Product Security Engineer
All, Maryland, United States of America
Hewlett Packard Enterprise
Discover HPE edge-to-cloud, enterprise compute IT, data, and security solutions. Learn how HPE empowers digital transformation through AI and sustainability.This role has been designated as ‘Remote/Teleworker’, which means you will primarily work from home.
Who We Are:
Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world. Our culture thrives on finding new and better ways to accelerate what’s next. We know diverse backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.
Job Description:
We are looking for a person excited to work at the intersection of software engineering, security, and assurance and trust. HPE Aruba produces a variety of types of software, from embedded firmware to Linux-based appliances to containerized cloud applications, but what these all have in common is a need to build security in from the beginning and to demonstrate to our customers that these products are trustworthy for use in their own environments. This role is part cybersecurity auditor, part consultant, part implementor who can work directly with software engineering teams on how to continually improve security maturity.
Role and Responsibilities:
• Assist in the execution of product compliance assessments against various frameworks (e.g. NIST SP 800-218, SP 800-53, CIS Benchmarks, EU CRA)
• Assist in the development and/or maintenance of GRC and SDLC tooling implementations, including scripting and automation.
• Operate as a representative of HPE Aruba in working groups, with government representatives, and with auditors.
• Provide consulting, information, and advice to product teams around implementing and improving the maturity of our SDLC.
• Document known issues and provide information to product teams in a manner which allows for easy interpretation and corrective actions to be performed.
• Monitor worldwide government standards and communicate to management and product teams when changes are made that may impact an existing control or introduce new requirements.
• Minimal travel (approximately 5-10%) may be required at times.
Qualifications and Education Requirements:
- BS in Information Security, Computer Science, or related technical field.
- A background in software security, either academic or work experience, including reverse engineering, vulnerability classes such as buffer overflows and their prevention, web application security, and/or cloud security.
- Programming knowledge of at least one programming language (e.g. C, Go, Java, Python) with the ability to look at source code and analyze for policy violations. Familiarity with the purpose of tools such as IDEs, compilers, source code revision control systems, and code scanners.
- Minimum 3 years of experience working directly in software engineering or in an adjacent field with exposure to the software engineering environment
- Experience conducting risk assessments, threat modeling, and/or compliance assessments. This includes the application of frameworks such as ISO 27001, NIST CSF, NIST SP 800-218, etc. against various products or infrastructure.
- Experience supporting the integration of security practices through the software development lifecycle. This includes but is not limited to reviewing code, providing secure coding guidance, developing and maintaining SDLC policies, and collaborating effectively with product teams to implement security controls.
Preferred Skills:
- Strong foundation in cybersecurity principles, including knowledge of various attack vectors, vulnerabilities, and security best practice.
- Industry certifications such as CISSP, CISA, CCSP, CSSLP, CGRC, or GIAC are helpful; we will help you obtain these if you don’t have them already.
- Knowledge of relevant regulations and standards and how to interpret and implement these requirements within the organization's products.
- Ability to develop and implement security policies, procedures, and guidelines that align with organizational goals and compliance requirements.
- Technical experience with scripting and automation.
- Experience with participating in or leading external security standards communities or working groups.
- Familiarity with the Agile development methodology.
- Ability to manage security projects, setting priorities, and meeting deadlines as an independent performer.
- Strong communicator with ability to collaborate with various teams.
- Experience with Project Management software (e.g. Jira, Asana, Confluence)
- Experience with the procurement process for IT tools, particularly with product evaluations
Join us and make your mark!
We offer:
• A competitive salary and extensive social benefits
• Diverse and dynamic work environment
• Work-life balance and support for career development
• An amazing life inside the element! Want to know more about it?
Then let’s stay connected!
https://www.facebook.com/HPECareers
https://twitter.com/HPE_Careers
HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT and Affirmative Action employer. We are committed to diversity and building a team that represents a variety of backgrounds, perspectives, and skills. We do not discriminate and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global diverse team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together.
Accommodation of special needs for qualified candidates may be considered within the framework of the HPE Accommodation Policy.
Additional Skills:
Cloud Architectures, Cross Domain Knowledge, Design Thinking, Development Fundamentals, DevOps, Distributed Computing, Microservices Fluency, Full Stack Development, Security-First Mindset, User Experience (UX)What We Can Offer You:
Health & Wellbeing
We strive to provide our team members and their loved ones with a comprehensive suite of benefits that supports their physical, financial and emotional wellbeing.
Personal & Professional Development
We also invest in your career because the better you are, the better we all are. We have specific programs catered to helping you reach any career goals you have — whether you want to become a knowledge expert in your field or apply your skills to another division.
Diversity, Inclusion & Belonging
We are unconditionally inclusive in the way we work and celebrate individual uniqueness. We know diverse backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good.
Let's Stay Connected:
Follow @HPECareers on Instagram to see the latest on people, culture and tech at HPE.
#unitedstatesJob:
EngineeringJob Level:
TCP_03
States with Pay Range Requirement
The expected salary/wage range for a U.S.-based hire filling this position is provided below. Actual offer may vary from this range based upon geographic location, work experience, education/training, and/or skill level. If this is a sales role, then the listed salary range reflects combined base salary and target-level sales compensation pay. If this is a non-sales role, then the listed salary range reflects base salary only. Variable incentives may also be offered. Information about employee benefits offered can be found at https://myhperewards.com/main/new-hire-enrollment.html.
USD Annual Salary: $78,700.00 - $181,200.00Estimated job application period closure is May 2025. While this is the expected application time frame, there are many factors which may result in a change. If this position is still open beyond the anticipated closure time frame, it is likely HPE is still actively recruiting for this role and all qualified and interested candidates are encouraged to apply.HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT and Affirmative Action employer. We are committed to diversity and building a team that represents a variety of backgrounds, perspectives, and skills. We do not discriminate and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global diverse team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: Equal Employment Opportunity.
Hewlett Packard Enterprise is EEO F/M/Protected Veteran/ Individual with Disabilities.
HPE will comply with all applicable laws related to employer use of arrest and conviction records, including laws requiring employers to consider for employment qualified applicants with criminal histories. .
Tags: Agile Application security Asana Automation C CCSP CGRC CISA CISSP Cloud Compilers Compliance Computer Science Confluence CSSLP DevOps Full stack GIAC ISO 27001 Java Jira Linux Microservices NIST NIST 800-53 Product security Python Reverse engineering Risk assessment Scripting SDLC Vulnerabilities
Perks/benefits: Career development Competitive pay Health care
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.