Principal Product Security Engineer

Semtech
US, Georgia
$121K-$190.3K a year
Full-time

Location : US-Remote

Our Team :

Semtech’s Product Security team is a group of passionate and talented security professionals tasked to support product development teams in the creation of high-quality products that are secure by design.

We ensure our customers and partners feel comfortable deploying our products, knowing security is an integral part of the development process.

We are expanding a versatile and exceptionally talented team of individuals to make this vision a reality.

Job Summary :

The Principal Product Security Engineer will support Semtech’s Business Units with product security initiatives. The ideal candidate will support creating high-quality, security focused products by providing product development teams with the necessary support, subject matter expertise, requirements validation, tools, training and assistance.

This role also assists the office of the CTO in conceptualizing, developing and commercializing technologies to shape the technical future of the organization.

Responsibilities :

Lead the development of product security requirements for applications, infrastructure, cloud, and / or other products, and participate in the full lifecycle of product design in all business units.

Assess, identify, develop threat models and provide recommendations with the explicit purpose of influencing design decisions to address the likely threats to a product’s security and resilience.

Design and implement security solutions that support overall product security in all business units.

Conduct manual and automated security testing of applications, infrastructure, cloud, and / or other platforms to discover security vulnerabilities.

Review and learn new Semtech technologies / products quickly and assess them from a security perspective.

Evaluate cloud architectures, configurations, and processes comprehensively.

Provide technical leadership and guidance to technology teams involved in cloud projects.

Foster a culture of collaboration and knowledge sharing across the organization.

Build key relationships between BUs and functions involving key stakeholders while conducting interviews, surveys, and workshops to gather necessary input regarding their needs, expectations, and concerns.

Provide assistance and support for ISO certifications, including ISO 27001, ISO 9001, and ISO 22301, contributing to the implementation and maintenance of compliance efforts.

Lead incident management activities, coordinating responses to security incidents or breaches in products both from internal and external reported sources, and implementing corrective measures.

Demonstrate proficiency in firmware, with a preference for experience in hardware and module devices, including IoT modules and router devices.

Provide guidance to business units on security best practices in the cloud, applications, and infrastructure.

Support the MVNO and associated telecom business units on product security.

Support the research and implementation of robust secure encryption and protection mechanisms.

Oversee penetration testing activities to identify and address reported security vulnerabilities.

Assist with the design and adoption of security measures in IoT products and components, including protocols such as TLS, SSH and Lightweight M2M.

Minimum Qualifications :

Bachelor’s degree in computer science, a related field, or relevant work experience.

Minimum 10 years’ experience working in information / cyber security with an emphasis on product security.

Experienced working with embedded hardware systems and their respective security considerations.

Knowledgeable of cryptographic standards and how they are applied to ensure robust product security.

Knowledge of major cloud platforms (with specific concentration on AWS) and cloud-native technologies.

Experienced in tracking to remediation application, infrastructure, chip, cloud and other security vulnerabilities.

Telco stack knowledge, including HLR / HSS, P-Gateway and 2G-4G mobile core protocols, is desirable.

Strong analytical and problem-solving skills.

Demonstrated understanding of common security threats and vulnerabilities.

Skilled in architecting software solutions using a variety of architectural patterns such as Microservices, Monolithic and serverless tailored to project requirements and scalability needs.

Certified Information Systems Security Professional (CISSP)

Desired Qualifications

AWS Certified Cloud Practitioner

AWS Certified Solutions Architect

Working knowledge of TOGAF enterprise architecture framework

Dynamic and detail-oriented with a solid background in software development, proficient in Python, C++ and Java.

A reasonable estimate of the pay range for this position is $121,000 - $190,300. There are several factors taken into consideration in determining base salary, including but not limited to : job-related qualifications, skills, education and experience, as well as job location and the value of other elements of an employee’s total compensation package.

10 days ago
Related jobs
Promoted
Lockheed Martin
Marietta, Georgia

Remain current on all proposed and pending engineering changes for assigned systems and monitor systems performance indicators to identify emerging failure trends. Coordinate required vendor and engineering support during investigation, fact finding, and resolution/disposition. Must be able to effec...

Promoted
ServiceNow
Atlanta, Georgia

The Sr Staff Product Security Engineer will serve as a technical leader on ServiceNow’s PSIRT. The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. The Engineer will aggressively identify and co...

Semtech
US, Georgia

The Principal Product Security Engineer will support Semtech’s Business Units with product security initiatives. Semtech’s Product Security team is a group of passionate and talented security professionals tasked to support product development teams in the creation of high-quality products that are ...

Oldcastle Infrastructure
Atlanta, Georgia

The Product Engineer is responsible for project designs and layouts, new product design, and existing product enhancement to support Oldcastle Infrastructure’s growing business. Performs, oversees, and directs product structural design and detailing along with product prototyping and testing. Partne...

Truist
Atlanta, Georgia

Strong functional and technical knowledge of information/cyber security capabilities with deep expertise in one or more of the following areas: Encryption, Data Security, Application Security, End Point Security, Identity and Access Management, Windows/Unix/Linux Systems Security, Mainframe Security...

Capital One
Atlanta, Georgia

Principal Associate, Security Engineer (CyberArk). Perform hands-on keyboard tasks for CyberArk PAM product offerings such as Privileged Session Manager (PSM), Privileged Session Manager Proxy (PSMP) and HTML5 Gateway components. Perform hands-on keyboard tasks related to AWS EC2, S3, Load Balancer,...

Panasonic
Peachtree City, Georgia

Integrates new security features and updates into existing products and ensures the security of all products is maintained throughout the product lifecycle. Detects and mitigates security risks, responds to product security incidents, and works with customers regarding product security related issue...

Milstaf
Atlanta, Georgia

We are looking for a Principal Information Security Engineer to focus on web access information security projects. As a Principal Information Security Engineer, you will be a technical leader with massive impact. Principal Information Security Engineers are pragmatic visionaries who can translate bu...

New Relic, Inc.
Atlanta, Georgia
Remote

Principal Software Engineer - Platform Security/Compliance Architect - (Remote). Principal Software Engineer - Platform Security/Compliance Architect - (Remote). You will collaborate with cross-functional teams, including engineering, security, legal and compliance to ensure our software complies wi...

ServiceNow
Atlanta, Georgia
Remote

The Sr Staff Product Security Engineer will serve as a technical leader on ServiceNow’s PSIRT. The ServiceNow Security Organization (SSO) delivers world-class, innovative security solutions to reduce risk and protect the company and our customers. The Engineer will aggressively identify and communic...