Application Security Engineer (Remote)

| Hybrid
Sorry, this job was removed at 7:15 a.m. (CST) on Wednesday, October 13, 2021
Find out who's hiring in Chicago.
See all Cybersecurity + IT jobs in Chicago
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Donnelley Financial Solutions (DFIN) is a leader in risk and compliance solutions, providing insightful technology, industry expertise and data insights to clients across the globe. We’re here to help you make smarter decisions with insightful technology, industry expertise and data insights at every stage of your business and investment lifecycles. As markets fluctuate, regulations evolve and technology advances, we’re there. And through it all, we deliver confidence with the right solutions in moments that matter. 

Location

We are accepting non-local / remote candidate for this role.

Position Summary

Application Security Engineer will functionally support product engineering and development teams to secure company’s SaaS products portfolio. Application Security Engineer will be responsible for assessing and understanding the security posture and attack surface of all DFIN products, and for assistance in the development of the appropriate security controls.

Responsibilities

  • Conduct security assessments, security penetration testing and validation of test results
  • Provide security insights to vulnerability scan/pen test results
  • Working closely with development teams to assess the security posture/risk of the product features being developed
  • Perform architectural risk analysis, threat modeling, secure design and source code review
  • Effectively manage relationship with external application security and penetration testing partners
  • Incorporate security tools/tasks into automated product development and deployment lifecycle (SAST/DAST/IAST integration into CI/CD pipeline)
  • Provide expert knowledge and guidance to the product development teams about security vulnerabilities and applicable remediation paths
  • Serve as a critical resource to ensuring each DFIN product is developed in alignment with industry-leading Secure Product/Software Development standards
  • Participate in development of the DFIN Application Security Standards, best practices and associated metrics

Required Skills

  • Bachelor degree with 5+ years of relevant work experience OR demonstrated ability to meet the job requirements through a comparable number of years of applicable work experience and education
  • Self-driven, highly motivated with a strong customer focus
  • Strong analytical and problem-solving skills
  • Solid project management skills, especially in a cross-functional environment
  • Familiarity with Agile/Scrum methodologies and associated tools
  • Prior exposure to modern CI/CD pipelines including tools and technologies such as Azure DevOps (former VSTS), GitHub, Jenkins and others
  • Must have a “breaker” mentality, but be effective at designing the mitigating controls
  • Ability to develop technical (XSS, etc.) and functional (fraud, etc.) abuse test cases
  • Working knowledge of vulnerability management and penetration testing tools such as NMAP, Core Security, Burp, ZAP, Rapid7 Nexpose, Kali Linux, or Metasploit
  • Working knowledge of NIST framework, Open Web Application Security Project (OWASP) and Open Source Security Testing Methodology Manual (OSSTMM)

Required Skills (Cont.)

  • Solid understanding of OWASP security concepts and common application security risks, such as XSS, CSRF, SQL Injection, Cookie Manipulation, etc.
  • Solid understanding of fundamental application security building blocks such as: authentication, authorization, data validation, encryption, exception handling and logging
  • Solid understanding of leading cloud platforms such as MS Azure and Amazon AWS, their inherent security risks and relevant security controls
  • Solid understanding of the micro-services, containerization technologies (Docker, Kubernetes) and associated security technologies/controls (Aqua, Twistlock and others)
  • Experience with one of the market leading SAST/DAST/IAST tools such as Checkmarx, Veracode, Rapid7 AppSpider, IBM AppScan or HP/Microfocus Fortify
  • Experience with one of the programming languages and/or programming frameworks such as C#, JavaScript, .Net or others

It is the policy of Donnelley Financial Solutions to select, place and manage all its employees without discrimination based on race, color, national origin, gender, age, religion, actual or perceived disability, veteran's status, actual or perceived sexual orientation, genetic information or any other protected status. 

If you are a qualified individual with a disability or a disabled veteran, you have the right to request a reasonable accommodation if you are unable or limited in your ability to use or access jobs.dfinsolutions.com as a result of your disability. You can request a reasonable accommodation by sending an email to [email protected]#TalentknowsTalent


Read Full Job Description
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

Technology we use

  • Engineering
  • Product
  • Sales & Marketing
    • C#Languages
    • JavaLanguages
    • JavascriptLanguages
    • PythonLanguages
    • SqlLanguages
    • jQueryLibraries
    • ReactLibraries
    • AngularFrameworks
    • Angular.JSFrameworks
    • ASP.NETFrameworks
    • KubernetesFrameworks
    • Node.jsFrameworks
    • TerraformFrameworks
    • DynamoDBDatabases
    • Microsoft SQL ServerDatabases
    • MongoDBDatabases
    • MySQLDatabases
    • NoSQLDatabases
    • PostgreSQLDatabases
    • SAP HANADatabases
    • SnowflakeDatabases
    • TeradataDatabases
    • Microsoft AzureServices
    • New RelicServices
    • IllustratorDesign
    • PhotoshopDesign
    • Aha!Management
    • ConfluenceManagement
    • JIRAManagement
    • Microsoft ProjectManagement
    • DocuSignCRM
    • LinkedIn SalesNavigatorCRM
    • Microsoft DynamicsCRM
    • SalesforceCRM
    • MarketoLead Gen
    • Oracle EloquaLead Gen

Location

Located in the heart of downtown Chicago’s financial district, we are steps from all Metra stations, good eats and entertainment.

An Insider's view of DFIN

How would you describe the company’s work-life balance?

The company culture that I love the most about Donnelley is the flexibility and work-life balance. Working in this role with my peers, my leadership team, and within my own team — everyone understands that you have other things to take care of outside of your work.

Aravinda

VP, IT Infrastructure & Operations

How do you collaborate with other teams in the company?

The new employee is paired up with one or two team members to accomplish their first set of tasks and collaboration is encouraged every step of the way. We have other meetings on a cadence and will break into smaller groups when it feels right. For local employees who thrive on face-to-face collaboration, we try to meet in-person when possible.

Gary

Engineering Manager

What makes someone successful on your team?

Active and honest listening – Contrary to the stereotypical, extroverted sales rep, some of my most effective and insightful client interactions are when I do the least amount of talking, and the most active listening. Client insight is exponentially easier to excavate when you stop “pitching” – and start listening.

Carey

Senior Sales Representative

What is your vision for the company?

Our business plan reflects the change in products DFIN is selling today versus what we sell in five years. DFIN today is a company that offers a lot of professional services that we added software to, but the goal is to become a SaaS company that has services to support it.

Stephen

SVP, Global Head of Engineering

What are DFIN Perks + Benefits

DFIN Benefits Overview

The world continues to change in ways we never expected, but there is one constant: your safety and well-being is a top priority, and DFIN has you covered with our benefits.

Culture
Volunteer in local community
Partners with nonprofits
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Employee resource groups
Employee-led culture committees
Quarterly engagement surveys
Hybrid work model
Employee awards
Flexible work schedule
We value a work / life balance at DFIN.
Remote work program
We have partial and fully remote opportunities at DFIN.
Diversity
Documented equal pay policy
Dedicated diversity and inclusion staff
Highly diverse management team
Mandated unconscious bias training
Diversity manifesto
Diversity employee resource groups
Hiring practices that promote diversity
Diversity recruitment program
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Wellness programs
Mental health benefits
Wellness days
Unlimited PTO structure to support Wellness.
Financial & Retirement
401(K)
401(K) matching
Company equity
Employee stock purchase plan
Performance bonus
Child Care & Parental Leave
Childcare benefits
Generous parental leave
Family medical leave
Family Medical Leave granted under the Family and Medical Leave Act (FMLA).
Adoption Assistance
Return-to-work program post parental leave
Vacation + Time Off
Unlimited vacation policy
Generous PTO
Paid holidays
Paid sick days
Flexible time off
Floating holidays
Bereavement leave benefits
Hardship benefits
Office Perks
Commuter benefits
Company-sponsored outings
Free snacks and drinks
Some meals provided
Company-sponsored happy hours
Onsite office parking
Employee parking available
Fitness stipend
Mother's room
Onsite gym
Professional Development
Job training & conferences
Lunch and learns
Promote from within
Mentorship program
Continuing education available during work hours
Online course subscriptions available
Customized development tracks
Paid industry certifications
Personal development training
Apprenticeship programs

Additional Perks + Benefits

DFIN has implemented a Employee Stock Purchase Program.

More Jobs at DFIN

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about DFINFind similar jobs like this