Product Security Engineer
Group 1001
Group 1001 is a consumer-centric, technology-driven family of insurance companies on a mission to deliver outstanding value and operational performance by combining financial strength and stability with deep insurance expertise and a can-do culture. Group1001’s culture emphasizes the importance of collaboration, communication, core business focus, risk management, and striving for outcomes. This goal extends to how we hire and onboard our most valuable assets – our employees.
Why This Role Matters
As a Product Security Engineer at Group 1001, you will lead efforts to integrate security best practices into the full product development lifecycle, ensuring the security and integrity of our revenue-generating applications and systems from design to deployment. This role requires experience across a number of security disciplines, including application security, cloud security, platform engineering, software engineering, and process improvement. This is an exciting opportunity to exert significant positive change by driving secure development practices and delivering security features to our end-user and internet-facing applications/systems in partnership with highly successful development teams for profitable businesses.
How You'll Contribute
- Collaborate with development teams to employ, improve, and customize automated security analysis tooling.
- Contribute security improvements and features to production applications and supporting infrastructure.
- Commoditize developed security features and integrations to be leveraged across disparate engineering teams and their respective applications.
- Conduct security reviews and provide guidance on architectural designs to address security requirements.
- Lead efforts to design security features into product applications and systems (avoiding bolt-on security implementations).
- Stay up to date on emerging threats and industry best practices in product security.
What We're Looking For
- Bachelor's degree in computer science or a related field.
- 5+ years of experience in product security, application security, software development, or related fields. Strong understanding of secure coding practices and common vulnerabilities (e.g. OWASP Top 10).
- Experience with application security testing tools and technologies (e.g. SAST, DAST, SCA). Proficiency in one or more software programming languages (e.g. Python, JavaScript/TypeScript, Java, Kotlin, Golang).
- Proficiency in one or more infrastructure automation frameworks (e.g. Terraform, Ansible). Familiarity with modern platform, API, and application frameworks (e.g. Kubernetes, ArgoCD, Apollo GraphQL).
- Familiarity with major cloud platforms (e.g. AWS, Azure, GCP).
- Excellent communication and interpersonal skills, with the ability to collaborate effectively with cross-functional teams.
Compensation:
Our compensation reflects the cost of labor across several U.S. geographic markets. The total compensation for this position ranges from $145,000/year in our lowest geographic market up to $215,000/year in our highest geographic market. Pay is based on a number of factors including market location and may vary depending on job-related knowledge, skills, and experience.
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Product Security Engineer. Be the first to apply!
