وصف الوظيفة
Role Overview
Lead Security Engineer at Dyson. This role provides software security test quality assurance support to software development teams across the organization.
Role Purpose
Ensure that software scrum teams follow the defined software security development lifecycle process and conformance to related regulations and industry standards. Monitor the health of implemented software systems, provide guidance to scrum teams, and drive continuous improvement to the software security process while maintaining compliance to Dyson software security quality policies and procedures.
Key Responsibilities
Security Testing & Assessment
- Perform ongoing software security penetration testing and code review activities using both automated and manual techniques to identify and exploit vulnerabilities in IoT consumer products.
- Define penetration testing methodologies combining automated and manual tools.
- Build automated systems to support continuous testing and analysis of nightly builds.
- Develop familiarity with new tools and best practices in security testing.
Design & Implementation
- Implement, test, and operate advanced software security techniques in compliance with technical reference architecture.
- Contribute to the design, development, implementation, and integration of Offensive Cyber Operations tools against platforms, payloads and systems.
- Provide engineering designs for new software solutions to help mitigate security vulnerabilities.
- Agree the desired Security Level with the organization, reviewing requirements to build tests.
Governance & Compliance
- Ensure compliance to Dyson software security quality policies and procedures.
- Provide critical input at all stages of design and development of new features.
Team Collaboration & Guidance
- Work in a SAFe Agile team across a global organization.
- Consult team members on software secure coding practices.
- Develop security test strategies across different platforms: Lighting, Environmental, Hair and Robotics.
Risk Management
- Proactively identify security risks.
Qualifications & Experience
- Bachelor's degree in Computer Engineering, Electronic Engineering, or related field.
- More than 3 years software quality or software test relevant experience.
- Cyber security experience including penetration testing, security posture assessment, cloud security assessment, IoT security, vulnerability analysis, and risk assessment.
- Experience in regulated environments such as ISO, IEC, FDA and related standards.
- Experience working in Agile software development and DevOps environments.
- Knowledge of software in IoT products, such as embedded, app, cloud and related components.
Skills & Competencies
Technical Security Skills
- Experience using scan, attack and assess tools and techniques.
- In-depth knowledge of wireless protocols: Wi-Fi, Bluetooth, JTAG and USB.
- Proficiency in Security concepts for IoT, Linux and RTOS Operating Systems.
Programming & Tools
- Competency in at least one scripting or coding language: Python, C, or C++.
- Test Management Systems: Jira, Confluence, Stash, Git, Bamboo.
Process & Analysis
- Understanding of software security development lifecycle.
- Good understanding of statistical process control.
- Ability to select, define, and apply product and process metrics and analytical techniques, and communicate results.
Professional Attributes
- Persistent nature with inquisitive attitude and results-driven focus.
- Creative and product-focused ability to generate numerous concepts for new technologies.
- Excellent attention to detail.
- Strong communication skills.
- Able to work independently and in teams.
- Able to work in fast-paced environment and deliver quality under minimal supervision.
Certifications
- CREST certification (advanced level preferred).
Additional Information
- Dyson is an equal opportunity employer. Employment decisions are made without regard to race, colour, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or any other dimension of diversity.
- The role operates in a supportive environment where the team embraces new techniques to improve itself and grow capability.