Logo
HPE Aruba Networking

Product Security Engineer - Secure SDLC Analyst

HPE Aruba Networking, Aguadilla, Aguadilla, us, 00603

Save Job

Overview This role is hybrid: work 2 days per week from an HPE office while working on the intersection of software engineering, security, and assurance and trust. The Secure SDLC role is part cybersecurity auditor, part consultant, part implementor who can work directly with software engineering teams to continually improve security maturity.

How You'll Make Your Mark

Assist in the execution of product compliance assessments against various frameworks (e.g. NIST SSDF, NIST SP 800-218, SP 800-53, CIS Benchmarks)

Assist in the development and/or maintenance of GRC and SDLC tooling implementations, including scripting and automation.

Operate as a representative of HPE Aruba in working groups, with government representatives, and with auditors.

Provide consulting, information, and advice to product teams around implementing and improving the maturity of our SDLC.

Document known issues and provide information to product teams in a manner which allows for easy interpretation and corrective actions to be performed.

Monitor worldwide government standards and communicate to management and product teams when changes are made that may impact an existing control or introduce new requirements.

Minimal travel (approximately 5-10%) may be required at times.

Qualifications And Education Requirements

BS in Information Security, Computer Science, or related technical field.

A background in software security, either academic or work experience, including reverse engineering, vulnerability classes such as buffer overflows and their prevention, web application security, and/or cloud security.

Programming knowledge of at least one programming language with the ability to look at source code and figure out what it’s doing.

Familiarity with the purpose of tools such as IDEs, compilers, source code revision control systems, ASPM, SCA and code scanners.

Minimum 3 years of experience working directly in software engineering or in an adjacent field with exposure to the software engineering environment.

Experience conducting risk assessments, threat modeling, and/or compliance assessments. This includes the application of frameworks such as ISO 27001, NIST CSF, NIST SP 800-218, NIST SSDF, against various products or infrastructure.

Experience supporting the integration of security practices through the software development lifecycle. This includes but is not limited to reviewing code, providing secure coding guidance, developing and maintaining SDLC policies, and collaborating effectively with product teams to implement security controls.

About You

Strong foundation in cybersecurity principles, including knowledge of various attack vectors, vulnerabilities, and security best practice.

Industry certifications such as CISSP, CISA, CCSP, CSSLP, CGRC, or GIAC are helpful; we will help you obtain these if you don’t have them already.

Knowledge of relevant regulations and standards and how to interpret and implement these requirements within the organization's products.

Ability to develop and implement security policies, procedures, and guidelines that align with organizational goals and compliance requirements.

Technical experience with scripting and automation. Experience with participating in or leading external security standards communities or working groups.

Familiarity with the Agile development methodology.

Ability to manage security projects, setting priorities, and meeting deadlines as an independent performer.

Strong communicator with ability to collaborate with various teams.

Experience with ASPM, SCA, DAST and SAST tools.

Experience with Project Management software (e.g. Jira, Asana, Confluence).

Experience with the procurement process for IT tools, particularly with product evaluations.

Benefits We provide a comprehensive suite of benefits supporting physical, financial, and emotional wellbeing, promote personal and professional development, and maintain an inclusive workplace culture.

Equal Employment Opportunity HPE is an Equal Employment Opportunity/Veteran/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are based on qualifications, merit, and business need. Hewlett Packard Enterprise is a protected veteran/individual with disabilities. HPE will comply with all applicable laws related to employer use of arrest and conviction records, including laws requiring employers to consider for employment qualified applicants with criminal histories.

#J-18808-Ljbffr