Product Security Engineer
When you join Verizon
Verizon is one of the world’s leading providers of technology and communications services, transforming the way we connect across the globe. We’re a diverse network of people driven by our shared ambition to shape a better future. Here, we have the ability to learn and grow at the speed of technology, and the space to create within every role. Together, we are moving the world forward – and you can too. Dream it. Build it. Do it here.
What you’ll be doing...
As a product security engineer, you will work to conduct security assessments on both Consumer and Business products and solutions. You will help to create, define, and implement security controls and tooling in conjunction with product development teams and product owners. You will manage multiple projects with a degree of impact and complexity that must be carefully controlled to support the internal business unit security requirements.
You will also work in conjunction with security stakeholders in other areas of the business and make decisions and help lead initiatives to ensure timely delivery of security solutions that support business objectives.
You will also manage work that involves coordination with multiple organizations and is the focal point within the group.
You will often work with little or no supervision, and will regularly be given high-level directives and allowed to work independently to satisfy the requirements.
- Helping implement Secure Software Development Lifecycle (SSDLC) practices and using automation where possible.
- Working with the product teams to perform security design/code reviews and vulnerability assessment.
- Providing security guidance to Engineering and Product teams.
- Building threat models and conducting risk assessments for new features and services.
- Creating application threat models and providing guidance on effective countermeasures.
- Contributing to security architecture and assisting in building and rolling out processes for secure code development and deployment involving truly cutting edge technology.
- Providing subject matter expertise on encryption, security controls, and secure design and programming practices across the Technology organization.
- Contributing to security policy, standards, and guidelines related to Information Security.
- Evaluating and operationalizing new technologies for securing the organization.
- Training and mentoring Security Champions throughout the development.
- Sharing thought leadership in the product and application security space.
- Creating security user stories and security test cases for products that are tailored to the product attributes and technology.
- Supporting and advising product owner and product development teams by ensuring technical and architectural feasibility, readiness and compliance.
Where you'll be working...
In this hybrid role, you'll have a defined work location that includes work from home and assigned office days set by your manager.
What we’re looking for...
You'll need to have:
- Bachelor's degree or four or more years of work experience.
- Six or more years of relevant work experience.
- Four or more years of technical experience such as in application development or security.
- Five years of professional experience with any combination of at least three technical disciplines, including the following: cloud security, application security, mobile security, secure development methodologies, software development and coding.
Even better if you have one or more of the following:
- Bachelor's degree in Computer Science, Software Engineering, Security, or other OR a relevant combination of education, training, and experience.
- Three years of experience building or reviewing threat models.
- Four years of experience with conducting security assessments.
- Knowledge of application security vulnerabilities, secure coding, and countermeasures.
- Written and verbal skills for communicating security concepts and solutions.
- Ability to prioritize between and execute on multiple work streams.
- Experience with application programming and the overall software development life cycle.
- Strong organizational and interpersonal skills.
- Experience with secure SDLC, governance and compliance for PCI, FedRAMP and NIST.
If Verizon and this role sound like a fit for you, we encourage you to apply even if you don’t meet every “even better” qualification listed above.
Equal Employment Opportunity
We're proud to be an equal opportunity employer - and celebrate our employees' differences, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, and Veteran status. At Verizon, we know that diversity makes us stronger. We are committed to a collaborative, inclusive environment that encourages authenticity and fosters a sense of belonging. We strive for everyone to feel valued, connected, and empowered to reach their potential and contribute their best. Check out our diversity and inclusion page to learn more.