Product Solution & Security Engineer

extra holidays - extra parental leave
Work set-up: 
Full Remote
Contract: 
Experience: 
Senior (5-10 years)
Work from: 

Offer summary

Qualifications:

7+ years of experience in cloud security architecture in enterprise environments., At least 3+ years of experience with security tools like Coverity or SonarQube., Expertise in secure architecture, implementation, or testing., Proficiency in scripting languages such as Python, JavaScript, or TypeScript..

Key responsibilities:

  • Guide project teams in security activities throughout the product lifecycle.
  • Collaborate with developers to validate application security measures.
  • Enhance and maintain the security posture of products in a cloud environment.
  • Lead security reviews, threat modeling, and automation efforts.

Dotmatics logo
Dotmatics SME http://www.dotmatics.com/
501 - 1000 Employees
See all jobs

Job description

Our Why At Dotmatics 

At Dotmatics, we believe science, data, and decision-making must be deeply intertwined for innovation to thrive. 

Our Portfolio includes Luma, LumaLab Connect, ELN Platform, Graphpad Prism, Geneious, SnapGene, Protein Metrics, OMIQ, FCS Express, LabArchives, NQuery, EasyPanel, MStar, SoftGenetics and Virscidian.

We have a vision for a new Lab of the Future that will change the future of scientific research.

We have created the world’s most comprehensive digital science platform – best-of-breed software applications already used by more than 2 million scientists, together in a single ecosystem united by a powerful, flexible enterprise data platform. This is not flat data buried away in digital graveyards. This is dynamic, multi-dimensional decision-making.

Scientific enterprises need a new level of effectiveness to achieve tomorrow’s breakthroughs. Illness will not wait. The biosphere will not wait. We are tireless in our vision, because the time for innovation is now.

Shaping the Future of Science At Dotmatics 

Our global team of more than 800 colleagues are dedicated to supporting our customers in over 180 countries. Together, with our scientific community of users, we accelerate scientific innovation in order to make the world a healthier, cleaner, and safer place to live.

You’ll join a collaborative, global team pushing the boundaries of scientific innovation.  Your ideas and efforts will have a tangible impact, accelerating scientific progress and discovery. We offer a dynamic, remote-friendly environment that fosters high integrity and collaboration, empowering you to excel. Dotmatics is a company built by scientists, for scientists. Combined, we are now the world’s largest cloud-based scientific research R&D platform. We need your help to keep growing and pioneering the future.

 

We are Science Driven. We are Customer Centric. We are Better Together. 

 

Your Opportunity to Make an Impact

As the Product Solution & Security Engineer will be responsible for providing technical expertise to enhance the security of our products throughout their lifecycle. This role involves working closely with our developer teams and Product Solution Security Officer. It plays an important role to ensure that every step of the software development and operation lifecycle (SDLC) complies with industry, Dotmatics, Siemens Digital Industries Software Product Solution Security standards, and implements best practices for product security. We are committed to delivering high-quality products and services to our customers while ensuring the highest standards of security and privacy.

In this role you’ll get to: 

  • Be responsible for guiding project teams in executing the Product Solution Security (PSS) related activities.
  • Provide technical expertise about Product Solution Security (PSS). 
  • Work with developers to provide repetitive validation of application security measures.
  • Experience building controls in a 100% cloud-based infrastructure
  • Build relationship and Security knowledge effectively across multiple internal departments and Customer teams. Demonstrating strong technical acumen and leadership to align security practices across diverse business units, while considering differing seniority and technical and non technical audiences 
  • Continually enhance and strengthen product’s application security posture.
  • Provide subject-matter expert (SME) level input on secure coding, architecture, and automation.
  • Lead and support application security efforts, such as security/code reviews and threat modelling.

We’re looking for people who have 7+ years of experience with the design and development of cloud security architectures in an enterprise-scale environment,  with at least 3+ years’ experience in setting up Coverity or SonarQube or other SAST tools and auditing security findings. You will demonstrate excellent communication and presentation skills and the ability to lead and coach both junior security engineers and non security developers to improve their skills and effectiveness.

The key skills we are looking for:

  • Expert knowledge  in at least two of the following areas: Secure Architecture and Design, Secure Implementation, Secure Project Integration, Secure Services, and Security Testing.
  • Advanced skills in developing automation with at least one scripting languages such as Go, TypeScript, JavaScript or Python
  • Advanced knowledge of  AWS, GCP, or VMware implementations.  Azure experience may be considered 
  • Expert understanding of designing and applying vulnerability assessments, application penetration testing, and a solid understanding of network and web protocols.
  • Advanced experience in Identifying information security risks through source code review and secure interaction between code, libraries, languages, APIs, database, and core platform infrastructures (e.g. Tomcat, Java). 
  • Project Management: Leading multiple work streams/projects across a wide range of products
  • Modern techniques of secure networking and communications in public cloud environments.
  • Full Stack Software development experience: C/C++, Java, Node JS, Typescript, React.  is a plus.
  • Hands-on experience in automation techniques in DevSecOps, e.g. how to integrate and automate SAST/DAST/SCA tools in the SDLC process and serve as a tool-smith for the dev teams.
  • Cloud environments and containerization technologies (such as Kubernetes) and modern microservice design principles.

You may also have:

  • BA or BS degree Computer Science,  Systems Analysis, or a related field
  • Working knowledge of cloud computing technologies business drivers and emerging computing trends
  • Working knowledge of business process reengineering principles and processes

 

Research shows us the confidence gap and imposter syndrome can get in the way of meeting outstanding candidates, so please don’t hesitate to apply — we’d love to hear from you.

By submitting your application, you agree that Dotmatics may collect your personal data for recruiting, global organization planning, and related purposes. Dotmatics Privacy Notice explains what personal information we may process, where we may process your personal information, our purposes for processing your personal information, and the rights you can exercise over Dotmatics use of your personal information. 

Dotmatics is an equal opportunity employer. We are a welcoming place for everyone, and we do our best to make sure all people feel supported and connected at work.

Required profile

Experience

Level of experience: Senior (5-10 years)
Industry :
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Presentations
  • Coaching
  • Communication
  • Leadership

Security Engineer Related jobs