Job Description
Talkdesk is seeking a Senior Security Engineer I to join their Security Engineering Team. The ideal candidate will be passionate about security and contribute to building a safer Talkdesk. This role involves providing security guidance to development teams, performing threat modeling, and collaborating with stakeholders to improve the overall security posture of Talkdesk.
Responsibilities include:
- Providing support for vulnerability management and mitigation.
- Offering technical support to development teams for patching strategies.
- Providing security guidance throughout the development lifecycle.
- Developing security standards and practices.
- Performing threat modeling.
- Recommending security enhancements.
- Collaborating with stakeholders to gather security requirements.
- Providing operational support for security technologies.
- Working to improve Talkdesk's overall security.
- Performing pentests and managing findings.
Requirements:
- At least 5 years of experience in application security with SAST, DAST, and SCA tooling.
- Experience integrating security testing into CI/CD pipelines.
- Familiarity with IaaC tooling and methodology (Terraform, Ansible, ArgoCD).
- Strong experience as a vulnerability management specialist and security advisor.
- Strong experience with OWASP TOP 10, CVE, CWE, and other vulnerability taxonomy.
- Coding experience in one or more languages (Java, Ruby, Python).
- Experience with secure development security tools.
- Experience in application architecture security review.
- Strong experience with secure coding practices and standards.
- Knowledge in applications and systems security.
- Knowledge in cryptographic concepts.
- Knowledge of networking and web protocols.
- Understanding of cybersecurity standards and frameworks (ISO27001, NIST, CIS, OWASP, SANS).
- Linux/Unix proficiency.
- Excellent communication skills.
- Strong stakeholder management skills.
- Fluent in English.
- Critical thinking and problem-solving skills.
- Comfortable in a fast-paced environment.
Nice to have:
- Familiarity with Git, Ruby, Kotlin, RabbitMQ, Redis, MongoDB, PostgreSQL.
- Experience in conducting security tests in web and mobile applications.
- Experience with AI security.
- Knowledge of rating vulnerabilities using CVSS 3.0 & 4.0.
- Prior experience as DevOps and/or Software Engineer.
- Prior experience handling security incidents.
- Certifications such as OSCP, CISM, CISSP, GSEC.