ShipBob

Principal Security Engineer

Remote US
Go Python Bash PowerShell SQL Azure Kubernetes
This job is closed! Check out or
Description

As a member of the ShipBob Team, you will benefit from an environment where everything is achievable. We aim to be a place where you can:

  • Write Your Career Story.  Because we are solving some of the most difficult problems in global commerce, you have the opportunity to write the story that will make your career.
  • Experience Global Impact and Global Connection.  At ShipBob we benefit from diverse cultures and perspectives in service of the global community.
  • Grow With An Ownership Mindset. We believe that great innovation comes from great transparency.  We are more resilient and more creative when we have an inclusive and transparent culture where everyone knows our strengths and opportunities.

Title: Principal Security Engineer

Location: Remote in these states: AZ, CA, CO, FL, GA, KS, KY, ID, IL, IN, MA, MI, MN, MO, NC, NH, NJ, NV, NY, OH, OR, PA, RI, SC, SD, TN, TX, VA, VT, WA, WI

Role Description:

As a Principal Security Engineer, you will help manage and implement enterprise information security priorities including management of the company's efforts to maintain ISO 27001 certification and SOC2 compliance; including but not limited to overall security posture, production data & system security and corporate network security. As part of the Information Technology Security team, this person will build relationships throughout the enterprise to bring internal business stakeholders and their projects and initiatives into the company’s comprehensive security posture.

What you’ll do:

  • Work with Sr. Director of Information Technology and Manager of Security and Compliance to design and implement application security processes and controls.
  • Assist with implementation, management, review, and maintenance in accordance with ISO 27001 and SOC2 compliance requirements.
  • Serve as the main point of contact for application security and privacy related matters.
  • Actively manage projects in the areas of risk management, risk assessment, governance and security program development.
  • Assist with IT and information security risk assessments.
  • Create and manage security and privacy strategies.
  • Oversee application security audits (either internal or with services provided by third-party vendor).
  • Partner with Operations, Engineering and Corporate IT to analyze existing application security defenses and make recommendations for changes / improvements.
  • Assess current application architecture for vulnerabilities, weaknesses and for possible upgrades or improvement.
  • Organize, conduct and/or orchestrate periodic tests and “ethical hacks”.
  • Communicate and visualize security system status and keep users informed.
  • Assist with RFPs and other security-oriented questionnaires.
  • Keep technical knowledge current through continuing education.
  • Implement and oversee technological upgrades, improvements and major changes to the application environment.
  • Communicate data and application security and privacy goals effectively; collaborate with other departments to push success.
  • Additional duties and responsibilities as necessary.

What you’ll bring to the table:

  • Advanced knowledge of application security standards, principles and practices.
  • Advanced knowledge of securing various cloud-based application types.
  • Demonstrated relevant security expertise in implementing secure solutions and services for a mix of the following areas: Secure Web Gateways, Data Loss Prevention, Application Security, Database Security (MS-SQL), Compliance - SOX, PCI, ISO 27001, Cloud, Colocation, Cloud Technologies, Forensics, Cyber Intelligence National and International Privacy laws and regulations.
  • Knowledge in the following areas are highly desirable: Databases, Encryption, PKI, Identity Management, Certificate Management, Integrity Monitoring.
  • Proficient at the techniques that go into the implementation of solution architectures, including requirements discovery and analysis, application of abstraction, formulation of solution context, solution alternatives identification and assessment, technology selection, and implementation.
  • Experience with CI/CD pipelines using toolsets like Azure DevOps, Jenkins, CircleCI, Artifactory, etc.
  • Experience with delivering and managing solutions on Azure required.
  • Experience with WhiteSource Bolt, Qualys Vulnerability Management, or SonarQube is a plus.
  • Experience with containers, container runtimes (i.e. Kubernetes), and/or serverless technologies.
  • Proficient in at least one scripting language (Go, Python, Bash, PowerShell).
  • Able to successfully elicit requirements from appropriate business partners and stakeholders (e.g. functional, performance, technical, compliance), and identify solutions to non-standard requests.
  • Self-directed and comfortable with working in a fast-paced, results-oriented environment.
  • Able to assess risk and translate it to business relevant considerations and facts.
  • Demonstrate pride in work, showing focus, high attention to detail and build quality, and a sense of urgency to reach goals on time.
  • Critical thinking and proactive problem solving, appropriately challenges the status quo.
  • Able to take a new perspective using or improving on existing solutions.
  • Excellent verbal and written communication skills to effectively collaborate and build consensus with both business and technical teams.
  • Actively participates by sharing information, offering suggestions and taking initiative to get things done.
  • Able to learn and apply new concepts quickly.
  • Able to independently and effectively handle multiple competing priorities and make good use of resources (e.g. time, people, money).
  • Must be trustworthy in keeping sensitive data confidential.

Classification: Exempt

Reports to: Senior Director, Information Technology

Perks & Benefits:

  • Medical, Dental, Vision & Basic Life Insurance
  • Paid Maternity/Parental Leave Program
  • Flexible Time Off Program
  • Quarterly Wellness Day
  • 401K Match 
  • Competitive Salary, Performance Bonus & Equity
  • Variety of voluntary benefits, such as, short term disability
  • Referral Bonus Program
  • Fun Culture >>> Check us out on Instagram (@lifeatshipbob)

We recognize that people come with a wealth of experience and talent beyond just the technical requirements of a job. If your experience is close to what you see listed here, please still consider applying. Diversity of experience and skills combined with passion is a key to innovation and excellence; therefore, we encourage people from all backgrounds to apply to our positions.

About You:

At ShipBob, we’re looking to bring on board people who embody our core values:

  • Be Mission-Driven.  We want team members that are passionate about helping entrepreneurs improve their business, and bring that passion every day.
  • Be Humble. We have ambitious goals, and our team members understand that success or failure depends on us working together and leaving egos at the door.
  • Be Resilient. Logistics is a complicated business. So is software. We value team members that never give up and keep iterating until a problem is solved.
  • Be a Creative Problem Solver. As a startup, we value smart, innovative solutions to complex problems. We fall in love with the problem, not our “favorite” solution.
  • Be Safety Minded. It’s not just talk; it’s the way you work.

About Us: 

ShipBob is a cloud-based logistics platform that partners with over 7,000+ e-commerce businesses to help make their entrepreneurial dreams a reality. We offer a full suite of fulfillment solutions for our merchants, including the ability to improve their transit times, shipping costs and deliver best in class experience to their customers. With an almost 100% accuracy rate in fulfilling orders and orders shipped on time, our merchants can count on us to deliver excellent service. 

As one of the fastest growing tech companies in Chicago with over $330M+ raised from blue-chip investors like Menlo Ventures, Bain Capital Ventures, Hyde Park Venture Partners and SoftBank Vision Fund 2, our goal is to continue to be the #1 best fulfillment technology in the industry. 

ShipBob provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

 

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

50,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 210 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

Cancel anytime / Money-back guarantee

Wall of love from fellow engineers