Senior Security Engineer - Product Security

TaxSlayer
US - Florida
View Company Profile / << Go Back

  • Job Type: Full time
  • 3 days ago

Job Description

Senior Security Engineer Product Security Augusta Ga Work Location \& Schedule This is a hybrid position based in our Augusta GA office Team members are expected to work on site two days per week in our Augusta office and remotely three days per week This schedule supports collaboration while offering flexibility and work life balance For the right candidate this position may also be considered as a fully remote opportunity for individuals residing in Georgia South Carolina North Carolina Florida or Tennessee only Who we are At TaxSlayer were more than just a tax software development company; were empowering individuals and small businesses to plan for and file their tax returns online with confidence and ease As a leading innovator in tax prep software TaxSlayer LLC has been revolutionizing the way people file their taxes since 1965 Our user friendly platform offers an intuitive interface that guides customers through the tax filing process step by step ensuring accuracy and maximum refunds TaxSlayer is headquartered in Augusta GA with a satellite office in Charlotte NC TaxSlayer proudly employs nearly 200 individuals year round plus 300 additional in season support agents Our employees are among the brightest most talented group of innovators who work collaboratively to improve our products and exceed customer expectations season after season Are you a TaxSlayer About the Role The Senior Security Engineer Product Security serves as the primary security partner to software development teams helping ensure security is embedded throughout the software development lifecycle This role is responsible for identifying and mitigating application security risks conducting security assessments managing TaxSlayers bug bounty program and supporting compliance and risk management initiatives Working closely with engineering product and Information Security teams this position helps protect sensitive taxpayer and financial data while fostering secure development practices across the organization Core Responsibilities Serve as the primary security point of contact for assigned Development teams participating in sprint planning architecture discussions and design reviewsReview product features system designs APIs authentication mechanisms and third party integrations to identify and mitigate security risksPartner with engineering teams to integrate security controls early in the software development lifecycle and promote secure coding practicesConduct secure code reviews threat modeling activities architecture risk assessments and security testing for applications and product releasesPerform hands on penetration testing and coordinate third party testing efforts when appropriateManage and optimize SAST DAST and CICD security tooling and processesTrack identified vulnerabilities through remediation and collaborate with engineering teams to address findingsOwn day to day administration of the companys bug bounty program including researcher engagement submission triage validation and remediation coordinationMonitor and report bug bounty program performance metrics and recommend process improvementsSupport governance risk and compliance initiatives including audits and assessments related to PCI DSS SOC 2 IRS security requirements and other applicable regulationsContribute to enterprise risk management activities and maintain product level security risk documentationAssist with security incident response activities including investigation root cause analysis and remediation trackingMentor engineering teams on secure coding practices threat modeling and product security best practicesOther duties as assignedHow your Success is measured Reduction in application and product security vulnerabilities identified in production environmentsTimely completion of security reviews threat models and vulnerability remediation activitiesEffective integration of security controls within the software development lifecycleSuccessful management and continuous improvement of the bug bounty program including response and remediation timelinesPositive audit and compliance assessment outcomes related to product security controlsIncreased adoption of secure coding practices and security standards across development teamsClear communication of technical risks and effective collaboration with engineering and business stakeholdersEducation \& Experience Bachelors degree in Cybersecurity Computer Science Information Technology or a related field or equivalent combination of education and experienceMinimum of 5 years of experience in application security product security security engineering or a related fieldExperience partnering closely with software development teams to integrate security into the development lifecycleExperience identifying and validating vulnerabilities in web applications APIs and cloud based environmentsSkills \& Competencies Strong knowledge of secure software development lifecycle SDLC practicesExperience with threat modeling methodologies such as STRIDE PASTA or similar frameworksKnowledge of common vulnerability frameworks including OWASP Top 10 and CWESANS Top 25Experience with SAST DAST penetration testing code review and CICD security toolsStrong understanding of web application API and cloud security principlesAbility to assess and communicate technical security risks to technical and non technical audiencesStrong problem solving collaboration and relationship building skillsAbility to balance security requirements with business objectives and product delivery schedulesPreferred certifications include OSCP OSWE GWAPT CSSLP or comparable credentialsExperience with bug bounty or vulnerability disclosure programs is strongly preferredFamiliarity with regulatory frameworks including PCI DSS SOC 2 FTC Safeguards Rule IRS security requirements CCPA and related standards is preferredPhysical \& Work Environment Requirements This is a hybrid or remote roleWork is performed in a standard office environment with minimal physical demandsMust be able to work at a computer for extended periodsOccasional travel may be required for meetings training or business needsReady to Join UsApply today and be sure to opt in for text updates to stay connected with our recruiting team throughout the process What We OfferAt TaxSlayer we know that our greatest strength lies in the talented individuals who drive our innovation and success Thats why were proud to offer a competitive comprehensive and flexible benefits package designed to support your well being growth and work life balance Flexible Work Options Enjoy remote and hybrid work opportunities depending on the role and team needs Generous Time Off Full Time employees receive a robust PTO bank plus paid holidays to recharge and refresh Health \& Wellness Coverage Medical Dental and Vision insurance through Aetna and SunLifeCoverage options include Employee Only Employee SpouseDomestic Partner Employee Children or FamilyAccess to a Wellness Program and on site fitness facilityFinancial Benefits 401k with a 150 match on up to 3 of your contributionPerformance based bonuses and regular salary reviewsAdditional Perks Company paid life insurance short term and long term disabilityOptional critical illness and accident insuranceEducation assistance to support your professional developmentCompany paid parking company store and unlimited free coffeePlease note As a federal contractor we are responsible to ensure our employees meet any obligations set forth by the US government We will inform you of any applicable requirements as they arise Legal Disclaimers TaxSlayer is an equal opportunity employer and complies with all applicable laws regarding discrimination Employment is based on qualifications merit and business need This job description is not intended to be all inclusive and may be subject to change to meet business needs




Fast Track Upload