Adventure's around the corner...
Senior Security Engineer
- DepartmentInformation Security
- LocationIndia - Bangalore
- Location TypeHybrid
Guidewire PSIRT (Product Security Incident Response Team) is responsible for:
- Guidewire product vulnerability management process for all Guidewire applications.
- Coordination of customer/external product security incidents and reported security issues affecting various Guidewire products and applications.
- Working cross-functionally with all business units, sustaining engineers, product security team members, customer support, legal and external security researchers to ensure timely resolution of security incidents and events.
- Development, maintenance and continuous improvement of the product security incident monitoring, detection and response tools and process, including all required supporting materials.
- Pen testing Guidewire applications to ensure timely discovery of the vulnerabilities.
- Security Review and Code Review of Guidewire applications
We are looking for a new team member who will be responsible to perform following activities (but not limited to):
- Ensure proper execution of PSIRT Process - triage security related issues (external / internal), verify those on different versions, products.
- Perform root cause analysis to ensure validity of reported issues.
- Triage code defect based issues, quantitatively evaluate risk and provide guidance to engineering teams regarding the impact of security issues using industry standard metrics such as CVSS.
- Work closely with project management, product management, engineering and sustaining teams to drive issues to closure.
- Cultivate strong working relationships with external researchers, reporting organizations and customers to ensure effective collaboration. Work with customer facing and internal teams to continually improve processes used to identify and fix product security issues
- Enhance existing product security incident response program
- Coordinate with internal product development teams in accomplishing regular security reviews and penetration testing assessments.
- Execute the penetration tests internally to identify critical vulnerabilities.
- Perform security-focused code reviews
- Support the preparation of security releases.
- Develop security tooling and automation
- Assist teams in reproducing, triaging, and addressing application security vulnerabilities.
- Validate findings from security scanning tools and ideate data-driven enhancement strategies for dynamic (DAST), static (SAST), open-source application security testing (SCA) and container security scanning including troubleshooting, and continuous process improvement
- Bachelor's/master’s in computer science or equivalent
- Industry related certifications are preferred (E.g. CSSLP, CISSP, GIAC, OSCP, etc.)
- Minimum 7-10 years of relevant Application Security Experience
- At least 2-5 years of experience with Penetration testing
- Solid understanding of OWASP Top 10, common classes of product security vulnerabilities and attack/defense methodologies.
- Strong written and verbal communications skills
- Proven ability to build relationships and influence individuals at all levels, as well as external security researchers, vendors and service providers
- Experience with various application security tools - Static code analysis, dynamic code analysis, vulnerability scanning, pen testing
- AWS/Cloud Experience a strong plus
- Bug bounty program participation a plus
- ● Knowledge of the security research community is a strong plus
- ● Scripting skills (i.e. Python/Perl/Ruby, shell scripting) or development experience
- (Java/C++/Python) is a significant plus!
Guidewire is the platform P&C insurers trust to engage, innovate, and grow efficiently. We combine digital, core, analytics, and AI to deliver our platform as a cloud service. More than 540+ insurers in 40 countries, from new ventures to the largest and most complex in the world, run on Guidewire.
The perks. The rewards. The good stuff.
We’re proud to shout about our awesome benefits packages. Holistic wellness is a big deal for us. We offer everything you need to support your work and, most importantly, your work-life balance. We’re committed to helping you be the best version of yourself. Inside and outside of work.
Receive market-competitive pay and incentive programs—because you deserve it! To help future-proof your income, we offer generous support through retirement savings plans.
HEALTH AND WELLNESS
Keep your physical and emotional health in tip-top shape with health insurance for you and your family, an employee assistance program, annual wellness reimbursement, and access to wellness resources.
Work in an environment where you’ll have the freedom and trust to make an impact, with time for your life outside of work.
Relax and kick back through our generous paid time-off programs. Make a difference in your community with three volunteer days each year. Take your own personal day of rest with My Day. We also offer ample paid leave for all new parents.
We encourage self-directed learning, giving you every chance to become a better version of yourself, both professionally and personally. At Guidewire, lifelong learning is here for the taking.
Your career opportunities are only limited by your own imagination. Guidewire’s community is filled with chances to expand your horizons across any of our teams or worldwide locations.