Now hiring

Software Product Security Engineer (Monterrey, NLE, MX) @ Celestica Jobs

MXOnsiteFull-time
Apply with ResuMinder

Opens on the employer's site

About this role

<p>Req ID: 133574 <br> Remote Position: No<br> Region: Americas <br> Country: Mexico <br> State/Province: Nuevo Leon <br> City: Monterrey </p> <div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">General Overview</H2> </div><div><p><b>Functional Area: </b>Information Technology (ITM)<br> <b>Career Stream: </b> IT Solutions (SOLN)<br> <b>Role: </b>Specialist (SPE)<br> <b>Job Title: </b>Specialist, IT Solutions <br> <b>Job Code: </b>SPE-ITM-SOLN<br> <b>Job Level: </b> Band 8<br> <b>Direct/Indirect Indicator: </b> Indirect</p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Summary</H2> </div><div><p style="margin-top:0.0pt;margin-bottom:12.0pt"><span style="font-size:11.0pt;font-family:Arial, sans-serif">A Software Product Security role (often called </span><strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">Product Security Engineer</span></strong><span style="font-size:11.0pt;font-family:Arial, sans-serif"> or </span><strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">ProdSec</span></strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">) is the bridge between traditional cybersecurity and software engineering. Unlike IT security, which focuses on protecting the company&apos;s internal network, Product Security focuses on ensuring the software the company </span><em><span style="font-size:11.0pt;font-family:Arial, sans-serif">sells or provides</span></em><span style="font-size:11.0pt;font-family:Arial, sans-serif"> is resilient against attacks.</span></p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Detailed Description</H2> </div><div><p><span style="font-size:11.0pt;font-family:Arial, sans-serif">The Product Security Engineer works directly with DevOps and Engineering teams to bake security into the </span><strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">Software Development Life Cycle (SDLC)</span></strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">. The goal is to move security "left"—finding and fixing vulnerabilities during the design and coding phases rather than after the product has launched.</span></p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Knowledge/Skills/Competencies</H2> </div><div><ul> <li> <ul style="margin-top:0.0px;margin-bottom:0.0px"> <li style="font-size:11.0pt;font-family:Arial, sans-serif"> <p style="margin-top:0.0pt;margin-bottom:0.0pt"><strong><span style="font-size:11.0pt">Secure Design &amp; Threat Modeling:</span></strong><span style="font-size:11.0pt"> Reviewing new features before a single line of code is written. You’ll identify potential attack vectors and suggest mitigations.</span></p> </li> <li style="font-size:11.0pt;font-family:Arial, sans-serif"> <p style="margin-top:0.0pt;margin-bottom:0.0pt"><strong><span style="font-size:11.0pt">Vulnerability Management:</span></strong><span style="font-size:11.0pt"> Triaging bugs found via automated scanners, internal audits, or </span><strong><span style="font-size:11.0pt">Bug Bounty</span></strong><span style="font-size:11.0pt"> programs.</span></p> </li> <li style="font-size:11.0pt;font-family:Arial, sans-serif"> <p style="margin-top:0.0pt;margin-bottom:0.0pt"><strong><span style="font-size:11.0pt">Security Tooling:</span></strong><span style="font-size:11.0pt"> Implementing and managing tools like </span><strong><span style="font-size:11.0pt">SAST</span></strong><span style="font-size:11.0pt"> (Static Analysis), </span><strong><span style="font-size:11.0pt">DAST</span></strong><span style="font-size:11.0pt"> (Dynamic Analysis), and </span><strong><span style="font-size:11.0pt">SCA</span></strong><span style="font-size:11.0pt"> (Software Composition Analysis) to catch insecure dependencies.</span></p> </li> <li style="font-size:11.0pt;font-family:Arial, sans-serif"> <p style="margin-top:0.0pt;margin-bottom:0.0pt"><strong><span style="font-size:11.0pt">Code Reviews:</span></strong><span style="font-size:11.0pt"> Performing manual "deep dives" into critical codebases to spot logic flaws that automated tools might miss.</span></p> </li> <li style="font-size:11.0pt;font-family:Arial, sans-serif"> <p style="margin-top:0.0pt;margin-bottom:0.0pt"><strong><span style="font-size:11.0pt">Incident Response:</span></strong><span style="font-size:11.0pt"> Acting as a subject matter expert when a security flaw is exploited in production.</span></p> </li> <li style="font-size:11.0pt;font-family:Arial, sans-serif"> <p style="margin-top:0.0pt;margin-bottom:12.0pt"><strong><span style="font-size:11.0pt">Internal Red Teaming</span></strong><span style="font-size:11.0pt">: Lead activities to find ways to bypass the logic to alter "Recipe" files or production data.</span></p> </li> </ul> <strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">Developer Training:</span></strong><span style="font-size:11.0pt;font-family:Arial, sans-serif"> Creating "Security Champions" programs to teach engineers how to write defensive code.</span></li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Physical Demands</H2> </div><div><ul> <li> <div align="left"> <table style="border:none"><colgroup><col style="width:121.0px"><col style="width:494.0px"></colgroup> <tbody> <tr style="height:40.75pt"> <td style="border-width:0.833333pt;border-style:solid;vertical-align:top"> <p style="margin-top:0.0pt;margin-bottom:24.0pt"><strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">Languages</span></strong></p> </td> <td style="border-width:0.833333pt;border-style:solid;vertical-align:top"> <p style="margin-top:0.0pt;margin-bottom:24.0pt"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Proficiency in at least one "product" language (C# (.Net core) , JavaScript, SQL).</span></p> </td> </tr> <tr style="height:40.75pt"> <td style="border-width:0.833333pt;border-style:solid;vertical-align:top"> <p style="margin-top:0.0pt;margin-bottom:24.0pt"><strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">Knowledge</span></strong></p> </td> <td style="border-width:0.833333pt;border-style:solid;vertical-align:top"> <p style="margin-top:0.0pt;margin-bottom:24.0pt"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Deep understanding of the </span><strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">OWASP Top 10</span></strong><span style="font-size:11.0pt;font-family:Arial, sans-serif"> (SQLi, XSS, CSRF) and cloud security (AWS/Azure/GCP).</span></p> </td> </tr> <tr style="height:40.75pt"> <td style="border-width:0.833333pt;border-style:solid;vertical-align:top"> <p style="margin-top:0.0pt;margin-bottom:24.0pt"><strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">Tools</span></strong></p> </td> <td style="border-width:0.833333pt;border-style:solid;vertical-align:top"> <p style="margin-top:0.0pt;margin-bottom:24.0pt"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Experience with Snyk, Checkmarx, Burp Suite, or GitHub Advanced Security.</span></p> </td> </tr> <tr style="height:40.75pt"> <td style="border-width:0.833333pt;border-style:solid;vertical-align:top"> <p style="margin-top:0.0pt;margin-bottom:24.0pt"><strong><span style="font-size:11.0pt;font-family:Arial, sans-serif">Infrastructure</span></strong></p> </td> <td style="border-width:0.833333pt;border-style:solid;vertical-align:top"> <p style="margin-top:0.0pt;margin-bottom:24.0pt"><span style="font-size:11.0pt;font-family:Arial, sans-serif">Familiarity with Docker, Kubernetes, and CI/CD pipelines (Jenkins, GitLab CI).</span></p> </td> </tr> </tbody> </table> </div> </li> </ul> <p> </p> <p> </p></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Typical Experience</H2> </div><div><ul> <li>4 to 6 years; Experience in similar roles</li> </ul></div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Typical Education</H2> </div><div><ul> <li dir="ltr"> <p dir="ltr">Bachelor Degree or consideration of an equivalent combination of education and experience.</p> </li> <li dir="ltr"> <p dir="ltr">Educational Requirements may vary by Geography</p> </li> </ul> </div></div><div style="padding:10.0px 0.0px;border:1.0px solid transparent"><div style="font-size:16.0px;word-wrap:break-word"><H2 style="font-size:1.0em;margin:0.0px">Notes</H2> </div><div><p>This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.</p></div></div></div><p><span style="font-size:10.0px">Celestica is an equal opportunity employer. All qualified applicants will receive consideration for employment and will not be discriminated against on any protected status (including race, religion, national origin, gender, sexual orientation, age, marital status, veteran or disability status or other characteristics protected by law).<br> At Celestica we are committed to fostering an inclusive, accessible environment, where all employees and customers feel valued, respected and supported. Special arrangements can be made for candidates who need it throughout the hiring process. Please indicate your needs and we will work with you to meet them.</span></p> <p> </p> <p><span style="font-size:10.0px"><b>COMPANY OVERVIEW:</b><br> Celestica (NYSE, TSX: CLS) enables the world’s best brands. Through our recognized customer-centric approach, we partner with leading companies in Aerospace and Defense, Communications, Enterprise, HealthTech, Industrial, Capital Equipment and Energy to deliver solutions for their most complex challenges. As a leader in design, manufacturing, hardware platform and supply chain solutions, Celestica brings global expertise and insight at every stage of product development – from drawing board to full-scale production and after-market services for products from advanced medical devices, to highly engineered aviation systems, to next-generation hardware platform solutions for the Cloud. Headquartered in Toronto, with talented teams spanning 40+ locations in 13 countries across the Americas, Europe and Asia, we imagine, develop and deliver a better future with our customers.</span></p> <p> </p> <p><span style="font-size:10.0px">Celestica would like to thank all applicants, however, only qualified applicants will be contacted.<br> Celestica does not accept unsolicited resumes from recruitment agencies or fee based recruitment services.</span><br> </p>

Ready to apply?

Install the ResuMinder extension and we'll auto-fill the application in seconds — no rewriting.

See how your CV scores