Match score not available

Director of Application and Product Security

Remote: 
Full Remote
Contract: 
Experience: 
Expert & Leadership (>10 years)
Work from: 

Offer summary

Qualifications:

5+ years in application or product security, Hands-on experience in software projects, Strong knowledge of secure coding practices, Experience with threat modeling, Familiarity with cloud infrastructure.

Key responsabilities:

  • Review architecture, code, provide security guidance
  • Collaborate on threat modeling and secure design
  • Drive security tooling for CI/CD pipeline
  • Cultivate internal security culture among teams
  • Promote secure building practices for engineers
Newfold Digital logo
Newfold Digital Large https://newfold.com/
1001 - 5000 Employees
See more Newfold Digital offers

Job description

Who we are.

Newfold Digital is a leading web technology company serving millions of customers globally. Our customers know us through our robust portfolio of brands. We have some of the industry's most prominent and storied go-to-market brands, including Bluehost, HostGator, Domain.com, Markmonitor, Network Solutions, Register.com and Web.com. We help customers of all sizes build a digital presence that delivers results. With our extensive product offerings and personalized support, we take pride in collaborating with our customers to serve their online presence needs. The strength of our company lives in the intersection of our people, our customers, and our brands.

We are looking for a passionate and effective technical leader to help drive Application and Product Security Engineering across our development and operations teams who are responsible for our core customer applications and product platforms, including large-scale web hosting, ecommerce and email servicesWe believe that we can improve our application and product security by integrating a security mindset early in the development lifecycle as our applications and products are being designed, embracing security best practices and instrumentation at all stages of development and deployment. 

You will lead a team which will collaborate with other security, operations and software development teams to guide secure architecture, design and implementation, and reduce security risk in the organization through the construction of guardrails and paved paths that empower engineers to make informed security decisions. The threat landscape for our products and services continue to evolve and expand rapidly, and you will be challenged to help solve large-scale, complex problems that have real impact for our customers, our products, and for the larger Internet community. 

What you’ll be doing and how you'll make your mark:
 

 Review architecture and code and provide security guidance (70%)  

  • Provide holistic assessments of security layers across infrastructure, application, people, and process. 

  • Collaborate with product managers, designers, and engineers to threat model and architect secure and resilient systems. 

  • Review source code against secure coding best practices and contribute security requirements. 

Create a paved road for engineers to build securely (20%) 

  • Drive the software design and implementation of security services, tools, and libraries to provide secure defaults to the rest of the organization. 

  • Promote security remediations in the CI/CD pipeline by building tools and services for engineers to consume. 

  • Help build the platform that ensures software development at Newfold is safe, easy, and low-risk. 

Cultivate and promote a security culture (10%) 

  • Champion an internal security culture. 

  • Help engineers understand how security events impact them.  

Who you are & what you’ll need to succeed.

Required qualifications: 

  • Ability to clearly communicate security topics and vulnerability classes (e.g. OWASP Top Ten) and provide actionable direction to product teams. 

  • A record of partnering with internal engineering teams to tackle security problems across an entire stack with empathy and creativity.  

  • Hands-on experience in software engineering projects. We primarily develop in Java, Python, JavaScript, SQL, and Perl 

  • Working knowledge of modern development concepts (virtualized environments, containerization, continuous integration + delivery). 

Preferred qualifications: 

  • 5 or more years of experience in application security or product security roles. 

  • Practical understanding and experience with shared and dedicated web hosting at scale.  

  • Proven professional experience guiding software teams on secure architecture design. 

  • Working knowledge of network architecture and system architecture, including cloud infrastructure. 

  • Experience building or reviewing threat models and ability to craft malicious user, attacker, and abuse/misuse cases. 

  • Working knowledge of hardware and software supply chain security. 

Why you’ll love us:  

We’ve evolved; we provide three work environment scenarios. You can feel like a Newfolder in a work-from-home, hybrid or work-from-the-office environment.  

Work-life balance. Our work is thrilling and meaningful, but we know balance is key to living well. We celebrate one another’s differences.  We’re proud of our culture of diversity and inclusion. We foster a culture of belonging. Our company and customers benefit when employees bring their authentic selves to work. We have programs that bring us together on important issues and provide learning and development opportunities for all employees.  We have 20 + affinity groups where you can network and connect with Newfolders globally.  

Where can we take you? We’re fans of helping our employees learn different aspects of the business, be challenged with new tasks, be mentored, and grow their careers. Unfold new possibilities with #teamnewfold! 

 

#LI-AD1 


This Job Description includes the essential job functions required to perform the job described above, as well as additional duties and responsibilities. This Job Description is not an exhaustive list of all functions that the employee performing this job may be required to perform. The Company reserves the right to revise the Job Description at any time, and to require the employee to perform functions in addition to those listed above.


This Job Description includes the essential job functions required to perform the job described above, as well as additional duties and responsibilities. This Job Description is not an exhaustive list of all functions that the employee performing this job may be required to perform. The Company reserves the right to revise the Job Description at any time, and to require the employee to perform functions in addition to those listed above.

Required profile

Experience

Level of experience: Expert & Leadership (>10 years)
Spoken language(s):
English
Check out the description to know which languages are mandatory.

Other Skills

  • Collaboration
  • Problem Solving
  • Creativity
  • Empathy
  • Verbal Communication Skills

CPO - Chief Product Officer Related jobs