Website Protection Security Engineer

1 month ago


Shanghai, China Thermo Fisher Scientific Full time

Division Specific Information

Discover Impactful Work: As a Website Protection Engineer, you will be part of a distributed team passionate about reducing security findings across the Thermo Fisher Scientific web properties landscape. This group works across Infrastructure, Security and Product Teams to identify solutions and compensating controls that reduce risk faced by our colleagues, customers and partners.

A day in the Life:

Review websites to ensure compliance with corporate standards. Participate in architecture review board meetings to discuss non-compliance issues. Cultivate meaningful relationships across Product, Infrastructure and Security teams to understand level of effort, existing compensating controls and necessary investment to implement critical security controls. Partner with teams to implement solutions to findings reducing the risk to the company and our customers. Working with stakeholders to provide vulnerability remediation guidance across web properties. Participates in incident response activities as necessary. Partner with teams in the remediation of vulnerabilities and risk across a diverse ecosystem that spans traditional, web, infrastructure, and industrial internet of things product landscapes.

Keys to Success:

This person will be able to identify and drive implementation of mitigation relating to security deficiencies, including obtaining buy-in from system owners across teams. This will require a creative, problem-solving approach and can-do demeanor that is continuously learning and challenging norms.

Education

Bachelor's Degree in cybersecurity, computer science, engineering or other relevant field. Equivalent work experience also accepted.

Experience

Experience in developing remediation and solutions for product or infrastructure vulnerabilities. 2+ years’ experience in system, network, and/or web application security. 2+ years’ experience in threat modeling, interpreting vulnerability disclosures or assessing true risk and impact of a publicly disclosed vulnerability.

Knowledge, Skills, Abilities

Solid foundation in web application fundamentals and core security concepts involved in securing and/or hardening web applications. Communicate effectively with engineers, business and executive leaders to assist in clear understanding of requirements and how to secure a variety of environments. Analyzes current offerings for business impact and exposure, based on emerging security threats, vulnerabilities and risks. Knowledge or experience with web application compliance standards or regulatory frameworks. Performing ad-hoc security tests and scans on web properties in support of confirming the validity of vulnerabilities and/or the degree of success in remediation actions. Identifying and reporting on security vulnerabilities, risks, and incidents. Recommending and implementing security patches, fixes, and enhancements. Developing and maintaining security policies, procedures, and documentation. Providing security training and awareness to the IT, development, and content teams. Staying up to date with the latest web security trends, threats, and best practices.

  • Shanghai, China Thermo Fisher Scientific Full time

    Division Specific Information Discover Impactful Work: As a Website Protection Engineer, you will be part of a distributed team passionate about reducing security findings across the Thermo Fisher Scientific web properties landscape. This group works across Infrastructure, Security and Product Teams to identify solutions and compensating controls...


  • Shanghai, China Thermo Fisher Scientific Full time

    Division Specific Information Discover Impactful Work: As a Website Protection Engineer, you will be part of a distributed team passionate about reducing security findings across the Thermo Fisher Scientific web properties landscape. This group works across Infrastructure, Security and Product Teams to identify solutions and compensating controls...


  • Shanghai, Shanghai, China Jensen Hughes Full time

    Company OverviewEstablished in 1939, we have been pioneers in safety, security, and risk-based engineering and consulting, handling some of the most intricate global projects. Our commitment to gaining your trust and safeguarding lives, property, and reputation has been unwavering since our inception. Rooted in history, yet focused on the future, we lead the...


  • Shanghai, China Jensen Hughes Full time

    Company OverviewSince 1939, we have been at the leading edge of safety, security and risk-based engineering and consulting, serving the most complex global projects. In addition, we pride ourselves on driving code and standard development and adoption throughout the world and across industries. We planted our roots with a commitment to earning your trust and...


  • Shanghai, China 0093 eBay Engineering&Research Full time

    Description : eBay’s Software-Defined Security Platform enables adaptive micro-segmentation of applications using a declarative policy model. The platform provides a robust policy language, scalable policy store and role-based access control for the governance of network policies. It also provides a dynamic and declarative enforcement mechanism that...


  • Shanghai, China 0093 eBay Engineering&Research Full time

    Description : eBay’s Software-Defined Security Platform enables adaptive micro-segmentation of applications using a declarative policy model. The platform provides a robust policy language, scalable policy store and role-based access control for the governance of network policies. It also provides a dynamic and declarative enforcement mechanism that...


  • Shanghai, Shanghai, China Kering Investment Management Group Co., Ltd. Full time

    Description SUMMARY This is a newly created position based in Shanghai with primary responsibilities to delivers the Corporate Security mission by implementing and executing programs that maximize business resiliency, ensure cost effective and efficient retail security loss prevention and risk management are designed to safeguard business interests,...

  • Client Engineer

    3 months ago


    Shanghai, China Electronic Arts Full time

    As a client engineer, you will be responsible for ensuring the safety and security of our mobile clients. You will work closely with our software engineering and product teams to create and implement security measures that protect our mobile clients from potential threats and you will report to a Senior Software Engineer or Technical Director. Job location:...

  • Client Engineer

    4 weeks ago


    Shanghai, China Electronic Arts Full time

    As a client engineer, you will be responsible for ensuring the safety and security of our mobile clients. You will work closely with our software engineering and product teams to create and implement security measures that protect our mobile clients from potential threats and you will report to a Senior Software Engineer or Technical Director. Job location:...


  • Shanghai, Shanghai, China SAP Full time

    We help the world run better At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...


  • Shanghai, China SAP Full time

     We help the world run better At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...


  • Shanghai, China SAP Full time

     We help the world run better At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...


  • Shanghai, China SAP Full time

     We help the world run better At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...


  • Shanghai, China SAP Full time

     We help the world run better At SAP, we enable you to bring out your best. Our company culture is focused on collaboration and a shared passion to help the world run better. How? We focus every day on building the foundation for tomorrow and creating a workplace that embraces differences, values flexibility, and is aligned to our purpose-driven and...

  • Client Engineer

    3 days ago


    Shanghai, China Electronic Arts Full time

    Responsibilities You will develop and implement security protocols for mobile applications. You will collaborate with software engineers to ensure the integration of security into all phases of software development. You will implement encryption and secure data storage solutions. You will document any security breaches and assess their damage. ...

  • Security Engineer

    2 months ago


    Shanghai, China Donaldson Full time

    Donaldson is committed to solving the world’s most complex filtration challenges. Together, we make cool things. As an established technology and innovation leader, we are continuously evolving to meet the filtration needs of our changing world. Join a culture of collaboration and innovation that matters and a chance to learn, effect change, and make...


  • Shanghai, China Coca Cola Full time

    Description Summary: The Security Engineer will directly support organization-wide initiatives in delivering Security solutions in Greater China, and responsible for designing and implementing secure cloud computing solutions. You should have broad experience with IT security technologies and operations including but not limited to, endpoint...


  • Shanghai, Shanghai, China Thermo Fisher Scientific Full time

    Job DescriptionWhat we doThe Product Security team is a group of Builders, Breakers, and Fixers that specialize in collaborative security engagement. The goal of the Software Security (DevSecOps) team is to provide self-service security and to that end, the team is focused on enabling the 3 Ways of DevOps: Fast Flow, Rapid Feedback, and Continuous Learning....


  • Shanghai, China Thermo Fisher Scientific Full time

    Job DescriptionWhat we doThe Product Security team is a group of Builders, Breakers, and Fixers that specialize in collaborative security engagement. The goal of the Software Security (DevSecOps) team is to provide self-service security and to that end, the team is focused on enabling the 3 Ways of DevOps: Fast Flow, Rapid Feedback, and Continuous Learning....


  • Shanghai, China Thermo Fisher Scientific Full time

    Software Security Engineer engages with product development teams across the organization and acts as a subject matter expert for providing mentorship related to secure software development practices. Key responsibilities As a software security engineer on the Product Security team, you will be responsible for promoting and implementing secure...