Hewlett Packard Enterprise Development LP
Product Security Engineer - Secure SDLC Analyst
Hewlett Packard Enterprise Development LP, Albuquerque, New Mexico, United States
HPE Aruba Networking is looking for a person excited to work at the intersection of software engineering, security, and assurance and trust.
HPE Aruba Networking produces a variety of types of software, from embedded firmware to Linux-based appliances to containerized cloud applications, but what these all have in common is a need to build security in from the beginning and to demonstrate to our customers that these products are trustworthy for use in their own environments.
This Secure SDLC role is part cybersecurity auditor, part consultant, part implementor who can work directly with software engineering teams on how to continually improve security maturity.**Qualifications and Education Requirements*** BS in Information Security, Computer Science, or related technical field.* A background in software security, either academic or work experience, including reverse engineering, vulnerability classes such as buffer overflows and their prevention, web application security, and/or cloud security.* Programming knowledge of at least one programming language with the ability to look at source code and figure out what it’s doing.* Familiarity with the purpose of tools such as IDEs, compilers, source code revision control systems, ASPM, SCA and code scanners.* Minimum 3 years of experience working directly in software engineering or in an adjacent field with exposure to the software engineering environment.* Experience conducting risk assessments, threat modeling, and/or compliance assessments. This includes the application of frameworks such as ISO 27001, NIST CSF, NIST SP 800-218, NIST SSDF, against various products or infrastructure.* Experience supporting the integration of security practices through the software development lifecycle. This includes but is not limited to reviewing code, providing secure coding guidance, developing and maintaining SDLC policies, and collaborating effectively with product teams to implement security controls.***About you:**** Strong foundation in cybersecurity principles, including knowledge of various attack vectors, vulnerabilities, and security best practice.* Industry certifications such as CISSP, CISA, CCSP, CSSLP, CGRC, or GIAC are helpful; we will help you obtain these if you don’t have them already.* Knowledge of relevant regulations and standards and how to interpret and implement these requirements within the organization's products.* Ability to develop and implement security policies, procedures, and guidelines that align with organizational goals and compliance requirements.* Technical experience with scripting and automation. Experience with participating in or leading external security standards communities or working groups.* Familiarity with the Agile development methodology.* Ability to manage security projects, setting priorities, and meeting deadlines as an independent performer.* Strong communicator with ability to collaborate with various teams.* Experience with ASPM, SCA, DAST and SAST tools* Experience with Project Management software (e.g. Jira, Asana, Confluence)* Experience with the procurement process for IT tools, particularly with product evaluations* Assist in the execution of product compliance assessments against various frameworks (e.g. NIST SSDF, NIST SP 800-218, SP 800-53, CIS Benchmarks)* Assist in the development and/or maintenance of GRC and SDLC tooling implementations, including scripting and automation.* Operate as a representative of HPE Aruba in working groups, with government representatives, and with auditors.* Provide consulting, information, and advice to product teams around implementing and improving the maturity of our SDLC.* Document known issues and provide information to product teams in a manner which allows for easy interpretation and corrective actions to be performed.* Monitor worldwide government standards and communicate to management and product teams when changes are made that may impact an existing control or introduce new requirements.* Minimal travel (approximately 5-10%) may be required at times.HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: .**Hewlett Packard Enterprise**Technology innovation that fosters business transformation.We help customers use technology to slash the time it takes to turn ideas into value. In turn, they transform industries, markets and lives.Some of our customers run traditional IT environments. Most are transitioning to a secure, cloud-enabled, mobile-friendly infrastructure. Many rely on a combination of both. Wherever they are in that journey, we provide the technology and solutions to help them succeed.**COVID Policy**The health and safety of our team members, customers and partners is paramount at HPE. Accordingly,
be fully vaccinated against COVID-19 by the employment start date where permitted by law. Exemptions based on medical, religious or other grounds will be processed and approved in accordance with local laws.**Standards of Business Conduct (SBC)**The Hewlett Packard Enterprise Standards of Business Conduct (SBC) embody the fundamental principles that govern our ethical and legal obligations to Hewlett Packard Enterprise. They pertain not only to our conduct within the company but also to conduct involving our customers, channel partners, suppliers and competitors.Read more about how we**Equal Opportunity Employer (EEO)**Hewlett Packard Enterprise provides equal employment opportunity to any employee or applicant without regard to sex, gender, color, race, ethnicity, religion, creed, national origin, ancestry, citizenship, age, marital status, sexual orientation, gender identity and expression, physical or mental disability, medical condition, pregnancy, protected veteran status, uniformed service status, familial status, genetic information, political affiliation, or any other characteristic protected by federal, state, or local law. Please click here: **.**If you’d like more information about your EEO right as an applicant under the law, please click here:**E-Verify**
**(US & PR only)**
HPE is an E-Verify employer. E-Verify is an Internet-based system that compares information from an employee's Form I-9, Employment Eligibility Verification, to data from U.S. Department of Homeland Security and Social Security Administration records to confirm the employment eligibility of all newly hired employees. For more information . You can also download the posters with information on legal rights and protection by clicking
and .**Accessibility**Hewlett Packard Enterprise is committed to working with and providing reasonable accommodation to qualified, differently abled individuals. If you need assistance in filling out the employment application or require a reasonable accommodation while seeking employment, please email recruiting@hpe.com. Note: This option is reserved for applicants needing assistance/reasonable accommodation related to a disability.**Disclosure of Sensitive Personal Data**Please ensure the resume you submit to us does not include any sensitive personal data.
Sensitive personal data includes data revealing information about your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation.
To the extent the resume you submit does contain this type of personal data, you consent to the storing and processing of this data by HPE for the purpose of reviewing and managing your application.if applicable to the role you applied to, you must #J-18808-Ljbffr
HPE Aruba Networking produces a variety of types of software, from embedded firmware to Linux-based appliances to containerized cloud applications, but what these all have in common is a need to build security in from the beginning and to demonstrate to our customers that these products are trustworthy for use in their own environments.
This Secure SDLC role is part cybersecurity auditor, part consultant, part implementor who can work directly with software engineering teams on how to continually improve security maturity.**Qualifications and Education Requirements*** BS in Information Security, Computer Science, or related technical field.* A background in software security, either academic or work experience, including reverse engineering, vulnerability classes such as buffer overflows and their prevention, web application security, and/or cloud security.* Programming knowledge of at least one programming language with the ability to look at source code and figure out what it’s doing.* Familiarity with the purpose of tools such as IDEs, compilers, source code revision control systems, ASPM, SCA and code scanners.* Minimum 3 years of experience working directly in software engineering or in an adjacent field with exposure to the software engineering environment.* Experience conducting risk assessments, threat modeling, and/or compliance assessments. This includes the application of frameworks such as ISO 27001, NIST CSF, NIST SP 800-218, NIST SSDF, against various products or infrastructure.* Experience supporting the integration of security practices through the software development lifecycle. This includes but is not limited to reviewing code, providing secure coding guidance, developing and maintaining SDLC policies, and collaborating effectively with product teams to implement security controls.***About you:**** Strong foundation in cybersecurity principles, including knowledge of various attack vectors, vulnerabilities, and security best practice.* Industry certifications such as CISSP, CISA, CCSP, CSSLP, CGRC, or GIAC are helpful; we will help you obtain these if you don’t have them already.* Knowledge of relevant regulations and standards and how to interpret and implement these requirements within the organization's products.* Ability to develop and implement security policies, procedures, and guidelines that align with organizational goals and compliance requirements.* Technical experience with scripting and automation. Experience with participating in or leading external security standards communities or working groups.* Familiarity with the Agile development methodology.* Ability to manage security projects, setting priorities, and meeting deadlines as an independent performer.* Strong communicator with ability to collaborate with various teams.* Experience with ASPM, SCA, DAST and SAST tools* Experience with Project Management software (e.g. Jira, Asana, Confluence)* Experience with the procurement process for IT tools, particularly with product evaluations* Assist in the execution of product compliance assessments against various frameworks (e.g. NIST SSDF, NIST SP 800-218, SP 800-53, CIS Benchmarks)* Assist in the development and/or maintenance of GRC and SDLC tooling implementations, including scripting and automation.* Operate as a representative of HPE Aruba in working groups, with government representatives, and with auditors.* Provide consulting, information, and advice to product teams around implementing and improving the maturity of our SDLC.* Document known issues and provide information to product teams in a manner which allows for easy interpretation and corrective actions to be performed.* Monitor worldwide government standards and communicate to management and product teams when changes are made that may impact an existing control or introduce new requirements.* Minimal travel (approximately 5-10%) may be required at times.HPE is an Equal Employment Opportunity/ Veterans/Disabled/LGBT employer. We do not discriminate on the basis of race, gender, or any other protected category, and all decisions we make are made on the basis of qualifications, merit, and business need. Our goal is to be one global team that is representative of our customers, in an inclusive environment where we can continue to innovate and grow together. Please click here: .**Hewlett Packard Enterprise**Technology innovation that fosters business transformation.We help customers use technology to slash the time it takes to turn ideas into value. In turn, they transform industries, markets and lives.Some of our customers run traditional IT environments. Most are transitioning to a secure, cloud-enabled, mobile-friendly infrastructure. Many rely on a combination of both. Wherever they are in that journey, we provide the technology and solutions to help them succeed.**COVID Policy**The health and safety of our team members, customers and partners is paramount at HPE. Accordingly,
be fully vaccinated against COVID-19 by the employment start date where permitted by law. Exemptions based on medical, religious or other grounds will be processed and approved in accordance with local laws.**Standards of Business Conduct (SBC)**The Hewlett Packard Enterprise Standards of Business Conduct (SBC) embody the fundamental principles that govern our ethical and legal obligations to Hewlett Packard Enterprise. They pertain not only to our conduct within the company but also to conduct involving our customers, channel partners, suppliers and competitors.Read more about how we**Equal Opportunity Employer (EEO)**Hewlett Packard Enterprise provides equal employment opportunity to any employee or applicant without regard to sex, gender, color, race, ethnicity, religion, creed, national origin, ancestry, citizenship, age, marital status, sexual orientation, gender identity and expression, physical or mental disability, medical condition, pregnancy, protected veteran status, uniformed service status, familial status, genetic information, political affiliation, or any other characteristic protected by federal, state, or local law. Please click here: **.**If you’d like more information about your EEO right as an applicant under the law, please click here:**E-Verify**
**(US & PR only)**
HPE is an E-Verify employer. E-Verify is an Internet-based system that compares information from an employee's Form I-9, Employment Eligibility Verification, to data from U.S. Department of Homeland Security and Social Security Administration records to confirm the employment eligibility of all newly hired employees. For more information . You can also download the posters with information on legal rights and protection by clicking
and .**Accessibility**Hewlett Packard Enterprise is committed to working with and providing reasonable accommodation to qualified, differently abled individuals. If you need assistance in filling out the employment application or require a reasonable accommodation while seeking employment, please email recruiting@hpe.com. Note: This option is reserved for applicants needing assistance/reasonable accommodation related to a disability.**Disclosure of Sensitive Personal Data**Please ensure the resume you submit to us does not include any sensitive personal data.
Sensitive personal data includes data revealing information about your racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, health, sex life or sexual orientation.
To the extent the resume you submit does contain this type of personal data, you consent to the storing and processing of this data by HPE for the purpose of reviewing and managing your application.if applicable to the role you applied to, you must #J-18808-Ljbffr