Cycle (SDLC) practices across the organization, from design to deployment.

How will you make an impact?

Software Security Engineer engages with product development teams across the organization and acts as a subject matter expert for providing mentorship related to secure software development practices.

Key responsibilities

As a software security engineer on the Product Security team, you will be responsible for promoting and implementing secure software development lifecycle (SDLC) practices, reviewing software security architecture and code, developing, and maintaining security tools and automation, and mentoring and training other engineers on security topics. You will also collaborate with product teams, security management, and other stakeholders to identify and drive process improvement initiatives and security metrics.

  • Work closely with development teams to identify and mitigate security risks in our software and systems.
  • Implement and maintain security tools and processes to ensure the security of our software development lifecycle.
  • Conduct security assessments and code reviews to identify vulnerabilities and ensure compliance with security standards and best practices.
  • Develop and maintain secure coding guidelines and provide training to development teams.
  • Collaborate with cross-functional teams to ensure the timely and successful delivery of secure software.
  • Promote and implement Secure SDLC practices based on compliance requirements.
  • Review software security practices and architecture as requested by product teams.
  • Mentor and train less experienced team members on technical topics.
  • Develop solutions to automate processes and workflows.
  • Develop and promote automated scanning tools and practices throughout the organization.
  • Identify and drive process improvement initiatives to increase our productivity and/or reduce costs.
  • Lead security tool evaluations and Proof of Concepts to make defensible recommendations on tool acquisition, integration and maintenance plans.
  • Develop metrics and reporting from aggregated sources to assist Software Security Management with remediation prioritization within the company.
  • Contribute to the team's strategy and long-term roadmap.

How will you get here?

Education

  • Bachelor's or Master's degree in Engineering/Computer Science or equivalent work experience.

Experience

We are looking for candidates with 6+ years of experience in software development with a focus on security, including:

  • Experience writing and/or testing software applications; experience with automation.
  • Experience working with container technologies and cloud providers such as AWS.
  • Familiarity with one or more of the following languages: C/C++, Java, .NET, JavaScript, Python, Bash, PowerShell and/or Ruby.
  • Familiarity with one or more development tools such as: Eclipse, Visual Studio, Visual Studio Code, IntelliJ, Git, Jira, Jenkins, and/or Docker.
  • Strong attention to detail, with interpersonal and time management skills.
  • The ability to communicate effectively and professionally with a diverse group of people, including Vice Presidents, Directors, Managers, Developers, Domain Experts.

Knowledge, Skills, Abilities

In addition to the experience requirements, we are looking for candidates with the following:

  • Self-motivated person with an agile attitude
  • A track record of performing application security assessments either via Bug Bounty programs or capture the flag events.
  • Experience with mobile application security a plus.
  • A history of involvement in general information security practice and/or the community.
  • Proficient written and verbal communication in the English language.


  • Shanghai, Shanghai, China ZF Group Full time

    Your tasks Support the implementation of cyber security processes at CVS with the guide of a Cyber Security coach Keep CVS up-to-date regarding cyber security trends and emerging technologies Interacting with customers and suppliers to finalize security concepts Your profile: Major in Software Engineering, Information Engineering, etc Master...


  • Shanghai, Shanghai, China ZF Group Full time

    Req ID 64867 Shanghai, China We are currently expanding our R&D teams and looking for new colleagues who will join our team in Shanghai.Your tasks:Support the implementation of cyber security processes at CVS with the guide of a Cyber Security coach Keep CVS up-to-date regarding cyber security trends and emerging technologies Interacting with customers and...


  • Shanghai, Shanghai, China ZF Group Full time

    Req ID 64867 Shanghai, China We are currently expanding our R&D teams and looking for new colleagues who will join our team in Shanghai.Your tasks:Support the implementation of cyber security processes at CVS with the guide of a Cyber Security coach Keep CVS up-to-date regarding cyber security trends and emerging technologies Interacting with customers and...


  • Shanghai, Shanghai, China ZF Group Full time

    Req ID 64867 Shanghai, China We are currently expanding our R&D teams and looking for new colleagues who will join our team in Shanghai.Your tasks:Support the implementation of cyber security processes at CVS with the guide of a Cyber Security coach Keep CVS up-to-date regarding cyber security trends and emerging technologies Interacting with customers and...


  • Shanghai, Shanghai, China Ford Motor Company Full time

    Focus on Mobile App and Browser-based products' cybersecurity and act as cybersecurity SME Co-lead Vehicle/API Security Operations Center system design, development, deployment, and operations Provide cybersecurity technical services including but not limited to developing cybersecurity specifications, performing threat and risk assessment, performing...

  • Software Engineer

    4 weeks ago


    Shanghai, Shanghai, China Electronic Arts Full time

    Job Title: Software Engineer (Backend Security)-JavaFC Mobile Shanghai Studio is devoted to the development and operation of a high-quality mobile game with top sports IP as a global team. The team also continuously delivers fantastic game experience to global users. The quest for creativity, respect for autonomy, and emphasis on collaboration are at the...

  • Software Engineer

    2 months ago


    Shanghai, Shanghai, China Electronic Arts Full time

    Job Title: Software Engineer (Backend Security)-JavaFC Mobile Shanghai Studio is devoted to the development and operation of a high-quality mobile game with top sports IP as a global team. The team also continuously delivers fantastic game experience to global users. The quest for creativity, respect for autonomy, and emphasis on collaboration are at the...


  • Shanghai, Shanghai, China SAP Full time

    We empower individuals to unleash their full potentialJoining SAP means embracing a culture of teamwork and mutual dedication to improving global operations. Integrating advanced technologies, we strive daily to lay the groundwork for a better future while fostering diversity, flexibility, and purpose-driven work environments. Our collaborative and...

  • Software Engineer 2

    2 weeks ago


    Shanghai, Shanghai, China Microsoft Full time

    Overview Developer Division is an organization focusing on developer tooling and experiences, and application workload experiences. We're looking for a Software Engineer II to join us to develop and deliver the great, consistent and scalable AI tooling products. You will have opportunities to work on AI tooling by leveraging latest Microsoft AI...


  • Shanghai, Shanghai, China RELX Full time

    About the Role The Software Engineering Lead performs complex research, design, and software development assignments within a software functional area or product line, and provides direct input to project plans, schedules, and methodology in the development of cross-functional software products. This Lead performs software design - typically across...


  • Shanghai, Shanghai, China SAP Full time

    We help the world run better At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...


  • Shanghai, Shanghai, China Bose Full time

    You know the moment. It's the first notes of that song you love, the intro to your favorite movie, or simply the sound of someone you love saying "hello." It's in these moments that sound matters most.At Bose, we believe sound is the most powerful force on earth. We've dedicated ourselves to improving it for nearly 60 years. And we're passionate down to our...


  • Shanghai, Shanghai, China Qualcomm Full time

    Company: Qualcomm China Job Area: Engineering Group, Engineering Group > Software Engineering General Summary: As a leading technology innovator, Qualcomm pushes the boundaries of what's possible to enable next-generation experiences and drives digital transformation to help create a smarter, connected future for all. As a Qualcomm Software...


  • Shanghai, Shanghai, China Qualcomm Full time

    Company: Qualcomm China Job Area: Engineering Group, Engineering Group > Software Engineering General Summary: As a leading technology innovator, Qualcomm pushes the boundaries of what's possible to enable next-generation experiences and drives digital transformation to help create a smarter, connected future for all. As a Qualcomm Software...


  • Shanghai, Shanghai, China Mercedes-Benz Full time

    Tätigkeitsbereich:Forschung & Entwicklung incl. DesignFachabteilung:Research & Development SoftwareGesellschaft:Mercedes-Benz Group China Ltd.Standort:Mercedes-Benz Group China Ltd., BeijingStartdatum:sofortVeröffentlichungsdatum:..4Stellennummer:MERRXArbeitszeit:Vollzeit Join usAufgaben Job Objective - Support to manage the security lifecycle activities...


  • Shanghai, Shanghai, China Qualcomm Full time

    Company: Qualcomm China Job Area: Engineering Group, Engineering Group > Software Engineering General Summary: As a leading technology innovator, Qualcomm pushes the boundaries of what's possible to enable next-generation experiences and drives digital transformation to help create a smarter, connected future for all. As a Qualcomm Software...


  • Shanghai, Shanghai, China RELX Full time

    Do you enjoy collaborating with teams to tackle complex technical challenges in the field of employer-employee relations?We are seeking a back-end software engineering Lead in Shanghai, China. Are you up for the challenge?About the Role:The Software Engineering Lead undertakes complex research, design, and software development tasks within a software...


  • Shanghai, Shanghai, China RELX Full time

    About the Role The Consulting/Principal Software Engineer (Python)role performs complex research, design, and software development assignments within a software functional area or product line, and provides direct input to project plans, schedules, and methodology in the development of cross-functional software products. This SWE performs software design...


  • Shanghai, Shanghai, China RELX Full time

    Are you a champion for continuous improvement? Do you enjoy collaborating with teams to solve intricate technical issues in the realm of employer-employee relations? About our Team LexisNexis Legal & Professional serves customers in over 150 countries with 11,300 employees worldwide as part of RELX, a global provider of information-based analytics for...


  • Shanghai, Shanghai, China General Motors Full time

    Job Description Required Qualifications and Experience Bachelor's degree in Computer Science, Information Technology, or a related field. Proven 3 years+ experience as a Software QA Engineer, with globally distributed and large cross-functional teams, with a track record of having developed and performed testingwork (test plan, test cases, test...