Principal Application Security Engineer
Ottawa, ON, Canada
Full Time Senior-level / Expert USD 146K - 167K
Barracuda Networks Inc.
Barracuda Networks is the worldwide leader in Email Protection, Application Protection, Network Security, and Data Protection Solutions
Job ID 25 - 618 (2)
Come join our passionate team! Barracuda is a leading cybersecurity company providing complete protection against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR service, to strengthen cyber resilience. Hundreds of thousands of IT professionals and managed service providers worldwide trust us to protect and support them with solutions that are easy to buy, deploy, and use.We know a diverse workforce adds to our collective value and strength as an organization. Barracuda Networks is proud to be an Equal Opportunity Employer, committed to equal employment opportunity and equitable compensation regardless of race, gender, religion, sex, sexual orientation, national origin, or disability.
Envision yourself at BarracudaThe Principal Application Security Engineer assures the safety and security of Barracuda Networks software and services through source code review, manual application security assessment, operation and integration of automated security assessment solutions, architecture review, and expert advice regarding software security trends, threats, best practices and incidents. Through assuring the safety and security of Barracuda Networks software and services, the Application Security Engineer helps to keep our customers and their data safe and secure. Tech Stack Exposure
Come join our passionate team! Barracuda is a leading cybersecurity company providing complete protection against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR service, to strengthen cyber resilience. Hundreds of thousands of IT professionals and managed service providers worldwide trust us to protect and support them with solutions that are easy to buy, deploy, and use.We know a diverse workforce adds to our collective value and strength as an organization. Barracuda Networks is proud to be an Equal Opportunity Employer, committed to equal employment opportunity and equitable compensation regardless of race, gender, religion, sex, sexual orientation, national origin, or disability.
Envision yourself at BarracudaThe Principal Application Security Engineer assures the safety and security of Barracuda Networks software and services through source code review, manual application security assessment, operation and integration of automated security assessment solutions, architecture review, and expert advice regarding software security trends, threats, best practices and incidents. Through assuring the safety and security of Barracuda Networks software and services, the Application Security Engineer helps to keep our customers and their data safe and secure. Tech Stack Exposure
- A deep understanding of software security best practices and vulnerabilities, especially as they relate to web applications (e.g. OWASP Top 10)
- Experience identifying vulnerabilities in software and SaaS services
- Experience in source code review, preferably for Python, PHP and Go
- Experience in scoping and performing manual application penetration testing
- Experience in assessing the risk of identified vulnerabilities, and providing correct, robust and actionable recommendations to mitigate and/or resolve the vulnerabilities
- Experience in understanding software vulnerabilities, in finding other instances of the vulnerability across codebases, and in identifying collateral/related vulnerabilities.
- Experience in assessing the implemented resolution of a vulnerability for completeness and accuracy, and identifying bypasses for the implemented resolution
- Experience in working collaboratively with software development teams to identify vulnerabilities in all stages of software development
- Experience in communicating effectively with people of varying security proficiency and interest (fellow security professionals, engineering, and management)
- The ability to coordinate and participate in wide-scale Software Incident Security Response exercises such as the log4j response, understanding and unpacking information as incidents unfold, and in working across the organization to deliver a comprehensive "Identify, Resolve, Validate" solution
- Basic programming experience in at least one language, preferably Python or Go, and experience in automating routine tasks such as searching source code and manipulating data.
- Ensure the secure delivery of software from design through to implementation
- Maintain awareness of software security trends, incidents, and best practices, and provide expert advice and guidance to engineering teams regarding secure development and vulnerability remediation.
- Manage Barracuda’s bug bounty programs
- Work collaboratively with the organization, including with Security, Compliance and Engineering, to understand and remediate computer and software security incidents
- Evaluate new and emerging security technologies, features, and products.
- 7+ years of experience
- The ability to perform source code review in new and unfamiliar languages using knowledge of security best practices and a willingness to read documentation
- Solutions architecture review experience, and the ability to identify opportunities and vulnerabilities early in the specification and development of software
- Threat modelling experience
- Fuzzing experience
- Experience using and integrating automated software security scanners such as SAST/DAST/SCA
- An understanding of Infrastructure as Code and cloud platform security (preferably Azure and AWS)
- An understanding of identity, authentication and authorization protocols including OAuth/OpenID Connect and SAML
- Published examples of work such as original research, vulnerability advisories, conference talks, bug bounty writeups or CTF writeups
- The ability to identify opportunities for process improvement, including automation and the authorship of software (scanners, fuzzers, helper utilities etc.)
- Experience participating in and/or managing bug bounty programs
- Experience with and/or a willingness to collaborate with other security functions such as compliance and policy, network/corporate security, security monitoring and incident response
Job stats:
0
0
0
Categories:
AppSec Jobs
Security Engineering Jobs
Tags: Application security Automation AWS Azure Cloud Compliance CTF DAST Incident response Monitoring OpenID OWASP Pentesting PHP Python SaaS SAML SAST Security assessment Vulnerabilities XDR
Perks/benefits: Career development Equity / stock options Gear
Region:
North America
Country:
Canada
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.
Information Security Officer jobsSenior Security Analyst jobsInformation System Security Officer jobsSenior Cybersecurity Engineer jobsSystems Engineer jobsSenior Cloud Security Engineer jobsInformation Security Manager jobsSystems Administrator jobsSenior Network Security Engineer jobsSenior Information Security Analyst jobsCyber Security Specialist jobsIT Security Engineer jobsChief Information Security Officer jobsSecurity Specialist jobsIT Security Analyst jobsSecurity Consultant jobsInformation System Security Officer (ISSO) jobsInformation Systems Security Engineer jobsSenior Cyber Security Engineer jobsCyber Threat Intelligence Analyst jobsSecurity Operations Analyst jobsSenior Information Security Engineer jobsThreat Intelligence Analyst jobsSenior Product Security Engineer jobsCyber Security Architect jobs
GDPR jobsSaaS jobsEncryption jobsSplunk jobsSQL jobsBash jobsEDR jobsMalware jobsTop Secret jobsThreat detection jobsFinance jobsSDLC jobsIDS jobsRMF jobsForensics jobsTerraform jobsIPS jobsDocker jobsITIL jobsIntrusion detection jobsCompTIA jobsActive Directory jobsSOC 2 jobsOWASP jobsDoDD 8570 jobs
CRISC jobsSAP jobsGIAC jobsUNIX jobsAnsible jobsHIPAA jobsSANS jobsCCSP jobsOSCP jobsVPN jobsTCP/IP jobsBanking jobsJira jobsIT infrastructure jobsJavaScript jobsMITRE ATT&CK jobsSOX jobsSOAR jobsMachine Learning jobsIndustrial jobsData Analytics jobsClearance Required jobsVMware jobsPolygraph jobsNIST 800-53 jobs