The Lead Product Security Engineer position within the Asset and Wealth Management division is responsible for defining and evaluating solutions to improve overall cybersecurity risk posture of the firm. This role is pivotal in balancing commercial objectives with robust security controls, ensuring the division's resilience against an evolving threat landscape, and protecting client assets and data.
Requirements
- 6+ years' experience in secure architecture design, application security, and risk analysis techniques or related fields.
- Energetic, self-directed and self-motivated, able to build and sustain long-term relationships with colleagues.
- Must have experience managing multiple tasks and using sound judgment when managing risks, prioritizing and escalating.
- Must be able to work with deeply technical engineers, identify gaps that need addressing, and hold them to account.
- Security testing methodologies, tools and techniques - understanding of common application security vulnerabilities and controls to remediate.
- Expert knowledge of application security best practices including OWASP and CWE and cloud related concepts
- Hands-on software development and/or application Penetration Testing experience in complex environments an advantage
- Strong desire to learn and contribute solutions and ideas to a broad team.
- Experience with leveraging AI/ML to solve security problems and scale operations.
- Knowledge of secure coding languages (e.g., Python, Java, Go).
- Cloud related experiences
- CSSLP / CISSP / CCSP / OSCP is a plus
Benefits
- Comprehensive benefits package
- Competitive salary and bonus
- Generous paid time off
- 401k Matching
- Retirement Plan
- Visa Sponsorship
- Four Day Work Week
- Generous Parental Leave
- Tuition Reimbursement
- Relocation Assistance