Jobs

Senior Product Security Engineer

Strength in Trust  

At OneTrust, we exist to unlock every company's potential to thrive by doing what's good for people and planet. Using cutting-edge technology and a real-world approach to privacy, GRC, ethics, and ESG, we’ve created a no-nonsense platform to help supercharge the global push for Trust Intelligence. 

The Challenge

We are seeking an experienced Senior Product Security Engineer to join our growing product security team. In this role, you will be responsible for ensuring the security and protection of our company's applications and systems. You will work closely with our development teams to provide guidance and support on security best practices and to assess the security of new and existing applications. The successful candidate will have a deep understanding of container security and experience implementing security measures in a continuous integration and continuous deployment (CICD) environment. This is a critical role responsible for ensuring the security and integrity of our company's applications and systems.

Your Mission

  •        Conduct manual penetration testing, Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), and Software Composition Analysis (SCA) to identify vulnerabilities and security risks in the Software Development Life Cycle (SDLC).
  •        Collaborate with development teams to remediate vulnerabilities and implement security improvements.
  •        Develop security standards and guidelines to ensure the secure design and development of applications.
  •        Stay up to date with emerging security threats and technologies and advise on appropriate mitigation strategies.
  •        Evaluate and implement security controls for CICD pipelines.
  •        Conduct security assessments of applications and infrastructure.
  •        Develop and maintain security documentation, including standards and procedures.
  •        Collaborate with development teams to integrate security into the software development life cycle.
  •        Lead the design and implementation of secure container-based infrastructure.
  •        Stay current on industry best practices and emerging threats in container security.
  •        Provide specialized assistance to internal incidents team to effectively respond to application related security incidents
  •        Mentor junior members of the security team.
  •        Mentor and educate other team members on security best practices and techniques.

You Are

  •        Bachelor's degree in computer science, Information Systems, or related field.
  •        A minimum of 5 years of experience in application security, with a focus on container security.
  •        Experience working with security tools such as Burp Suite, Nessus, and Qualys.
  •        At least 5 years of experience in application security, with a focus on manual penetration testing and security testing tools such as DAST, SAST, and SCA.
  •        Strong understanding of containerization technologies such as Docker, Kubernetes.
  •        Knowledge of programming languages such as Java, Python.
  •        Experience with CICD tools such as Jenkins, Azure DevOps and CircleCI.
  •        Knowledge of security concepts such as network security, access controls, encryption, and vulnerability management.
  •        Strong understanding of web application security concepts, OWASP Top 10, and security standards such as PCI-DSS and ISO 27001.
  •        Working knowledge of Web Application Firewall (WAF).
  •        Strong interpersonal and communication skills, with the ability to explain technical security concepts to non-technical stakeholders.

Benefits

As an employee at OneTrust, you will be a part of the OneTeam. That means equity, bonuses, unlimited PTO, and 100% paid medical benefits (and that’s just the beginning!).  

Our employee rewards philosophy spans mental, physical, and emotional well-being because we want our people to succeed both in and out of the office. Some benefits differ depending on region, but here’s what you can expect from our OneTeam Total Rewards Program: 

  • Competitive Compensation: We offer top pay for top talent with competitive total packages including equity for all, performance bonuses, and retirement savings with match. We’re also committed to fair and equitable pay practices. 
  • Workstyle Flexibility: At home or in the office, we trust you to get the job done. Our people have the option to work in the office, fully remote, or a hybrid based on their role. Go green with commuter program discounts and in-office perks.  
  • Career Development: You’re not just joining any company; you’re joining the company that built the category-defining software platform for trust. You can become an expert and earn industry certifications with training and exams paid for by us and access to our learning & development program and guest speaker series.  
  • Employee Recognition: We celebrate our accomplishments the best way we know how – together. Our people are invited to attend employee appreciation social events (including our awesome annual holiday party), participate in ticket giveaways for local city events based on your home office location, and celebrate one another through our #CheersforPeers channel. 
  • Focus on Wellbeing: Take the vacation or volunteer - we have unlimited PTO globally. You’ll also have access to ClassPass memberships, generous company holidays and your birthday off, paid sick days, Employee Resource Groups (or, as we call them, Employee Trust Groups), and other ways to get connected or support company diversity, equity, and inclusion goals.  
  • Health Benefits: No package is complete without great health benefits. This role may receive company-paid employee healthcare premiums, parental leave, and access to mental health benefits and employee assistance programs. Specific benefits differ by location, so please check with your recruiter to specify what this role will receive. 

Our Commitment to You

When you join OneTrust you are stepping onto a launching pad — the countdown has begun. The destination? A career without boundaries working alongside a diverse and inclusive crew who is passionate about doing meaningful work. As a pioneer, your voice and expertise will help chart the direction of an entirely new industry — Trust. Our commitment to putting people first starts with you. Your growth is part of the mission. Our goal is to give you the power to embark on the next phase of your uniquely, unique career.

OneTrust provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

For California, Colorado, Connecticut, Nevada, New York, Rhode Island, and Washington-based candidates: the annual base pay range for this role is listed below. Within this range, individual pay is determined by several factors, including location, job-related skills, work experience, and relevant education and/or training. This role may also be eligible for discretionary bonuses, equity, and/or commissions, as well as benefits.

Salary Range$107,750—$143,675 USD

Resources  

Check out the following to learn more about OneTrust and its people: 

  • OneTrust Careers on YouTube
  • Your Ultimate Guide to Careers at OneTrust
  • @LifeatOneTrust on Instagram

Cyber Security Jobs by Category

Cyber Security Salaries