Product Security expert ensuring secure software development at NETGEAR. Championing security practices and monitoring vulnerabilities while collaborating with development teams.
Responsibilities
Serve as the product security subject-matter expert closely collaborating with other NETGEAR product development teams to identify, assess, root-cause, address, validate, and prevent product security issues.
Be the champion for secure and defensive programming techniques and use of automation to eliminate and prevent security problems.
Keep up to date with latest advancements in the field and continually elevate the secure software development practices at NETGEAR.
Use the latest and greatest bug hunting technologies to find security vulnerabilities at scale. Monitor the latest security trends, vulnerabilities, and threat intelligence, and assess their relevance to NETGEAR products.
Requirements
10+ years of relevant work experience in application security, hardware, IoT security, security pen-testing, vulnerability discovery, secure software development, and design security reviews.
Proven track record of implementing and scaling security tooling such as pre-commit hooks with static code analysis (SAST) and dependency security (OSS/SCA), and fine tuning them for the best developer experience.
Experience with using techniques like fuzzing, reverse engineering, writing SAST rules, semgrep, CodeQL,
Excellent knowledge of common security weaknesses (like OWASP top-n lists) and best ways to address them.
Understanding of network security technologies and vulnerabilities, especially in the networking device space.
Strong analytical and problem-solving skills, the ability to work both independently and collaboratively with diverse stakeholders
Excellent written and verbal communication skills in English.
BE or master’s degree in computer science, computer security, application security, information security, or networking.
Cybersecurity Consultant involved in deploying security tools and supporting compliance projects in Andorra. Working with cross - functional teams to enhance cybersecurity measures and documentation.
Microsoft Success Manager helping partners grow secure, scalable Microsoft practices across ANZ. Championing Microsoft security solutions and supporting partner success strategies in the region.
Assistant AVP overseeing a 5 - member team for Access Management services in Pune and Mumbai, ensuring high standards of service delivery and compliance.
Own global security systems infrastructure for QVC, managing access control and networked security systems across multiple regions. Collaborate with IT to ensure security and technology initiatives meet organizational needs.
Sales Account Manager growing ADAPTIT Cybersecurity business in Greece and Cyprus. Responsible for client relations, sales pipeline, and collaboration with the cybersecurity team.
Information Security Engineer focusing on Identity & Access Management and SSO at Westfield. Design, operate, and mature enterprise authentication and federation capabilities.
Cyber Security Engineer responsible for operational support and development activities with Ping Identity. Collaborate with global teams to strengthen cybersecurity and improve customer satisfaction.
Application Security Specialist focusing on security in software development lifecycle at Insight Investment in Manchester, driving DevSecOps practices across teams.
Cyber Security Engineer supporting mission - critical DoD contract at CACI. Involves reviewing infrastructure changes and implementing security measures in a cloud - based environment.
Security Incident Management Analyst coordinating information security incidents. Overseeing cyber incident response and providing guidance to senior management within a leading industrial software company.