Principal Application Security Engineer

2 weeks ago


Ottawa, Canada Barracudamsp Full time

Job ID 25-439(2)

Come Join Our Passionate Team At Barracuda, we make the world a safer place. We believe every business deserves access to cloud-enabled, enterprise-grade security solutions that are easy to buy, deploy, and use. We protect email, networks, data and applications with innovative solutions that grow and adapt with our customers’ journey. More than 200,000 organizations worldwide trust Barracuda to protect them — in ways they may not even know they are at risk — so they can focus on taking their business to the next level.

We are committed to a candidate selection process and work environment that is inclusive and barrier free. To ensure candidates are assessed in a fair and equitable manner, accommodations will be provided to prospective employees in accordance with the Accessibility for Ontarians with Disabilities Act (AODA) and the Ontario Human Rights Code.

Envision yourself at Barracuda

The Principal Application Security Engineer assures the safety and security of Barracuda Networks software and services through source code review, manual application security assessment, operation and integration of automated security assessment solutions, architecture review, and expert advice regarding software security trends, threats, best practices and incidents. Through assuring the safety and security of Barracuda Networks software and services, the Application Security Engineer helps to keep our customers and their data safe and secure.

Tech Stack Exposure
  • A deep understanding of software security best practices and vulnerabilities, especially as they relate to web applications (e.g. OWASP Top 10)
  • Experience identifying vulnerabilities in software and SaaS services
  • Experience in source code review, preferably for Python, PHP and Go
  • Experience in scoping and performing manual application penetration testing
  • Experience in assessing the risk of identified vulnerabilities, and providing correct, robust and actionable recommendations to mitigate and/or resolve the vulnerabilities
  • Experience in understanding software vulnerabilities, in finding other instances of the vulnerability across codebases, and in identifying collateral/related vulnerabilities.
  • Experience in assessing the implemented resolution of a vulnerability for completeness and accuracy, and identifying bypasses for the implemented resolution
  • Experience in working collaboratively with software development teams to identify vulnerabilities in all stages of software development
  • Experience in communicating effectively with people of varying security proficiency and interest (fellow security professionals, engineering, and management)
  • The ability to coordinate and participate in wide-scale Software Incident Security Response exercises such as the log4j response, understanding and unpacking information as incidents unfold, and in working across the organization to deliver a comprehensive "Identify, Resolve, Validate" solution
  • Basic programming experience in at least one language, preferably Python or Go, and experience in automating routine tasks such as searching source code and manipulating data.
What you’ll be working on
  • Ensure the secure delivery of software from design through to implementation
  • Maintain awareness of software security trends, incidents, and best practices, and provide expert advice and guidance to engineering teams regarding secure development and vulnerability remediation.
  • Manage Barracuda’s bug bounty programs
  • Work collaboratively with the organization, including with Security, Compliance and Engineering, to understand and remediate computer and software security incidents
  • Evaluate new and emerging security technologies, features, and products.
What you bring to the role
  • 7+ years of experience
  • The ability to perform source code review in new and unfamiliar languages using knowledge of security best practices and a willingness to read documentation
  • Solutions architecture review experience, and the ability to identify opportunities and vulnerabilities early in the specification and development of software
  • Threat modelling experience
  • Fuzzing experience
  • Experience using and integrating automated software security scanners such as SAST/DAST/SCA
  • An understanding of Infrastructure as Code and cloud platform security (preferably Azure and AWS)
  • An understanding of identity, authentication and authorization protocols including OAuth/OpenID Connect and SAML
  • Published examples of work such as original research, vulnerability advisories, conference talks, bug bounty writeups or CTF writeups
  • The ability to identify opportunities for process improvement, including automation and the authorship of software (scanners, fuzzers, helper utilities etc.)
  • Experience participating in and/or managing bug bounty programs
  • Experience with and/or a willingness to collaborate with other security functions such as compliance and policy, network/corporate security, security monitoring and incident response
What you’ll get from us

A team where you can voice your opinion, make an impact, and where you and your experience are valued. Internal mobility – there are opportunities for cross training and the ability to attain your next career step within Barracuda. In addition, you will receive equity, in the form of non-qualifying options.

The anticipated on-target earnings range for this role is 146,000 to 167,000. Actual compensation offered will be dependent upon the individual's skills, experience, and qualifications as they directly relate to the requirements of the position, the budget for the position, and applicable employment laws.

#J-18808-Ljbffr

  • Ottawa, Canada Synopsys, Inc. Full time

    p>At Synopsys, we’re at the heart of the innovations that change the way we work and play.Self-driving cars, Artificial Intelligence, cloud, 5G, The Internet of Things and more are ushering in the Era of Smart Everything, and we’re powering it all with the world’s most advanced technologies for chip design and software security.If you share our passion...

  • Application Security

    3 months ago


    Ottawa, Canada Ouster Full time

    We've transformed LIDAR from an analog device with thousands of components to an elegant digital device powered by one chip-scale laser array and one CMOS sensor. Our advanced sensor hardware and vision algorithms are used in autonomous cars, drones and many other applications. If you’re motivated by solving big problems, we’re hiring key roles across...


  • Ottawa, Canada Thales Full time

    Location: Ottawa, CanadaThales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billons of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more....


  • Ottawa, Canada https:www.energyjobline.comsitemap.xml Full time

    Location: Ottawa, Canada Thales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billions of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much...


  • Ottawa, Canada Entrust Limited Full time

    The Company: Entrust relies on curious, dedicated and innovative individuals whom anticipate the future and provide solutions for a more connected, mobile and secure world. Entrust’s technologies and expertise help government agencies, enterprises and financial institutions in more than 150 countries serve and safeguard citizens, employees and...


  • Ottawa, Canada The Chemical Engineer Full time

    p>Chemistry that MattersA career at SABIC provides you with an opportunity to leave a lasting positive impact on the world and yourself. From excellent health and well-being benefits to our comprehensive learning programs, we offer a wide range of benefits that recognize that our people have unique motivations and ambitions. p>As one of the world’s largest...


  • Ottawa, Canada Synopsys, Inc. Full time

    ASIC Digital Design Verification - Principal EngineerSynopsys is a worldwide leading supplier of semiconductor IP, which is used by our customers to design semiconductor integrated circuits. The product portfolio includes IP components and subsystems for Security, USB, DDR, PCIe/CXL, CPU cores, processor peripherals, embedded memories, and much more.For the...


  • Ottawa, Ontario, Canada Veeva Systems, Inc. Full time

    Veeva Systems, Inc. is a pioneer in industry cloud solutions, revolutionizing the life sciences sector by enabling companies to bring therapies to patients faster. The company's mission-driven approach emphasizes Customer Success, Employee Success, and Speed.The organization is committed to supporting its employees' flexibility and work-life balance by...


  • Ottawa, Canada Ainsworth Inc. Full time

    If you thrive in a team-oriented workplace that challenges your skills, to drive your career development, embraces diversity and rewards innovation, with competitive pay and great employee programs, join the Ainsworth, a subsidiary of GDI, team today!Position Summary:Reporting to the Project Manager, the Security Systems Application Specialist is responsible...


  • Ottawa, Ontario, Canada Axiad Ids, Inc. Full time

    Job DescriptionAxiad, a leading provider of identity and access management solutions, is seeking an experienced Cloud Security Engineer to join its Cloud team.This is a unique opportunity to lead the design, development, and deployment of highly secure and scalable cloud services. As a Cloud Security Engineer, you will be responsible for implementing...


  • Ottawa, Canada MDA Space Full time

    h3>Systems Security Engineer - Cyber SecurityMDA SpaceWith a 55-year record of firsts and 450+ missions, MDA Space is a trusted space mission partner to the rapidly expanding global space industry. Serving the world from our Canadian home and our global offices, MDA is an international space mission partner and robotics & space operations, satellite systems...


  • Ottawa, Canada Synopsys, Inc. Full time

    ASIC Digital Design Verification - Principal EngineerSynopsys is a worldwide leading supplier of semiconductor IP, which is used by our customers to design semiconductor integrated circuits. The product portfolio includes IP components and subsystems for Security, USB, DDR, PCIe/CXL, CPU cores, processor peripherals, embedded memories and much more.For the...


  • Ottawa, Canada Open Text Corporation Full time

    **Principal Product Manager**: - Req id: 40405- Ottawa, ON, CA Mississauga, ON, CA Richmond Hill, ON, CA Waterloo, ON, CA**OPENTEXT** OpenText is a global leader in information management, where innovation, creativity, and collaboration are the key components of our corporate culture. As a member of our team, you will have the opportunity to partner with...


  • Ottawa, Canada Open Text Corporation Full time

    **Principal Product Manager**: - Req id: 40151- Ottawa, ON, CA**OPENTEXT** OpenText is a global leader in information management, where innovation, creativity, and collaboration are the key components of our corporate culture. As a member of our team, you will have the opportunity to partner with the most highly regarded companies in the world, tackle...

  • RF Systems Engineer

    3 weeks ago


    Ottawa, Ontario, Canada Communications Security Establishment (CSE Full time

    Career Opportunities at the Communications Security Establishment (CSE)About CSE: As Canada's national cryptologic agency, we employ experts in code-making, code-breaking, and secure system creation to provide the Government of Canada with cybersecurity and foreign signals intelligence services.Critical Role of RF Engineers: We are seeking highly skilled...


  • Ottawa, Ontario, Canada CIMA+ Full time

    Company OverviewCIMA+ is a leading provider of infrastructure solutions in Ontario, Canada. Our team of experts has extensive experience in designing and delivering water and wastewater infrastructure projects.SalaryThe estimated annual salary for this position ranges from $120,000 to $150,000 based on industry standards and the location in Kitchener or...


  • Ottawa, Ontario, Canada Macdonald, Dettwiler And Associates Corporation Full time

    About the RoleAs a Principal Engineering Manager for EW Systems, you will be responsible for leading a team of engineers in the development and integration of complex systems. Your primary goal will be to deliver quality products and services within a committed budget and schedule.Key ResponsibilitiesLead teams through the system development and...


  • Ottawa, Canada Thales Full time

    Location: Ottawa, CanadaThales people architect identity management and data protection solutions at the heart of digital security. Business and governments rely on us to bring trust to the billons of digital interactions they have with people. Our technologies and services help banks exchange funds, people cross borders, energy become smarter and much more....


  • Ottawa, Canada CB Canada Full time

    Company DescriptionFounded in 1967, ADGA is a privately owned and operated Canadian company. We employ over 700 highly skilled team members who apply their knowledge and expertise in service delivery of advanced technology solutions for clients in the Defence, Security and Enterprise Computing markets across Canada.Celebrating over 50 years in business, we...


  • Ottawa, Ontario, Canada Ainsworth Inc. Full time

    Ainsworth Inc. is a leading integrated multi-trade company that offers end-to-end services and solutions for all asset maintenance and refurbishment requirements of our customers. We are committed to creating better and more advanced products, providing the highest quality service, and continually striving to improve.We are currently seeking an experienced...