OCC
We clear and settle trades for the options industry.
Hybrid

Associate Principal, Security Engineer

Sorry, this job was removed at 8:58 a.m. (CST) on Wednesday, May 19, 2021
Find out who's hiring in Chicago.
See all Cybersecurity + IT jobs in Chicago
Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Summary

 As an Associate Principal, Security Engineer you will be part of a team responsible for analyzing, triaging, solutioning vulnerabilities identified via Black Duck and Veracode scanning on open source libraries. This team is responsible for identifying solutions, testing out hands-on solutions across a variety of software, and working closely with the development community to implement solutions. The team is also responsible for assessing the total risk of the vulnerabilities with respect to The OCC environment.

You would be a good candidate for this role if you like:

  • learning about new technologies and their secure implementation
  • finding security vulnerabilities and helping team fix them
  • thinking about problems and solving the root cause instead of just the current symptoms
  • sharing your knowledge with others

Primary Duties and Responsibilities:

To perform this job successfully, an individual must be able to perform each primary duty satisfactorily.

  • Provide general guidelines for preventing commonly found vulnerabilities by defining and updating security requirements
  • Performing threat modeling on products, even if they don't fit a common pattern
  • Reliably estimating the likelihood of given threats when building a threat model
  • Conducting code reviews
  • Interacting with project teams to seek implementation and completion of security requirements
  • Documenting processes based on established guidelines
  • Identifying or writing exploit code for high complexity vulnerabilities such as remote code execution, memory corruption or SQL injection
  • Defining pen test plans through stories/tasks for moderately complex applications such as those deployed to Relativity platform (ADS app) or those involved in security critical workflows (e.g. authentication)
  • Collaborate with development, platform automation and security teams to create and continuously improve a simple to use standardized repeatable automated application pipeline that includes testing, security and automated deployment to development and QA environments.
  • Troubleshoot environments as problems arise, test fixes, and perform follow-ups to ensure problems have been adequately resolved.
  • Collaborate with development, platform automation, security teams.
  • Other job-related duties as assigned.

Supervisory Responsibilities:

Qualifications:

The requirements listed are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the primary functions.

  • Strong collaboration and presentation skills reaching across functional borders including technical and non-technical audiences.
  • Understanding of Kanban and/or Agile methodologies.
  • Hands-on experience working in Agile and DevOps cultures, focusing on process improvement and automation. Experience of working both independently and collaboratively in a fast paced, change oriented, and demanding IT environment with a strong focus on business outcomes.
  • Hands-on security engineering experience.
  • Self-starter – takes the initiative to research, learn and deliver. Anticipates the play.
  • Team player – humble, collaborative, and focused on making sure the entire team succeeds.
  • Experience in building threat models for web applications
  • Familiarity with common software vulnerabilities (e.g. OWASP Top 10) and their remediation
  • Deep interest in security architecture of applications and technologies (Web, Kubernetes, Network)
  • Ability to follow established processes
  • Ability to juggle several high visibility projects
  • Ability to read code in mainstream programming languages such as Python, C#, Java

Technical Skills:

  • Capability and hands-on experience with Vulnerability scanning tools/utilities
  • Ability to provide solutioning and testing the solutions before providing details to development community
  • 6+ years programming/scripting experience in languages such as Java, Bash, Python or Go.
  • 2+ years hands on with continuous integration and continuous delivery (CI/CD) tools (examples - GitHub, Jenkins, Artifactory, Docker, Docker-Compose, K8s).
  • 2+ years of experience in technology delivery in a DevOps and Cloud Engineering environment (AWS Preferred); relevant industry certifications such as AWS Solutions Architect Associate or similar are a plus.
  • Demonstrable experience of automation.

Education and/or Experience:

  • Bachelor’s or Master’s Degrees in Computer Science, Information Systems or other related field. Or equivalent work experience.

Certificates or Licenses:

See More
Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.

What are OCC Perks + Benefits

OCC Benefits Overview

Educational Assistance and Student Debt Forgiveness, 12-week paid parental leave, BYOD program with technology stipend up to $2,000 every three years, $35 per month pay to offset costs of mobile data plans. Open offices, online health coaching.

Culture
Volunteer in local community
Each year, OCC employees select a locally-based charitable organization for each of our three offices (Chicago, Dallas and Washington, D.C.). We offer multiple opportunities to get involved.
Partners with nonprofits
OCC Partners with local organizations in Dallas, Chicago and DC to raise funds and support their missions. Employees select the charity and are eligible for up to 8 hours of paid time to volunteer.
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Flexible work schedule
OCC provides employees with a flexible work schedule that includes Flexible start and end times.
Remote work program
2 days per week work from home program
Diversity
Dedicated diversity and inclusion staff
Mandated unconscious bias training
Diversity employee resource groups
Health Insurance + Wellness
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
HSA or FSA accounts available for those enrolled in medical plans.
Life insurance
Wellness programs
Includes back-up child or elder care along with other wellness programs.
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
OCC provides employees with a 401(k) matching plan managed by Fidelity. We match 50% of contributions up to 12% of an employee's annual gross pay.
Performance bonus
Charitable contribution matching
Child Care & Parental Leave
Generous parental leave
12-week paid parental leave
Vacation + Time Off
Generous PTO
OCC employees receive between 22 and 32 days per year of paid time off based on years of service.
Paid volunteer time
Sabbatical
Eligible employees get 30 days of paid sabbatical after their first 10 years of working at the company.
Paid holidays
Paid sick days
Office Perks
Commuter benefits
OCC Offers pre-tax commuter benefits for employees in Chicago and Washington, D.C.
Company-sponsored happy hours
Relocation assistance
OCC offers relocation assistance which varies based on the position level and location.
Home-office stipend for remote employees
Professional Development
Job training & conferences
OCC offers employees professional development opportunities including onsite training courses and the ability to attend job related certification courses, conferences and seminars.
Tuition reimbursement
Our tuition reimbursement plan offers an annual max of $10000.
Lunch and learns
OCC hosts leadership lunches on a regular basis so you can learn about your colleagues and their unique backgrounds.
Promote from within
Online course subscriptions available
Customized development tracks
Paid industry certifications
Employees are strongly encouraged to stay current in relevant technologies and supports certification programs.

Additional Perks + Benefits

We were recently recognized as one of LinkedIn's Top Company in Financial Services! Take a look at our blog post here: https://www.theocc.com/newsroom/press-releases/2022/06-23-linkedin-list…

More Jobs at OCC

Apply Now
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about OCCFind similar jobs like this