Enable job alerts via email!

Staff Product Security Engineer

M&T Bank

United States

Remote

USD 110,000 - 185,000

Full time

2 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

M&T Bank is seeking a Lead Product Security Engineer to enhance the software security culture across product development. The role encompasses collaboration with teams to implement security measures, provide guidance on secure coding, and manage vulnerability risks. Candidates should hold a degree in Computer Science with extensive experience in cybersecurity practices.

Benefits

Competitive pay
Mentoring programs
Work-life balance initiatives

Qualifications

  • Minimum 5 years of relevant work experience in cybersecurity.
  • Experience with security testing tools and fixing vulnerabilities.
  • Expertise in programming languages like Java, C#, and Python.

Responsibilities

  • Conduct code reviews and secure coding guidance.
  • Mentor product security engineers and DevSecOps professionals.
  • Develop analytics for effective vulnerability management.

Skills

Automation
Leadership
Problem-solving
Communication
Detail-oriented

Education

Bachelor’s degree in Computer Science

Tools

SAST
DAST
IAST
SCA

Job description

Overview:

As the Lead Product Security Engineer at M&T Bank, you will support and participate in the building and implementation of software security controls in all stages of the product development life cycle. This role will offer you the opportunity to be involved with a wide range of responsibilities in transforming the software security culture and technologies. We are looking for a highly motivated, talented, and hands-on engineer who will be responsible for identifying and mitigating software vulnerabilities through code reviews, security assessments, threat modeling, and providing secure coding guidance to software engineers. This role is integral to our technology transformation journey, ensuring the security posture of our bank-wide infrastructure and products.

Primary Responsibilities:
  • Collaborate with cross-functional teams to integrate security measures into the software development process including conducting code reviews, secure code guidance, threat modeling

  • Stay up to date on emerging threats and vulnerabilities, and proactively recommend security enhancements.

  • Partner with engineering teams and provide guidance and support to developers on secure coding practices and security best practices.

  • Mentor product security engineers and DevSecOps professionals to ensure a strong security posture across all software development and deployments.

  • Assist in the development of software security processes, configuration of tools, and management of solutions to tactically address software security vulnerabilities.

  • Build and support high quality security documentation for product security best practices.

  • Utilize product security scanning tools to track, analyze, and manage vulnerabilities.

  • Develop analytics to evaluate and enhance the effectiveness of the vulnerability management program including, tools, technologies, policies.

  • Communicate effectively with all levels of organizational leadership, conveying complex technical concepts in a clear and concise manner.

Education and Experience Required:

• Bachelor’s degree in Computer Science, Information Systems, Cybersecurity or applicable discipline and a minimum of 5 years of relevant work experience.

• Demonstrable experience developing and maintaining automation for product security tasks and defect identification.

• Advanced knowledge with industry standards and frameworks such as OWASP, ISO 27001, GDPR, PCI DSS, and NIST.

• Advanced experience with security testing tools and techniques and fixing vulnerabilities.

• Strong background in cybersecurity, manual code review, static/dynamic code analysis, threat modeling, bug bounty research and vulnerability management. • Experience with at least 2-3 of the following programming languages – Java, C#, JavaScript, Python, PHP, Ruby, Scala.

• Hands-on experience with product security tools and exploit tools and methods.

• Hands-on experience with product security testing tools such as SAST, DAST, IAST, SCA, and SBOM as well as experience with DevOps technologies such as CI/CD pipelines, repos, etc.

• Excellent communication and leadership skills.

• Capable of working on multiple projects of a complex nature

• Excellent problem-solving skills to assist in issue resolution.

• Detail-oriented with excellent verbal and written communication skills, with prior experience presenting to the target audience.

• Excellent organizational, teamwork, and time management skills

• Strong vertical thinking skills.

• Experience recommending and implementing security solutions.

• Experience driving project milestones and delivery dates.

• Proven mentoring and leadership capabilities.

Education and Experience Preferred:

• Cyber security certifications in the domain of product security or penetration testing (such as GWAPT, GCPEN, OSCP, CSSLP, CCSP).

• Proven experience in software development including architecture review & secure coding.

• Familiarity with mobile security testing.

• Strong understanding of mainframe, web productarchitectures, security protocols, and encryption.

• Familiarity with cloud security principles and practices.

• Experience running a bug bounty program.

• Knowledge of Cloud platforms such as AWS, GCP, Azure, Oracle.

#LI-JB3 #Remote

M&T Bank is committed to fair, competitive, and market-informed pay for our employees. The pay range for this position is $110,635.01 - $184,391.68 Annual (USD). The successful candidate’s particular combination of knowledge, skills, and experience will inform their specific compensation. The range listed above corresponds to our national pay range for this role. The specific pay range applicable to you may vary based on your location. Location Clanton, Alabama, United States of America
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Staff Product Security Engineer

Databricks

null null

Remote

Remote

USD 178,000 - 274,000

Full time

17 days ago

Staff Product Security Engineer

Databricks Inc.

null null

Remote

Remote

USD 178,000 - 274,000

Full time

10 days ago

Staff Cloud security Engineer

Teladoc Health, Inc.

null null

Remote

Remote

USD 160,000 - 180,000

Full time

18 days ago

Staff Security Engineer

MedStar Health

Mountain View null

Remote

Remote

USD 160,000 - 230,000

Full time

Yesterday
Be an early applicant

Staff Security Engineer

CVS Health

null null

Remote

Remote

USD 130,000 - 261,000

Full time

2 days ago
Be an early applicant

Staff Product Security Engineer

Data Direct Networks

null null

Remote

Remote

USD 100,000 - 150,000

Full time

30+ days ago

Staff Security Engineer

Quality Control Specialist - Pest Control

null null

Remote

Remote

USD 128,000 - 175,000

Full time

3 days ago
Be an early applicant

Staff Product Security Engineer

Vast

Long Beach null

On-site

On-site

USD 150,000 - 204,000

Full time

30+ days ago

Staff Security Engineer

Davita Inc.

Farmers Branch null

Remote

Remote

USD 120,000 - 152,000

Full time

14 days ago