Adventure's around the corner...
Product Security Manager - US Remote Option
- Department Information Security & Compliance
- Location United States - Remote
Responsibilities (Can include but not limited to)
- Work to continuously develop, maintain and mature Secure Development Lifecycle Program at Guidewire
- Be a resourceful part of the hardworking team responsible for seamless integration of security controls into Guidewire Software Development Lifecycle. This includes working closely with product security champions in an agile environment for following:
- Educate business on Secure Development Life Cycle frameworks
- Perform Threat Modeling in design phase and frequently review to identify and eliminate security issues in design or architecture.
- Facilitate compliance for Static Application Security Testing, Container Security Scanning & Open-source Security Analysis during the development phase in the pipeline
- Facilitate compliance for Dynamic Application Security Testing during the testing phase
- Facilitate compliance on Penetration Test prior to Release/GoLive
- Providing technical guidance in triaging, addressing security issues and tracking remediation will also be part of your responsibilities
- Contribute Guidewire to triage and contain product security incident response or vulnerability disclosures
- Develop comprehensive, accurate reports and presentations for both technical and executive audiences
- Ensure knowledge creation around common vulnerabilities within Guidewire landscape and corresponding remediation practices.
- Research the latest security standard methodologies and technologies, staying abreast of new threats and vulnerabilities and helping disseminate this information within the groups at Guidewire
- Own and manage Secure SDLC tools, related automation and innovation.
- Lead and manage high performance team.
Skills and Experience
- Preferred 10 years of strong background in security engineering, software development, architecture, and project management for industry leaders. (Experienced in integrating application security into the SDLC, remediating vulnerabilities, developing and providing security training.).
- Experience in threat modeling, static and dynamic application security testing, open-source security testing, developer security training/workshops, etc.
- Advanced knowledge and understanding in various disciplines such as security engineering, system and network security, authentication and security protocols, cryptography, and application security.
- Experience with cloud service providers and their offerings, preferred AWS
- Strong understanding of vulnerabilities and common attack vectors
- Strong communication (i.e., written and verbal), presentation, teamwork skills and resourcefulness
- Preferred Certifications: CISSP, CSSLP, AWS Solutions Architect, or equivalent.
The perks. The rewards. The good stuff.
We’re proud to shout about our awesome benefits packages. Holistic wellness is a big deal for us. We offer everything you need to support your work and, most importantly, your work-life balance. We’re committed to helping you be the best version of yourself. Inside and outside of work.
Receive market-competitive pay and incentive programs—because you deserve it! To help future-proof your income, we offer generous support through retirement savings plans.
HEALTH AND WELLNESS
Keep your physical and emotional health in tip-top shape with health insurance for you and your family, an employee assistance program, annual wellness reimbursement, and access to wellness resources.
Work in an environment where you’ll have the freedom and trust to make an impact, with time for your life outside of work.
Relax and kick back through our generous paid time-off programs. Make a difference in your community with three volunteer days each year. Take your own personal day of rest with My Day. We also offer 16 weeks of paid leave for all new parents.
We encourage self-directed learning, giving you every chance to become a better version of yourself, both professionally and personally. At Guidewire, lifelong learning is here for the taking.
Your career opportunities are only limited by your own imagination. Guidewire’s community is filled with chances to expand your horizons across any of our teams or worldwide locations.