FICO

Principal Engineer - Product Security - DevSecOps

Posted on: 13 Nov 2024

San Jose, CA

Job Description

The Opportunity?

 "As a Principal Engineer you will leverage your expertise with modern CI/CD systems to help establish the secure foundations for a new product development DevOps pipeline. As part of Product Security’s Engineering Engagement team you will collaborate directly with software development teams to enhance their focus on addressing security challenges and technical debt. You will collaborate closely with security engineers, architects, and software engineers to identify necessary Security architecture and design requirements. You will define and implement secure-by-default infrastructure and policy-as-code, create onboarding guidance, deploy automated security posture validation, and participate in threat modeling exercises."  - Senior Director, Cyber Security

What You’ll Contribute 

Collaborate between Cybersecurity, DevOps, and Development teams to achieve alignment between security and business objectives. 

Construct contextual security requirements for vendor tools and integrated systems. 

Develop vendor tool secure onboarding guidance for system administrators and users. 

Design and implement AWS based solutions using Terraform for automated Health Checks for security posture validation. 

Actively participate in security review and threat modeling exercises to identify risks. 

Provide technical guidance to development teams on security best practices, security architecture, and security controls. 

Integrate Application and DevOps processes with CI/CD pipelines of the software development lifecycle. 

Build CI/CD pipelines with Jenkins MPL and GitHub Actions for Security Artifacts. 

Leverage orchestration systems including Docker and Kubernetes to deliver security services. 

Integrate software service tools (Jenkins, jFrog Artifactory) into automation for security services. 

Evaluate and on-board security tools and/or scanners into the Security DevOps lifecycle for multiple tech stacks. 

Remediate code- and dependency-level security findings in partnership with product development teams. 

Introduce and enhance Continuous Monitoring (Cloud Architecture, App Performance and Logs) for security services. 

Evaluate the stability, compatibility, scalability, interoperability, and performance of software products. 

Contribute feature enhancements to internally developed Cybersecurity tools. 

Integrate Cybersecurity tools into the Security DevOps pipelines. 

Drive continuous improvement to both the Security DevOps pipelines, and to the Cybersecurity tools, services, and processes. 

Create and share practical demonstrations of proposed solutions. 

Mentor and train other engineers and support knowledge sharing. 

Drive technical discussions and serve as a source of technical expertise. 

What We’re Seeking 

Strong knowledge of programming, architecture, CI/CD, and automation. 

Solid experience with AWS API, EKS, and Terraform. 

Strong understanding and hands-on experience building CI/CD ecosystems to meet the demands of agile and secure development. 

Extensive architectural understanding of cloud security, Kubernetes, cloud-native computing, and microservices. 

Demonstrated ability to evaluate complex projects and clearly articulate secure design requirements, applying a “security mindset” and best-practices quality-first approach. 

Direct experience standing up and securely administering instances of ArgoCD, Crossplane, Akuity, Upbound Spaces, and Solo.io strongly preferred. 

Developer-level experience with Java and Golang strongly preferred. 

Direct experience standing up and securely administering instances of Artifactory, Backstage, Buf, and MongoDB preferred. 

Experience working within one or more compliance frameworks (PCI 4, SOC 2, ISO 27001) is a plus. 

Knowledge of Security Tools (DAST, SAST, SCA, IAST, IaC, etc.) is a plus. 

Experience leading or participating in threat modeling, penetration testing, and security reviews is a plus. 

Bachelor/Master's degree in computer science or related discipline, or relevant experience in software design, development, testing, and deployment. 

Our Offer to You

An inclusive culture strongly reflecting our core values:  Act Like an Owner, Delight Our Customers and Earn the Respect of Others.

The opportunity to make an impact and develop professionally by leveraging your unique strengths and participating in valuable learning experiences.

Highly competitive compensation, benefits and rewards programs that encourage you to bring your best every day and be recognized for doing so.

An engaging, people-first work environment offering work/life balance, employee resource groups, and social events to promote interaction and camaraderie.

The targeted base pay range for this role is: $151,000 to $237,000 with this range reflecting differences in candidate knowledge, skills and experience.
 

#LI-RR1

#LI-remote

FICO

San Jose, CA

FICO at a Glance

FICO’s groundbreaking use of Big Data and mathematical algorithms to predict consumer behavior has transformed entire industries. The company provides analytics software and tools used across multiple industries to manage risk, fight fraud, build more profitable customer relationships, optimize operations and meet strict government regulations. Many of our products reach industry-wide adoption — such as the FICO® Score, the standard measure of consumer credit risk in the United States. FICO solutions leverage open-source standards and cloud computing to maximize flexibility, speed deployment and reduce costs. The company also helps millions of people manage their personal credit health.

Founded in 1956, FICO introduced analytic solutions such as credit scoring that have made credit more widely available, not just in the United States but around the world. We have pioneered the development and application of critical technologies behind decision management. These include predictive analytics, business rules management and optimization. We use these technologies to help businesses improve the precision, consistency and agility of their complex, high–volume decisions.

A Global Presence

FICO has offices throughout the world serving industries including financial services, health care, insurance, automotive, public sector, retail, pharmaceuticals, telecommunications, travel and hospitality, media and entertainment, high tech and utilities.

Fortune 500 Clients

FICO clients include more than half of the top 100 banks in the world, more than 600 personal and commercial line insurers in North America and Europe including the top 10 US personal lines insurers, 400+ retailers and general merchandisers, including one-third of the top 100 U.S. retailers, 95 of the 100 largest financial institutions in the U.S., and all the 100 largest U.S. credit card issuers and more.

  • Industry
    Banking/Financial Services
  • No. of Employees
    3,400+
  • Jobs Posted
    152

Similar Jobs