Job Information
Insight Global Senior Cybersecurity Engineer in Chicago, Illinois
Job Description
You will be responsible for delivering a suite of security services according to internal processes and standards, including:
Security Defect Management - Analyzing, validating, communicating, and consulting on security defects identified by both automated and manual sources such as CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty, etc. In other words, our security engineers are partners to software engineers who require accurate information on why a vulnerability exists and what they can do about it.
Tool Enablement - Enabling and monitoring automated defect detection tooling (CodeQL, Rapid7, etc.) at the repository or application level according to established process.
Security Test Onboarding & Management Collecting and communicating required scope and access information for penetration testing and security assurance assessments, as well as handling the output of these assessments via our Defect Management Process.
Maturity Measurement Consulting with software engineers on practices which will improve their applications security maturity according to scorecards and maturity models established by Cat Digital.
Correction of Error Authoring, in close partnership with software engineers, correction of error reports which help engineers and architects across Cat Digital avoid similar mistakes in their own applications.
This role is an excellent opportunity for an experienced software engineer with a passion for cybersecurity to move to a full-time cybersecurity role and help their fellow software engineers deliver solutions securely.
Interaction with team:
- Working with the team lead. 4 FTE and 3 agency workers on team.
Work environment:
- Hybrid work model
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to HR@insightglobal.com .
To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: https://insightglobal.com/workforce-privacy-policy/ .
Skills and Requirements
- 5+ years of experience as a software engineer (in any language or framework) or software engineering manager
- 5+ years of experience as a software development-focused cybersecurity professional
- 5+ years of experience working on a major cloud platform (AWS, Azure, GCP, or Salesforce) as a software engineer, cloud/DevOps engineer, security engineer, or architect.
- 1. Experience analyzing and remediating security findings from automated and manual sources such as Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), penetration testing, Software Composition Analysis (SCA), etc.
- Experience leveraging one or more of the following resources to support secure coding and decision-making: OWASP Top 10, MITRE Common Weakness Enumeration (CWE) Top 25, OWASP Application Security Verification Standard (ASVS) and Other industry-standard best practice guides or frameworks
- Experience building or supporting web applications and APIs including Single Page Applications (SPA) and RESTful APIs.
- Proficiency in one or more programming languages.
- Decision-Making Ability Our engineers make sound, justifiable, customer-first decisions to determine which security issues to raise to software engineers/leaders and support work prioritization decisions.
- Strong Communication Our engineers relate complex technical concepts to non-technical audiences and technical audiences without a security background. Additionally, the Cat Digital team spans the globe, and our engineers must collaborate effectively with engineers from a number of locations and cultural backgrounds.
- Active Participation Software engineering is not a spectator sport. The input and experience our engineers bring to the table are valued and should be shared freely. Similarly, engineers are relied upon to complete complex assignments at a high level of quality with limited supervision.
(Desired)
- 1. Professional certifications in either cybersecurity or software engineering, such as: Associate or Professional-level certifications from a major cloud provider (AWS, Azure, GCP, or Salesforce), CompTIA Security+, Cloud+, etc., ISC2 Certified Software Lifecycle Professional (CSLP)
- Background in problem identification, root cause analysis, and process improvement.
- Excellent writing abilities and experience writing technical analysis and reports for consumption by software engineers, architects, and managers.
- Experience as a software or security engineer as an employee or contractor of a Fortune 500 company.
-
- Experience as a software or security engineer on eCommerce, device telematics, data analytics, or mobile applications.
- Bachelors degree (or equivalent) in Computer Science, Software Engineering, Cybersecurity, Electrical Engineering, or a related discipline. null
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion,sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military oruniformed service member status, or any other status or characteristic protected by applicable laws, regulations, andordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to HR@insightglobal.com.
Insight Global
-
- Insight Global Jobs