Aumni - Security Engineer III
Aumni
Job Description
As a Security Engineer III at JPMorgan Chase within the Aumni Line of Business, you serve as a seasoned member of a team that works to deliver software solutions that satisfy pre-defined functional and user requirements with the added dimension of preventing misuse, circumvention, and malicious behavior. Carry out critical technology solutions with tamper-proof, audit defensible methods across multiple technical areas within various business functions in support of the firm’s business objectives.
The Aumni Information Technology & Security department is responsible for maintaining the IT operations and security of Aumni’s product, systems, and data. We collaborate with all other departments in various capacities with an emphasis on reducing friction where possible while maintaining security.
Our team’s mission statement is:
To deliver stronger, smarter security solutions, provide peace of mind for the venture capital ecosystem, and enable the success of our customers, employees, and investors.
If you don’t have experience in each area listed below, don’t let that discourage you from applying. We are looking for an individual with a strong foundation, an aptitude to learn, and ability to ask good questions.
Job responsibilities
- Educate our software engineers on secure coding practices and even build out a robust security champions program
- Provide vulnerability remediation support
- Implement & manage various SAST, SCA, DAST, and OSS scanning tools.
- Maintain automations that enforce Secure SDLC
- Secure design reviews
Required qualifications, capabilities, and skills
- Formal training or certification on Application Security concepts and 2+ years applied experience
- Must be a team player who is eager to share domain knowledge with the team and eager to learn from others as well
- Experience of the Secure Software Development Lifecycle Framework.
- Understanding of security best practices for authentication, authorization, and permissions.
- Ability to teach developers how to follow security best practices
- Hands on experience investigating & prioritizing vulnerabilities discovered by third party security tools. (Identifying false positives, out of scope items, adjusting CVSS severity of vulnerability to business context, etc.)
- Hands on experience with DAST tools
- Knowledgeable of CI/CD tools and how to integrate security into the pipeline
- Experience with scripting languages (Bash, Python, etc.)
- Experience with cloud platforms and securing them
- Secure Design Reviews
- Experience configuring and monitoring secret scanning tools
- Experience performing high risk code review/testing
- Knowledge of well-known Security Frameworks (ASVS, NIST CSF)