Product Security Engineer (Remote)
Company
Enova
Location
Chicago, IL
Type
Full Time
Job Description
We are interested in every qualified candidate who is eligible to work in the United States. However, we are not able to sponsor visas or take over sponsorship at this time.
Enova is currently accepting candidates for remote positions in the following eligible states: AL, AK, AR, AZ, CT, GA, IA, ID, IL, IN, KY, LA, MA, ME, MD, MI, MN, MO, MS, NC, ND, NE, NH, NV, NJ, NM, OH, OK, OR, PA, RI, SC, SD, TN, UT, VT, WI, WV, WY.
About the role:Â
This is a hands-on role requiring in-depth knowledge of software security principles. You will be responsible for enabling security testing and enforcement across Enova Products. You will be responsible for prioritization and implementation of various DevSecOps projects and Tech initiatives which spans across all of Enova Products. In addition, you will be responsible for conducting application static code reviews, dynamic security assessments, secure architecture reviews. You will be expected to have a “can-do” attitude and work independently to drive solutions. Enova’s Security Engineering team designs, implements, and administers the tools and mechanisms involved with providing end to end IT security for Enova.
What you’ll be doing:Â
- Be a DevSecOps Evangelist.
- Conduct code reviews and security testing for new projects and initiatives
- Knowledge of Integrating Security Testing into the CI/CD Pipeline.
- Expertise in API Security testing.
- Automate security testing and embed security testing into the SDLC.
- Collaborate with architects, product managers, and other teams to deliver high quality secure productÂ
- Provide and Guide Secure Architecture Reviews.
- Perform internal/external application penetration tests.
- Lead projects independently while working collaboratively with the team to ensure its success.
- Run annual application security training for software developers.
We’re excited about you if you have:
- Experience with security testing tools such as Kali, Metasploit, Burp Suite, OWASP ZAP, etc.
- Proficiency with application pen testing and vulnerability assessments
- Experience with OWASP security concepts and discovering vulnerabilities such as XSS, XSRF, SQL Injection, Cookie Manipulation, etc.
- Understanding of static code analysis products
An ideal candidate may also have:
- Experience with Python, Go, Java, Ruby, JavaScript, PostgreSQL, React etc.
- Experience in Container security and cloud security/architecture patterns.
- OSCP, OSWE, SANs, AWS Security Speciality Certification, Certified Kubernetes Security Specialist (CKS).
- Experience with threat modeling and attack surface designÂ
About our team:
Our IT Security Engineering Team works alongside our teams in Systems, Monitoring, Application Engineering, and Network Engineering to deliver top notch and secure infrastructure and automation solutions. We are experts in the IT security field, but are also well-versed in applications, development life cycles, and automation techniques. We have passionate debates about technology with consensus in solutions, flexible team structures, an irrelevance of title in problem solving, and a desire to Do The Right Thing.
Enova currently uses a multitude of Application Security tools such as Checkmarx, Snyk, Burp Suite Pro, Anchore Container Security, AWS (GuardDuty, SecurityHub), GoSec. Our server and application platform primarily runs on Vmware and several workloads exist in Amazon, with plans to expand services into the cloud.
#LI-RC1
About Enova:
Enova is a leading financial technology company providing online financial services through its AI and machine learning powered lending platform. Enova serves the needs of non-prime consumers and small businesses, who are frequently underserved by traditional banks. Enova has provided more than 7 million customers with over $40 billion in loans and financing with market leading products that provide a path for them to improve their financial health. Want to learn more? Just ask any of our almost 1,500 employees.
Our goal at Enova, we believe that diversity and inclusion among our teammates is critical to our success as a global company, and we seek to recruit, develop and retain the most talented people from a diverse candidate pool. It is our policy to provide equal employment opportunity for all persons and not discriminate in employment decisions by placing the most qualified person in each job, without regard to any other classification protected by federal, state, or local law. California Applicants: Click here to review our California Privacy Policy for Job Applicants.
Date Posted
02/19/2023
Views
5
Similar Jobs
HVAC/R Service Tech 5 - Refrigeration - CoolSys
Views in the last 30 days - 0
Sr senior Service Tech refridgeration HVAC refrigeration HVACR HVACR diagnostic commercial service install mechanical mechanic apprentice AC
View DetailsAdvancement Reporting Analyst - The University of Chicago
Views in the last 30 days - 0
Conducts requirements analysis translating requirements into a scope document and developing reporting deliverables based on the design
View DetailsUnarmed Retail Security Officer - Per Mar Security Services
Views in the last 30 days - 0
The selected individual will patrol and secure assigned premises as well as identify risks to staff and patrons Are you looking to change careers
View DetailsSr Data Analyst - IDR Inc.
Views in the last 30 days - 0
4 years of experience with data visualization tools such as Alteryx and Power BI Collaborate with staff product teams IT and other functional areas wi...
View DetailsAWS Cloud Engineer - sg360°
Views in the last 30 days - 0
Bachelors degree in Computer Science Information Technology or related field AWS Certified SysOps Administrator DevOps Engineer or Solutions Architect...
View Details