25 days ago
Remote, United StatesStaff+
Base Salary
$177k - $225k/yr
Responsibilities
- Lead cross-functional projects and establish secure development lifecycle practices.
- Direct security design reviews and threat modeling for new and existing services.
- Evaluate, prototype, implement, and operate security-focused tools and services, including DAST, SAST, and SCA solutions.
- Create secure architecture standards, frameworks, and patterns across multiple application layers.
- Analyze emerging security threats and implement centralized mitigations.
- Drive security assessments, penetration testing, and bug bounty programs.
- Participate in security incident response.
- Define product security capabilities with global development teams and partner with senior leaders on company-wide security initiatives.
- Support application security training, security champions, awareness campaigns, and security team growth.
Requirements
- Bachelor’s degree in Computer Science or Engineering, or equivalent experience.
- 10+ years of technical security leadership experience at a top-tier software company.
- Experience with security products, threat modeling, security design, security architecture, cryptography, mobile security, and cloud computing technologies.
- Strong understanding of application and infrastructure vulnerabilities and mitigations, including OWASP Top 10 and CWE.
- Proficiency implementing Secure Development Lifecycle processes, technology, and automation in a DevOps environment.
- Experience with large-scale web applications and microservices, including API design, access management, authorization, authentication, data protection, and encryption.
- Knowledge of major programming languages and frameworks such as Python, C# .NET, JavaScript, Node.js, and Java.
- Experience in supply chain security.
- Preferred experience with Cloudflare security, AWS VPCs, EC2 instances, and Docker.
- Ability to use data to drive decisions, deliver KPIs, contribute to the security community, and attract and hire strong talent.
Benefits
- Fully remote role within the United States.
- Candidates must reside in the Pacific Standard time zone.
- iHerb offers equal employment opportunities and prohibits discrimination and harassment.
