Senior Security Engineer
Role details
Job location
Tech stack
Job description
Do you have the ability to become the subject matter expert in implementation of security throughout the software delivery life cycle and a drive to grow your skills in a collaborative environment? Became a part of the ASSA ABLOY Global Solutions Key and Asset Management business unit and enjoy a culture that empowers you to build a career you can be proud of., As a Senior Security Engineer you will be responsible for evolving the software development lifecycle to support a secure-by-default design that incorporates robust cyber security risk analysis and resolution. Reporting to the DevOps Lead, you'll help define security testing requirements, implement policy-as-code solutions, and integrate threat detection and gating into CI/CD pipelines to ensure secure and reliable software delivery. This role is currently completely remote from the UK.
You would also:
- Attest the cyber security posture across a wide range of areas including Embedded devices, Cloud infrastructure, and Mobile applications, while continuously deepening your understanding of our product platforms to tailor security strategies effectively.
- Implement and maintain Security Posture Management in line with best practices across multiple areas.
- Assist in fostering a security-first culture across development teams and the SDLC.
- Lead the implementation of remediation efforts for identified risks and vulnerabilities, including patch management.
- Collaborate on threat modeling exercises within development and DevOps teams.
Requirements
- Has knowledge of cyber security architecture within cloud provider environments such as AWS and/or Azure. Knowledge of Kubernetes is also a bonus.
- Brings specialist security hardening knowledge in one or more areas including embedded Linux, iOS/Android mobile, cloud environments.
- Possesses strong general software engineering skills, ideally in C# and Linux toolchains, Bash scripting and PowerShell.
- Has hands-on experience with IaC tools such as Terraform, CloudFormation, or Bicep.
- Is familiar with relevant software and infrastructure security compliance frameworks and guidelines, e.g. OWASP, CVE and others.
Benefits & conditions
We're passionate about providing amazing opportunities and benefits, so you can continue and progress a lifelong career with us - here's what we have to offer:
- 25 days holiday + bank holidays.
- Ex-gratia day for Christmas Eve.
- Access to an online benefits portal.
- ASSA ABLOY Family Brand discount (Yale).
- 3 x Annual salary life cover.
- Company Pension scheme standard 5%.
- Annual discretionary bonus.
- Access to Employee Care scheme.