Software Security Lead
About The Position
AnyVision, founded in 2015, is the world’s leading designer and developer of face, body, and object recognition platforms. We are a fast growing company that is seeking a talented and experienced Software Security Lead to join our “A(i)” R&D team.
You are:
- Leader, motivator and mentor
- Think like a hacker
You will:
- Own, manage and lead Threat Modeling and Security Standards workshops.
- Initiate and participate in code reviews, design reviews, etc.
- Prepare and deliver training and security awareness activities to the development teams.
- Make sure everyone in the department are involved in security and have knowledge on the security aspects of the product.
- Set the right security mindset to all the people and stakeholders of their groups.
- Manage security tools, train and help the developers on using those tools and reports.
- Conduct and train others on white-box security testing.
- Own and manage the hiring of external/internal pen-testing services.
- Become a company security expert in one or more technology domains (i.e. Web, C++, Python, Docker containers etc.).
- Acquire relevant knowledge, be updated, go to security conferences and be involved with the security community.
- Mentor new security engineers.
Requirements
- 6+ years of software development experience.
- 3+ years in software security (security researcher/ security engineer / security architect).
- Leading experience.
- Experience with Secure Software Development Life Cycle and development and coding practices.
- Experience with Security testing and assurance, architecture and design and assessment and Risk management.
- Knowledge in Threat Modeling.
- Security reviews for Code/Design/Architecture and requirements.
Knowledge in the following:
- Security standards and practices (OWASP, NIST, SANS, etc.).
- Hardening procedures.
- Fluent in English and Hebrew (speaking and writing), presentation and crowd-facing skills.
- Experience with Agile development.
Advantage:
- Experience as a security architect in a development organization.
- Security management certificates (CISSP, CSSLP, CISM, etc.).
- Have lectured at security conferences (BlackHat, OWASP, etc.).
- Security testing/research hands-on experience.