FreshRemote.Work

Security Application Engineer

Remote New Jersey

Say hello to opportunities.

It’s not everyday that you consider starting a new career. We’re RingCentral, and we’re happy that someone as talented as you is considering this role. First, a little about us, we’re a $2 Billion annual revenue company with double digit Annual Recurring Revenue (ARR) and a $93 Billion market opportunity in UCaaS, Contact Center and AI-powered adjacencies. We invest more than $250 million annually to ensure our AI-enabled technology and platforms meet or exceed the needs of our customers. 

RingSense AI is our proprietary AI solution. It’s designed to fit the business needs of our customers, orchestrated to be accurate and precise, and built on the same open platform principles we apply to our core software solutions. 


This is where you and your skills come in. We are looking for a Security Application Engineer with a strong understanding of web and mobile application vulnerabilities, how they can be detected, exploited and remediated.


Job Duties:
Consult developers on questions related to reports of security scanners*, which includes:

  • explain why an issue should be considered as a vulnerability

  • explain circumstances under which an issue might be exploitable

  • provide suggestions on how an issue can be remediated

Review and validate issues marked as potential false positives by developers; request additional clarifications where required.

Review and improve security scanners configurations:

  • review scanning rules in presets, make sure that important rules are enabled and irrelevant rules are disabled

  • make sure security scanners do not miss production code/applications, as well as do not scan testing-only code/applications

  • where possible and required, adjust scanning rules to improve their accuracy

  • collaborate with legal to make sure that license violation rules for open source software are configured correctly

Maintain access to security scanners.

Report breached security defects SLA.

Support risk exceptions process for the following cases:

  • violations of security defects SLA

  • deviations from security policies/standards (for example, releasing with a higher vulnerability level than defined as satisfactory)

Triage reports from the bug bounty platform, address them to responsible engineering teams

Triage reports from the external attack surface management platform, address them to responsible engineering teams

Maintain security scanners deployed in production environment, which includes:

  • deploy new versions

  • patch security vulnerabilities

  • make sure security hardening benchmarks are met (such as CIS or STIG)

  • make sure other requirements for production deployment are met (logging, monitoring, backups, etc.)

* - security scanners include, but are not limited to static …

This job isn't fresh anymore!
Search Fresh Jobs

Job Profile

Regions

North America

Countries

United States

Restrictions

U.S. citizenship required

Benefits/Perks

401K match and ESPP Coaching Commuter benefits Comprehensive medical, dental, vision Comprehensive medical, dental, vision, disability, life insurance Dental Disability Disability, life insurance Emergency backup care Employee Assistance Program Employee bonus referral program Employee perks and discounts ESPP Family-forming Benefits Free Legal Services FSAs HSA Life Insurance Medical Paid parental and pregnancy leave Paid Sick Leave Paid Time Off Paid time off and paid sick leave Pet Insurance Student Loan Refinancing Student loan refinancing assistance Vision Wellness programs Wellness programs including 1

Tasks
  • Collaborate with legal on license violations
  • Consult on security vulnerabilities
  • Maintain security scanners in production
Skills

AI Coaching Collaboration Communication Communications Contact center Contact Center Solutions Dynamic Application Security Testing Mobile application security Open Source Software Management Organizational Penetration Testing Risk Assessment Security Security Testing Software Composition Analysis Static Application Security Testing STIG Threat modeling Time Management UCaaS Vulnerability assessment Vulnerability Management Web application security

Experience

5 years

Education

Engineering

Certifications

Public Trust Verification

Timezones

America/Anchorage America/Chicago America/Denver America/Los_Angeles America/New_York Pacific/Honolulu UTC-10 UTC-5 UTC-6 UTC-7 UTC-8 UTC-9