Logo
F5

Sr Security Engineer - DevSecOps

F5, San Jose, California, United States, 95199

Save Job

Join to apply for the

Sr Security Engineer - DevSecOps

role at

F5 Overview

F5 is looking for a hands-on Sr. Security Engineer with experience owning vulnerability management and code security programs. This role supports vulnerability management of open-source components in the Edge 2.0 platform and includes responsibility for code security, static and multifaceted code scanning, and writing policies and procedures around the lifecycle of code and associated vulnerabilities. Responsibilities

Collaborate with software architects, security defenders, Operations, SRE, compliance specialists, and business leaders to understand the components of the platform and their requirements around vulnerability management, static and dynamic code analysis depending on the component’s structure and place in the platform. Write and maintain policies and procedures around vulnerability management and code analysis following industry methodologies and compliance directives. Integrate with scanning tools and provide mentorship to developers on integration, interpreting findings, and improving output. Work with architects of underlying frameworks to minimize reported vulnerabilities when there is significant code reuse. Collaborate with other members of the DevOps team to introduce tooling that increases clarity and better quantifies vulnerability remediation. Work with engineering teams to incorporate best standards from vulnerability management and code analysis into the SDLC. Work with other team members to safely introduce dynamic code analysis tools. Participate in Incident Response when appropriate. Minimum qualifications

US Citizenship BS degree in Computer Science or equivalent with 7+ years of secure software development experience Good understanding of the Docker container build process Experience with vulnerability management systems like Snyk, Whitesource, Trivy, Dependency-check, Nancy, etc. Experience with SAST tools like Coverity, FindSecBugs, Fortify, Veracode, etc. Familiarity with microservices architecture, Docker and Kubernetes Good understanding of complexities and security challenges in large-scale distributed systems The Job Description is intended to be a general representation of the responsibilities and requirements of the job. However, the description may not be all-inclusive, and responsibilities and requirements are subject to change. The annual base pay for this position is: $166,625.00 - $249,937.00 F5 maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, geographic locations, and market conditions, as well as to reflect F5’s differing products, industries, and lines of business. The pay range referenced is as of the time of the job posting and is subject to change. You may also be offered incentive compensation, bonus, restricted stock units, and benefits. More details about F5’s benefits can be found at the following link: https://www.f5.com/company/careers/benefits. F5 reserves the right to change or terminate any benefit plan without notice. Please note that F5 only contacts candidates through F5 email address (ending with @f5.com) or auto email notification from Workday (ending with f5.com or @myworkday.com). Equal Employment Opportunity It is the policy of F5 to provide equal employment opportunities to all employees and employment applicants without regard to unlawful considerations of race, religion, color, national origin, sex, sexual orientation, gender identity or expression, age, sensory, physical, or mental disability, marital status, veteran or military status, genetic information, or any other classification protected by applicable local, state, or federal laws. This policy applies to all aspects of employment, including, but not limited to, hiring, job assignment, compensation, promotion, benefits, training, discipline, and termination. F5 offers a variety of reasonable accommodations for candidates. Requesting an accommodation is completely voluntary. F5 will assess the need for accommodations in the application process separately from those that may be needed to perform the job. Request by contacting accommodations@f5.com.

#J-18808-Ljbffr