Senior Security Engineer, Application Security
Trail of BitsFull Time
Senior (5 to 8 years)
Candidates must possess a Bachelor's degree in Computer Science, Information Security, or Business Information Management, or equivalent work experience, along with over 5 years of experience in information security, application security engineering, or cybersecurity consulting. Deep expertise in Application Security Testing (AST) tools such as SAST, DAST, SCA, SBOM analysis, and Mobile AST is required, as is strong experience integrating security into CI/CD pipelines using tools like GitHub Actions and Jenkins. Proficiency in Python scripting, API development, and working with various data types is essential, along with hands-on experience with SQL, NoSQL, MongoDB, and Databricks, and a solid understanding of ETL fundamentals and API-based data ingestion. Familiarity with cloud-native and serverless architectures, including AWS services, knowledge of threat modeling and secure design review methodologies, and the ability to communicate effectively with technical and executive audiences are also necessary. Strong analytical and problem-solving skills, the ability to lead cross-functional collaboration, and adaptability to evolving threats are crucial. Preferred qualifications include security certifications like CISSP, CSSLP, CCSP, CISM, or CRISC.
The Senior Information Security Engineering Consultant will collaborate with engineering, data, and product teams to integrate secure development practices and deliver security metrics. Responsibilities include designing and implementing cybersecurity metrics (KPIs/KRIs) to measure control effectiveness, building centralized reporting capabilities, and integrating metrics into dashboards using Tableau, PowerBI, and Databricks. The role involves analyzing large datasets to identify trends and insights, collaborating with global engineering and DevOps teams to integrate security tooling into CI/CD pipelines, and preparing executive-level reports on security posture and risk trends. Additionally, the consultant will maintain documentation and process repositories to support compliance and continuous improvement, and stay current with industry trends and regulatory requirements.
Designs and sells athletic footwear and apparel
Nike designs, manufactures, and sells a variety of footwear, apparel, equipment, and accessories aimed at athletes, fitness enthusiasts, and everyday consumers. Their products are created to be stylish and performance-oriented, catering to the needs of a diverse clientele. Nike operates through multiple sales channels, including retail stores, online platforms, and third-party retailers, and enhances its brand image through endorsements from well-known athletes and sports teams. A key aspect of Nike's approach is its membership program, which offers exclusive access to products and content, fostering a deeper connection with consumers. Unlike many competitors, Nike places a strong emphasis on sustainability and corporate responsibility, integrating these values into its operations and product development. The company's goal is to continue growing by creating products that resonate with consumers while promoting positive social and environmental impact.