Sr. Product Security Engineer

Betterment Betterment · Fintech · New York, NY · Engineering

Senior Product Security Engineer at Betterment, a fintech company. This role focuses on building tools and improving the security of systems within a highly regulated environment. Responsibilities include leading security initiatives, writing and reviewing code for security concerns, conducting threat modeling, architecture reviews, and offensive security engagements. Requires 5+ years of software building experience, deep understanding of web app security, experience with exploiting and fixing vulnerabilities, and securing AWS cloud infrastructure.

What you'd actually do

  1. Lead and collaborate on product security initiatives strengthening our engineering practices
  2. Write and review customer facing code to resolve security concerns alongside product development engineers
  3. Conduct threat modeling exercises, architecture reviews, and offensive security engagements with product teams
  4. Innovate with modern cloud technologies to secure systems such as CI/CD, sensitive data storage, mobile design, front end web services, and more
  5. Provide mentorship and education for security and software engineering excellence

Skills

Required

  • 5+ years of experience building software
  • Deep experience and understanding of securing modern web apps (OWASP top 10, CWEs, and language specific application security issues)
  • Experience working in a product setting where the needs of the business and users must be weighed against security requirements
  • Experience with exploiting common security vulnerabilities and fixing them
  • Experience building high-availability distributed systems and services with any Object Oriented Programming language
  • Experience with the Linux command line interface
  • Experience with securing AWS cloud infrastructure (EC2, RDS, S3, VPCs)

Nice to have

  • GraphQL
  • React
  • CircleCI
  • Kubernetes
  • Terraform
  • Postgres

What the JD emphasized

  • highly regulated and secure environment
  • security requirements