Skip to main content
TransUnion

Product Security Advisor

RemoteIndia only
Published
Role
Security
Experience
Senior
Employment
Full-time
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to IN only. Set where you work from to check your eligibility.

No BS summary

Опытный продуктовый/информационный security инженер (5+ лет), специализирующийся на secure SDLC, threat modeling и безопасной архитектуре для веб/облачных приложений. Требуется практический опыт SAST/SCA/IAST/CNAPP, уметь внедрять процессы и взаимодействовать с командами разработки и аудитом. Роль удалённая с возможными поездками по Индии/доместик до 15%.

Core skills

threat modelingsecure SDLCapplication security

Required skills

secure coding practicessecure architecture designCI/CD pipelinesSASTSCAIASTCNAPPapplication vulnerability remediationcloud security (hybrid cloud)

Optional skills

CISSPSSCPCSSLP

What you'll do

  • Advises and contributes to product development teams on secure coding practices, vulnerability management, and secure software development lifecycle (SSDLC) processes
  • Assists Product Engineering teams with adoption of application security tooling (SAST, SCA, IAST, CNAPP) and analysis of its results
  • Works with engineering teams to ensure products comply with relevant security standards, regulations, and industry certifications (OWASP, CIS, PCI-DSS)
  • Conducts Threat Modeling of products using frameworks (STRIDE, PASTA, MAESTRO)
  • Partner with architecture teams to embed secure-by-design principles and lead security design reviews
  • Builds relationships and partners with functional areas and leadership across the business and Global Technology
  • Collaborate with audit and compliance teams to ensure product security controls are documented and audit-ready
  • Provide periodic updates, education and presentations to staff and management on product security
  • Stay up to date with emerging threats, technologies, and industry trends
  • Mentor and educate colleagues on secure coding practices and secure product architecture patterns

What they require

  • 5+ years of experience in cybersecurity, product security, or security architecture in a technology-related industry
  • 3+ years of information security experience in a hybrid cloud environment
  • In depth experience secure coding practices, threat modeling, secure architecture design, and secure SDLC/CICD pipelines
  • Prior experience in software development or engineering
  • In-depth technical experience identifying and advising on the remediation of application security vulnerabilities on cloud and web-based applications
  • Experience presenting to senior technology and information security executives and influencing stakeholders
  • Experience working with industry frameworks and standards such as OWASP, PCI, CIS, and NIST
  • BA/BS degree in a computer science or technology related field
  • Ability to travel domestically up to 15% of time

Benefits

  • Work/life flexibility
  • Resources for professional development
  • Opportunities to work with pioneering products and cutting-edge technology

American consumer credit reporting agency

🇺🇸 United StatesData AnalyticsEnterprisetransunion.com/

What people say about this company

3.7/ 5

  • Many employees appreciate the opportunities for career advancement.
  • The work environment is often described as collaborative and supportive.
  • Some employees report issues with management and communication.
Salary not disclosed