[SVLUG-Jobs] Box.com: Sr. Security Architect, Los Altos
Rick Moen
rick at linuxmafia.com
Tue Sep 10 18:41:53 PDT 2013
Sr. Security Architect
Technical Operations | Los Altos, CA, United States
The Application Security Architect (ASA) will provide software
development lifecycle security support to application development teams.
The ASA will be involved in all six atomic phases of Boxâs SDLC
(Requirements and Use Cases, Architecture and Design, Test Plans, Code,
Test Results and Feedback From the Field). The ASA must understand
Boxâs application architecture and features, how existing software
components interact and how newly proposed components will integrate and
interact. The ASA must use this understanding to apply security
touchpoints at each phase of the SDLC. This ranges from attack modeling
and abuse case design to code review, penetration testing and vetting of
newly identified vulnerabilities. While performing this role, the ASA
will update developers and QA staff on emerging attack vectors and
appropriate countermeasures.
This role will also serve as a resource cross-functionally to provide
security advice, support technical risk assessments, assist the Incident
Response team with investigations and incidents, and possibly to
implement vulnerability fixes.
Additional skills that are critical to this role include in-depth,
hands-on understanding of application architectures and technology,
including web applications, LAMP, web 2.0, strong authentication and
encryption.
Responsibilities:
Create abuse cases which map to use cases
Perform design-phase risk assessment
Ensure software security requirements are current, appropriate and are
met
Assist in creating risk-based security tests for QA staff
Ensure source code is reviewed via static analysis prior to code push
Ensure systems are tested via dynamic analysis prior to deployment
Assist developers and QA staff with interpretation of results from
analysis tools
Perform post-code risk analysis
Work with Information Security staff to perform penetration testing of
critical application changes prior to and after deployment
Work with developers to triage vulnerabilities reported by third parties
Facilitate customer penetration testing and vulnerability analysis of
Boxâs applications
Qualifications:
Excellent understanding of application security, including:
Attack types and appropriate prevention, remediation and mitigation
strategies
OWASP Top Ten
Static source code analysis tools and techniques
Methods for ensuring effective testing via dynamic analysis tools
Use of web app proxies to perform security testing
Vulnerability analysis and penetration testing
Excellent understanding of Web 2.0 technology
Excellent understanding of common PHP vulnerabilities
Ability to quickly and thoroughly understand and assess complex
applications and proposed changes for security implications
Strong PHP programming skills
Strong knowledge of relational databases
Understanding of common security flaws with popular mobile platforms,
including iOS and Android
Understanding of attack and threat modeling
Experience in research and development
Self-motivated with the ability to work independently and as a team
member with minimal direction
About Box:
Box provides a secure way to share content and improve collaboration on
any device. Desktop, tablet or mobile. From monolithic corporations to
mom and pop stores, Box believes technology should never limit anything
you do. Businesses of any size can be more productive, inventive and
powerful on Box. The company is well funded by top VC firms like
Andreessen Horowitz, Draper Fisher Jurvetson and U.S. Venture Partners.
Box is proud to be on Forbesâ list of Americaâs Most Promising
Companies, is used in 180,000 businesses - including 97% of the Fortune
500 â and is the go-to product of 20 million people.
https://www.box.com/about-us/careers/open-positions/?jvi=oXZpWfw1,Job
More information about the Jobs
mailing list