Harvard University
The Senior Security Engineer will have responsibility for supporting and advancing Harvard Medical School's application security, Secure SDLC, and penetration testing programs. This role will partner closely with others across HMS IT and Security to enable the HMS mission by implementing Secure SDLC practices, operating application security testing platforms, identifying security weaknesses through penetration testing, and collaborating with development teams to improve security throughout the software lifecycle. On a daily basis, this role will perform penetration testing of applications, systems, and emerging technologies; support the administration of application security platforms; conduct threat research; identify security risks and remediation opportunities; and help mature the organization's application security capabilities. This role will partner with SecOps when required during security incidents and investigations. The Senior Security Engineer, as part of the IT Security team, will partner with others across Security and IT to establish strategic and tactical roadmaps and help mature application and offensive security capabilities.
Principal duties and responsibilities:
• Perform penetration testing of applications, systems, infrastructure, cloud environments, and emerging technologies.
• Identify security weaknesses and provide remediation recommendations through technical testing.
• Support Secure SDLC initiatives and collaborate with development teams to improve application security.
• Administer and support application security platforms and testing tools.
• Assist with implementation and operation of SAST, SCA, DAST, API Security, Secrets Detection, and related application security capabilities.
• Conduct threat research and stay current on emerging attack techniques, vulnerabilities, adversary activity, and security trends.
• Inform the organization of emerging threats, attack techniques, vulnerabilities, and risks.
• Serve as an information security subject matter expert in penetration testing and application security.
• Research, evaluate, and recommend new security tools, technologies, and processes that improve HMS security capabilities.
• Abide by and follow Harvard University IT technical standards, policies, and Code of Conduct.
Real, currently open roles at Harvard University, sourced from their public smartrecruiters careers page.
Industry
Other
Zoox
Not disclosed
Yesterday