Principal Security Engineer
ROLE VALUE PROPOSITION:
The Product Security team, responsible for all application level security features, is seeking a Principal Product Security Engineer. You will be part of a team of highly skilled engineers architecting and implementing Symphony secure messaging vision. Specifically, a well qualified candidate will contribute towards secure client key delivery mechanisms, time-based automatic key rotation mechanisms, incident based key rotation, search over encrypted data, Certificate Authorities, cryptographic performance, authentication, and finally, help manage the risk of usual Internet security weather (such as the usual CSRF, XSS, fishing, injection attacks, vulnerability scanning, dependency management, and more).
- Analyze software designs and implementations of existing and new Symphony Communications services with a focus on security and privacy
- Design, develop and operate scalable engineering solutions to advance data protection and privacy in on-prem and in-cloud computing
- Work effectively with other teams across the company to further improve data protection and privacy of user data in the cloud
- Advocate strong security and privacy design across Symphony Communications
- Provide security consulting services internally to the engineering organization by giving guidance and functioning as an information security SME
- Act in a mentoring capacity for team members and further technical skills through certifications and continual self-learning.
- 5+ years of experience in one or more of the following information security domains: cryptography, identity and access management, enterprise security, data or application security
- 10+ years experience designing, implementing, testing, releasing, and maintaining distributed, high performance software systems in Java
- Master’s degree in Computer Science, Information Systems, or related field;
- Technical excellence in Java
- Extensive experience with cryptography, Java Security Providers, Java key store, PKI, Certificate Authority=
- Deep familiarity with design patterns, multi-threaded programming and REST web services
- Experience with distributed systems, persistence, caching, concurrent programming, NoSQL
DESIRED BUT NOT REQUIRED:
- Experience architecting and implementing enterprise security strategies for cloud adoption
- Hands-on technical expertise in Security Architecture, automation, integration, and deployment (DevOps)
- Industry certifications preferred (CISSP, CCSP, CISA, GIAC, etc…)
- Experience in our stack (GCE, AWS and related services (big table, dynamo dB, pub/sub, SQS)
Symphony is the cloud-based messaging and collaboration platform that connects markets, organizations and individuals, securely. Powered by an open and growing app ecosystem, and protected with customer-owned encryption keys, Symphony’s communication platform increases workflow productivity while maintaining global regulatory compliance. Already the platform of choice for the financial services industry, Symphony eliminates inefficient workflows to boost productivity in information-driven businesses. Founded in October 2014 and headquartered in Palo Alto, CA, the company has offices in New York, Hong Kong, Singapore and London.
Symphony has raised $170 million from the world’s largest financial institutions and recognized investors such as Bank of America - Merrill Lynch, Citibank, Goldman Sachs, JP Morgan Chase, BlackRock, Credit Suisse, Deutsche Bank, HSBC, Wells Fargo, UBS, Société Générale as well as Google.
We’re looking for top-notch talent to join our team to help us change the way the world communicates. If you have the skills and savvy to work with a world-class team and an appetite for game-changing disruption, we want to hear from you!
BENEFITS AND PERKS*:
- Medical, dental, and vision coverage
- 401(K) plan
- Life and AD&D coverage
- Short-term and long-term disability coverage
- Employee assistance program
- Flexible spending account benefits
- Unlimited vacation and sick time
- Fully stocked kitchen and catered or reimbursed lunches
- Discounted gym memberships
- Many other fun and exciting benefits and activities!
Competitive salary, Bonus Plan, Equity
Symphony reserves the right of ownership for all unsolicited resumes submitted for this requisition and is not responsible for any fees associated with unsolicited resumes. Symphony appreciates your interest in our company. Symphony is an Equal Opportunity Employer.
Meet Some of Symphony's Employees
As a UX developer, Matt perfects the surface of the app, collaborating with his cross-functional team as they translate user feedback into code to create a truly enjoyable user experience.
Back to top