Talent.com
Security Engineer (Contract)

Security Engineer (Contract)

Dr. SquatchLos Angeles, CA, US
21 days ago
Job type
  • Full-time
Job description

Job Description

Job Description

Why We Exist and What We Do :

At Dr. Squatch (www.drsquatch.com), we're raising the bar on men's personal care with our line of natural, high-performance products. We're on a high-growth, fast-moving ride, continually introducing new product categories, launching into retailers nationwide, and growing internationally. We have been recognized and certified by Great Place to Work® multiple times, and we achieved status as a certified B Corp in 2023. We are looking for passionate, talented people who want to join us in our mission to inspire and educate men to be happier and healthier!

About the Role :

We're looking for a Security and Privacy Engineer to support our efforts on a contractual basis to support the eCommerce team in securing our Shopify storefronts, maintaining our consent management solution, and standardizing and automating enterprise permissions at scale. This contract is ideal for someone who thrives at applying consistent permission structures to inconsistent SaaS applications to improve and standardize security across the company.

This role will be accountable to the Associate Director, Cybersecurity & Privacy.

Ideally, this contractor should be in the Los Angeles Metropolitan area.

The contractor term is anticipated to be up to 30 hours per week for approximately 12 weeks.

What You'll Do :

Security Responsibilities

You'll be an embedded resource for our eCommerce and Data team and review our Shopify and GitHub environments to identify vulnerabilities and remediate the findings.

  • You'll identify, classify, and remediate the high-risk findings to improve our website's security posture
  • You'll deploy Aikido, train the teams on how to use it, and remediate the high-risk findings
  • You'll encourage secure SDLC processes within the engineering team
  • You'll be the security SME for the engineering team
  • You'll help develop and secure our Shopify DTC storefront
  • Collaborate with stakeholders on the Digital Product team to secure features in our software products

Privacy Responsibilities

You'll partner with our eCommerce and Legal teams to ensure our existing Consent Management solution is harmonized with our Shopify storefronts.

Identity & Access Management Responsibilities

You'll automate our identity and access management processes across cloud environments, SaaS platforms, and our enterprise stack. In-scope applications include Okta, NetSuite, Shopify, Looker, Snowflake, GitHub, and our social media websites.

  • Platform Reviews
  • Review the in-scope applications for permissions creep, stale accounts, and violations of our security policies.
  • Partner with the business teams to understand how to apply least-privilege and Role-Based Access Control on each application.
  • Adjust permissions accordingly.
  • Automations
  • Assess the existing applications, users, and permissions identify opportunities for automation and standardization.
  • Automate and standardize the identity and access management processes across the company.
  • Provide knowledge transfer to internal IT / security teams as needed.
  • Timeline

  • Week 1 : Dr. Squatch intro and Transcend / Shopify architecture review
  • Week 2-5 : Transcend x Shopify Deep Dive and Alignment
  • Week 6 : Security Scorecard report review, and Github / Shopify assessment
  • Week 7 : Aikido deployment and training
  • Week 7-9 : Security Scorecard high-risk remediations
  • Week 10 : Review in-scope applications to identify and design automation opportunities
  • Week 10-12 : Implement automation strategies to better standardize and manage user permissions across all in-scope systems
  • The extension will be mutually agreed upon and confirmed in two-week increments. The confirmation extension should be completed no later than two weeks before the anticipated end date. We estimate that this project should take 20-30 hours per week.

    Deliverables

  • Security Scorecard before and after report demonstrating risk reduction
  • Aikido / Github before and after report demonstrating risk reduction
  • Shopify Consent Management documentation
  • Automated provisioning / deprovisioning scripts or documentation
  • Knowledge transfer sessions and training materials
  • Ideal Contractor Skills & Experience

  • DTC experience, specifically in securing Shopify-centric environments
  • 3 years of software engineering experience with web languages : JavaScript, TypeScript, React or Vue.js, HTML, CSS, CSS preprocessors (eg : SASS, postscript).
  • Experience in a Consent Management platform or Shopify Privacy API
  • Deep experience with IAM tools, preferably Okta
  • Scripting and automation skills
  • Excellent communication and documentation skills
  • #LI-BD1 #LI-CONTRACT

    Who We Are :

    Our core values come naturally and make us a better, more whole, and unique team. We are Bold & Innovative - we are creative, rethink how things are done, and find a way. We Play to Win - we have high standards, we encourage ownership of work, we are scrappy, we act with urgency, and we invest in the outcome of our work. We are Team Squatch - we are humble, help others outside our own wheelhouse, stay positive, have fun, and have approachable and transparent leadership.

    We offer a competitive salary in a growth-focused & collaborative team environment. Benefits include medical, dental, vision, 401k with Squatch match, and PTO. We also have great perks like healthy snacks, frequent company events, and of course, free products!

    For Applicants with Disabilities. Reasonable accommodation will be made so that qualified applicants with disabilities may participate in the application process. If you need any accommodations during the hiring process, please let us know when you submit your application and we'll do our very best to adjust as needed.

    For Information regarding Data Privacy , please review https : / / privacy.drsquatch.com / .

    Unsolicited Resume Policy. Dr. Squatch ("DRSQ") employs an internal Talent Acquisition department. Exceptionally, DRSQ may choose to supplement that internal team with support from temporary staffing agencies, placement services, and / or recruiting agencies ("Agency"). Agencies are hereby specifically directed NOT to contact DRSQ employees directly in an attempt to present candidates. DRSQ's Talent Acquisition team is responsible for all candidate presentations to our hiring managers.

    To protect the interests of all parties, Dr. Squatch will not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to DRSQ, including unsolicited resumes sent to a DRSQ email address or mailing address, directly to DRSQ employees, or to DRSQ's resume database will be considered property of Dr. Squatch.

    DRSQ will not pay a placement, service or other fee for any placement resulting from the receipt of an unsolicited resume . This also includes partial resumes, LinkedIn profiles, general candidate profiles, and / or candidate details or information. DRSQ will consider any candidate for whom an Agency has submitted an unsolicited resume to have been referred by the Agency free of any charges or fees.

    DRSQ's Talent Acquisition team must provide advance written approval to an Agency to submit resumes and / or profiles for a specific job-opening, and the approval must be in conjunction with a valid fully executed staffing, placement or other service agreement. DRSQ will not pay a fee to any Agency that does not have a fully executed agreement in place prior to submission, receipt and placement of candidates.

    Create a job alert for this search

    Security Engineer • Los Angeles, CA, US

    Related jobs
    • Promoted
    Security Engineer (Associate - Mid Level)

    Security Engineer (Associate - Mid Level)

    G2 Ops IncEl Segundo, CA, United States
    Full-time
    Location : El Segundo, CA at our customer site.Work Setting : In person, some remote opportunity, and / or flexible working hours, not a fully remote position. Salary Range : $90,000 - $150,000 plus comp...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer, Enterprise Infrastructure Security, Level 5

    Security Engineer, Enterprise Infrastructure Security, Level 5

    SnapchatLos Angeles, CA, United States
    Full-time
    Snap Inc is a technology company.We believe the camera presents the greatest opportunity to improve the way people live and communicate. Snap contributes to human progress by empowering people to ex...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer

    Security Engineer

    VastLos Angeles, CA, United States
    Full-time
    We are looking for talented people who share these values to join as we grow our team.Our vision is to widely distribute AI computing to reshape our future for the good of humanity.If witnessing th...Show moreLast updated: 3 days ago
    • Promoted
    API Security Engineer

    API Security Engineer

    Omni InclusiveLos Angeles, CA, United States
    Full-time
    Configuring Secured APIs : The primary responsibility is to configure APIs to ensure they are secure.This involves implementing security measures to protect APIs from threats and vulnerabilities.Enh...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer

    Security Engineer

    Red Cup ITLos Angeles, CA, United States
    Full-time
    We are looking for a Security Engineer who is responsible for design, implement, and maintain systems to protect organizations from cyber threats, ensuring data confidentiality, integrity, and avai...Show moreLast updated: 3 days ago
    • Promoted
    Advanced Security Engineer - Cyber Security

    Advanced Security Engineer - Cyber Security

    RelativityLos Angeles, CA, United States
    Full-time
    As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer, Enterprise Infrastructure Security, Level 5

    Security Engineer, Enterprise Infrastructure Security, Level 5

    SnapLos Angeles, CA, United States
    Full-time
    Snap Inc () is a technology company.We believe the camera presents the greatest opportunity to improve the way people live and communicate. Snap contributes to human progress by empowering people to...Show moreLast updated: 3 days ago
    • Promoted
    Endpoint Security Engineer

    Endpoint Security Engineer

    Insight GlobalLos Angeles, CA, United States
    Full-time
    Insight Global is seeking a skilled Endpoint Security Engineer for a top media / entertainment client.The ideal candidate will have extensive experience in endpoint security engineering, particularly...Show moreLast updated: 3 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    UnavailableSan Marino, CA, United States
    Full-time
    Since 1973, East West Bank has served as a pathway to success.With over 110 locations across the U.Asia, we are the premier financial bridge between the East and West. Our teams of experienced, mult...Show moreLast updated: 3 days ago
    • Promoted
    Information Security Architect-Hybrid

    Information Security Architect-Hybrid

    Logix Federal Credit UnionValencia, CA, United States
    Full-time
    Information Security Architect-Hybrid.Information Security Architect.LFCU enterprise information security architecture.Enforce information security technology standards, roadmaps, and governance.Co...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer, Audible Security

    Security Engineer, Audible Security

    AmazonCulver City, CA, United States
    Full-time
    At Audible, we believe stories have the power to transform lives.It's why we work with some of the world's leading creators to produce and share audio storytelling with our millions of global liste...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer

    Security Engineer

    Pipe RecruitOrange, CA, United States
    Full-time
    About the job Security Engineer.Orange County, CA (Local candidates preferred).Full-Time (Only USC / GC candidates).Implement and manage security controls in. SOX, PCI) and support security audits.Req...Show moreLast updated: 3 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    SourcePro Search, LLCLos Angeles, CA, United States
    Full-time
    We have a great opportunity for an experienced Senior Security Engineer in our global law firm client's Los Angeles office. The Senior Security Engineer is a hands-on role that requires a high level...Show moreLast updated: 30+ days ago
    • Promoted
    Lead Security Engineer - Cyber Security

    Lead Security Engineer - Cyber Security

    RelativityLos Angeles, CA, United States
    Full-time
    As a Lead Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging threat...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer- Onsite - (Fulltime)

    Security Engineer- Onsite - (Fulltime)

    The Dignify Solutions LLCSanta Ana, CA, United States
    Full-time
    Azure Cloud Security- Design, Implementation, and support.Application Security - DAST and SAST tools.Network Security & Firewall (Palo Alto). Security Risk and Compliance management.Minimum three (8...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    ZipRecruiterLos Angeles, CA, United States
    Full-time
    Job DescriptionJob Description .At Serve Robotics, we’re reimagining how things move in cities.Our personable sidewalk robot is our vision for the future. It’s designed to take deliveries away from ...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer

    Security Engineer

    Group Nine LLCOrange, CA, United States
    Full-time
    Location : Orange County, CA (prefer local profiles).Assists in the planning and deployment of the Company's cloud information security strategies. Review and identify any gap in Paloalto Firewall ru...Show moreLast updated: 3 days ago
    • Promoted
    10390 - Security Engineer II

    10390 - Security Engineer II

    Hyundai AutoEver AmericaFountain Valley, CA, United States
    Full-time
    Location : Fountain Valley, CA (5-days onsite).Hyundai AutoEver America (HAEA), a subsidiary of Hyundai and Kia Motor Companies, provides premier IT services across North America.The Security Engine...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer for ITS Security - LA METRO

    Security Engineer for ITS Security - LA METRO

    Cornerstone Concilium IncLos Angeles, CA, United States
    Full-time
    Security Engineer for ITS Security - LA METRO.Los Angeles - Los Angeles, CA 90001 US (Primary).This project entails providing cybersecurity staff augmentation services to Metro's Information Securi...Show moreLast updated: 30+ days ago
    • Promoted
    Founding Security Engineer - Governance, Risk & Compliance (GRC)

    Founding Security Engineer - Governance, Risk & Compliance (GRC)

    Sift ScienceEl Segundo, CA, United States
    Full-time
    At Sift, we're redefining how modern machines are built, tested, and operated.Our platform provides engineers with real-time observability over high-frequency telemetry, eliminating bottlenecks and...Show moreLast updated: 3 days ago