Principal Application Security Engineer
6 days ago
Job ID 25 - 618 (2)
Come join our passionate team Barracuda is a leading cybersecurity company providing complete protection against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR service, to strengthen cyber resilience. Hundreds of thousands of IT professionals and managed service providers worldwide trust us to protect and support them with solutions that are easy to buy, deploy, and use.
We know a diverse workforce adds to our collective value and strength as an organization. Barracuda Networks is proud to be an Equal Opportunity Employer, committed to equal employment opportunity and equitable compensation regardless of race, gender, religion, sex, sexual orientation, national origin, or disability.
Envision yourself at BarracudaThe Principal Application Security Engineer assures the safety and security of Barracuda Networks software and services through source code review, manual application security assessment, operation and integration of automated security assessment solutions, architecture review, and expert advice regarding software security trends, threats, best practices and incidents. Through assuring the safety and security of Barracuda Networks software and services, the Application Security Engineer helps to keep our customers and their data safe and secure.
Tech Stack Exposure- A deep understanding of software security best practices and vulnerabilities, especially as they relate to web applications (e.g. OWASP Top 10)
- Experience identifying vulnerabilities in software and SaaS services
- Experience in source code review, preferably for Python, PHP and Go
- Experience in scoping and performing manual application penetration testing
- Experience in assessing the risk of identified vulnerabilities, and providing correct, robust and actionable recommendations to mitigate and/or resolve the vulnerabilities
- Experience in understanding software vulnerabilities, in finding other instances of the vulnerability across codebases, and in identifying collateral/related vulnerabilities.
- Experience in assessing the implemented resolution of a vulnerability for completeness and accuracy, and identifying bypasses for the implemented resolution
- Experience in working collaboratively with software development teams to identify vulnerabilities in all stages of software development
- Experience in communicating effectively with people of varying security proficiency and interest (fellow security professionals, engineering, and management)
- The ability to coordinate and participate in wide-scale Software Incident Security Response exercises such as the log4j response, understanding and unpacking information as incidents unfold, and in working across the organization to deliver a comprehensive "Identify, Resolve, Validate" solution
- Basic programming experience in at least one language, preferably Python or Go, and experience in automating routine tasks such as searching source code and manipulating data.
- Ensure the secure delivery of software from design through to implementation
- Maintain awareness of software security trends, incidents, and best practices, and provide expert advice and guidance to engineering teams regarding secure development and vulnerability remediation.
- Manage Barracuda's bug bounty programs
- Work collaboratively with the organization, including with Security, Compliance and Engineering, to understand and remediate computer and software security incidents
- Evaluate new and emerging security technologies, features, and products.
- 7+ years of experience
- The ability to perform source code review in new and unfamiliar languages using knowledge of security best practices and a willingness to read documentation
- Solutions architecture review experience, and the ability to identify opportunities and vulnerabilities early in the specification and development of software
- Threat modelling experience
- Fuzzing experience
- Experience using and integrating automated software security scanners such as SAST/DAST/SCA
- An understanding of Infrastructure as Code and cloud platform security (preferably Azure and AWS)
- An understanding of identity, authentication and authorization protocols including OAuth/OpenID Connect and SAML
- Published examples of work such as original research, vulnerability advisories, conference talks, bug bounty writeups or CTF writeups
- The ability to identify opportunities for process improvement, including automation and the authorship of software (scanners, fuzzers, helper utilities etc.)
- Experience participating in and/or managing bug bounty programs
- Experience with and/or a willingness to collaborate with other security functions such as compliance and policy, network/corporate security, security monitoring and incident response
A team where you can voice your opinion, make an impact, and where you and your experience are valued. Internal mobility – there are opportunities for cross training and the ability to attain your next career step within Barracuda. In addition, you will receive equity, in the form of non-qualifying options.
The anticipated on-target earnings range for this role is 146,000 to 167,000. Actual compensation offered will be dependent upon the individual's skills, experience, and qualifications as they directly relate to the requirements of the position, the budget for the position, and applicable employment laws.
#LI-hybrid
#J-18808-Ljbffr
-
Chief Application Security Engineer
3 days ago
Ottawa, Ontario, Canada Maplesoft Group Full timeMaplesoft Group is a forward-thinking organization that values innovation and excellence. We are committed to developing inclusive, barrier-free recruitment and selection processes, and a work environment that supports our diverse workforce.We are seeking a Chief Application Security Engineer to join our team. As a key member of our security team, you will...
-
Application Security Architect
5 days ago
Ottawa, Ontario, Canada Barracuda Networks Full timeAbout UsBarracuda Networks is a leading cybersecurity company providing complete protection against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR service, to strengthen cyber resilience. Hundreds of thousands of IT professionals and managed service providers worldwide trust us to...
-
Software Security Engineer Lead
5 days ago
Ottawa, Ontario, Canada Barracuda Networks Full timeAbout This OpportunityBarracuda Networks is a leader in the cybersecurity industry, providing innovative solutions to protect against complex threats. We are seeking a highly skilled Principal Application Security Engineer to join our team.As A Principal Application Security Engineer At Barracuda Networks, You Will:Ensure the secure delivery of software from...
-
Senior Data Engineer
3 days ago
Ottawa, Ontario, Canada Data Engineer Jobs Full timeJob Description:At Quantexa, we're innovating the data analytics market in ways no one else can. Our technology started out in FinTech, helping tackle serious criminal activity. Now, its potential is virtually limitless. We're a real team, collaborating and constantly engineering better solutions. As a senior data engineer, you'll bring it all together,...
-
Senior Application Security Engineer
4 weeks ago
Ottawa, Ontario, Canada Maplesoft Group Full timeMaplesoft implements TimeLive for Electronic time tracking.Please view the demo below on how to enter and approve time.Do you want to work in a dynamic environment where your contributions count?At Maplesoft, we value the contributions of all our employees and contractors. We listen and act upon suggestions, advice, and innovative ideas to further our...
-
Principal Cloud DevOps Engineer
4 weeks ago
Ottawa, Ontario, Canada Entrust Full timeEntrust is an innovative leader in identity-centric security solutions, providing an integrated platform of scalable, AI-enabled security offerings. Headquartered in Minnesota, we offer our colleagues the ability to work globally, in a flexible and collaborative environment. Entrust's technologies and expertise help government agencies, enterprises and...
-
Principal Cloud DevOps Engineer
2 weeks ago
Ottawa, Ontario, Canada Entrust Full timeEntrust is an innovative leader in identity-centric security solutions, providing an integrated platform of scalable, AI-enabled security offerings. Headquartered in Minnesota, we offer our colleagues the ability to work globally, in a flexible and collaborative environment. Entrust's technologies and expertise help government agencies, enterprises and...
-
Application Security Engineer
3 days ago
Ottawa, Ontario, Canada Software Secured Full timeSecure Applications with Us!Software Secured is a leading provider of Penetration Testing as a Service, committed to helping software development teams secure their applications. We are seeking an experienced Intermediate Pentester to join our team and help us deliver high-quality security services to our clients.In this role, you will be responsible for...
-
Principal Cloud DevOps Engineer
4 weeks ago
Ottawa, Ontario, Canada Entrust Full timeCareer Growth, Flexibility and Collaboration Entrust is an innovative leader in identity-centric security solutions, providing an integrated platform of scalable, AI-enabled security offerings. Headquartered in Minnesota, we offer our colleagues the ability to work globally, in a flexible and collaborative environment. Our team makes an impact The Company: ...
-
Principal Cloud DevOps Engineer
2 weeks ago
Ottawa, Ontario, Canada Entrust Full timeCareer Growth, Flexibility and Collaboration Entrust is an innovative leader in identity-centric security solutions, providing an integrated platform of scalable, AI-enabled security offerings. Headquartered in Minnesota, we offer our colleagues the ability to work globally, in a flexible and collaborative environment. Our team makes an impact The Company: ...
-
Principal Cloud DevOps Engineer
2 days ago
Ottawa, Ontario, Canada Entrust Full timeCareer Growth, Flexibility and CollaborationEntrust is an innovative leader in identity-centric security solutions, providing an integrated platform of scalable, AI-enabled security offerings. Headquartered in Minnesota, we offer our colleagues the ability to work globally, in a flexible and collaborative environment. Our team makes an impactThe Company :...
-
Application Security Architect
15 hours ago
Ottawa, Ontario, Canada Marsh & McLennan Companies Full time**Job Overview**Application Security Architect - Secure SDLCWe are seeking an experienced application security architect to lead our Secure SDLC initiatives and drive the implementation of secure software development lifecycle processes.Key Responsibilities:Design and develop secure SDLC frameworks and guidelines for application development teamsEvaluate and...
-
Senior Security Engineer 3, Product
2 weeks ago
Ottawa, Ontario, Canada Pager Full timeSenior Security Engineer 3, Product & Application SecurityTorontoPagerDuty empowers teams of all kinds to do the critical work that moves business forward through the PagerDuty Operations Cloud.PagerDuty is seeking a Senior Security Engineer to join our diverse, customer-focused team As a Senior Security Engineer, you will be a key contributor in leading,...
-
Quantexa Senior Data Engineer
4 days ago
Ottawa, Ontario, Canada Data Engineer Jobs Full timeJob Description: What we're all about. It isn't often you get to be part of a tech company that, since 2016, has been innovating the data analytics market in ways no one else can. Our technology started out in FinTech, helping tackle serious criminal activity. Now, its potential is virtually limitless. Working at Quantexa isn't just intellectually...
-
Professional Services Engineer
2 weeks ago
Ottawa, Ontario, Canada acre security Full timeAre you passionate about shaping the future of security solutions? Do you thrive in an environment that values innovation and teamwork? If so, acre security is the place for you Join us in making the world a safer place, one innovation at a time.Position: Professional Services EngineerLocation: Ottawa/ CanadaA Bit About Us:At acre, we're not just creating...
-
Senior Application Security Specialist
2 days ago
Ottawa, Ontario, Canada Maplesoft Group Full timeMaplesoft Group is a dynamic company that implements innovative solutions for electronic time tracking. We are seeking a Senior Application Security Engineer to join our team.The ideal candidate will have 7+ years of experience in security advisory, application security, or cloud security roles. They will be responsible for defining and owning the security...
-
Data Engineering Specialist
3 days ago
Ottawa, Ontario, Canada Data Engineer Jobs Full timeAbout Us:We're a collection of bright, passionate minds harnessing complexities and helping our clients and their communities. One culture, made of many. Heading in one direction - the future. At Quantexa, we have one mission: to help businesses grow, make data easier, and make the world a better place.About the Role:We're seeking a highly skilled senior...
-
Security Engineer-Automation Engineer
2 weeks ago
Ottawa, Ontario, Canada High Tech Genesis Inc. Full timeLocation: On-site in Ottawa, ONMust be willing to relocateTerm: Full time, permanentThe Security Automation Engineer is responsible for analyzing, designing, implementing, and maintaining security best practices in applications, IT infrastructure, and operations. The role requires conducting security assessments, automating security scans, ensuring...
-
Security Engineer-Automation Engineer
7 days ago
Ottawa, Ontario, Canada High Tech Genesis Inc. Full timeLocation: On-site in Ottawa, ONMust be willing to relocateTerm: Full time, permanentThe Security Automation Engineer is responsible for analyzing, designing, implementing, and maintaining security best practices in applications, IT infrastructure, and operations. The role requires conducting security assessments, automating security scans, ensuring...
-
radio frequency engineer
7 days ago
Ottawa, Ontario, Canada Communications Security Establishment (CSE Full timeEMPLOYER: Communications Security Establishment (CSE) JOB DESCRIPTION: START DATE IS APPROXIMATE, DEPENDENT ON SECURITY SCREENING*** Communications Security Establishment (CSE) is Canada's national cryptologic agency. Unique within Canada's security and intelligence community, we employ code-makers, codebreakers, and secure system creators to provide the...