News Corp
Product Security Engineer
News Corp, New York, New York, us, 10261
Equal Opportunity Employer
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status, or disability status. EEO/AA/M/F/Disabled/Vets
Job Description :
Job Description
Product Security Engineer
Location: NYC - 3 days a week in office
Job Description:We have an exciting role for a Product Security Engineer who will be responsible for the design,development, and strategy to secure digital products within NewsCorp supporting the NY POST.
The successful applicant will contribute expertise, embrace emerging trends, and provide overall guidance onsecurity best practices across all of News Corp businesses and technology groups. Thesuccessful candidate will possess excellent interpersonal and communication skills required topartner with other leaders across the global business to identify opportunities and risks. Theposition will require the ability to multitask and work independently, as well as workcollaboratively with teams, some of which may be geographically distributed.
Key responsibilities include:•Build, maintain and execute a strategy to secure our application ecosystem•Provide technical consultation and direction on secure application design, architecture andsystem security•Perform security reviews, code reviews and threat models of our products; identify any securityissues and develop guidance and plans to remediate•Work with software engineers to design preventative and/or detective controls for specificsecurity issues•Partner with engineering teams to build reusable security components•Facilitate penetration tests and code reviews for applications (web/mobile)•Validate and triage vulnerabilities submitted by researchers from the News Corp bug bountyprogram•Identify security risks and exposures, determine the causes of security violations and suggestsprocedures to prevent future incidents•Help proliferate the use of automated security tools into development workflows to identifysecurity issues quickly•Participate in teaching secure development practices to software engineers
Qualifications and Skills:•Degree in Technology, Computer Science/Engineering, Cybersecurity, a related field orequivalent experience•Demonstrated experience in one or more of the following languages/frameworks: Node.js, PHP,Java, and/or Python•Knowledge of OWASP TOP 10 and CWE Top 25 and how to mitigate them and can explain howto resolve the issues to developers.•Proficient in cloud best practices and security - AWS, GCP and Azure•Experience with Static and Software Composition Analysis tools such as Checkmarx and theirimplementation within CICD build pipelines.•Familiar with container technologies (Docker/Kubernetes etc) and use of cloud services•Expertise on modern web and mobile application security practices and trends•Dev tools experience (Github, Terraform, CircleCI, Jenkins, etc.)
•Working knowledge of common and industry standard cloud-native/cloud-friendly authenticationmechanisms (OAuth, OpenID, AWS IAM etc)•Excellent communication and presentation skills. Ability to effectively communicate, both orallyand in writing, through all levels of the organization•Any additional training, security certifications, or history of responsible disclosure is preferredbut not required
Location: NYC - 3 days a week in office
News Corp is a global diversified media and information services company focused on creatingand distributing authoritative and engaging content to consumers throughout the world. Thecompany comprises businesses across a range of media, including: news and informationservices, book publishing, digital real estate services, cable network programming in Australia,and pay-tv distribution in Australia.Headquartered in New York, the activities of News Corp are conducted primarily in the UnitedStates, Australia, and the United Kingdom.
Job Category:
Pay Range: 80,000 - 100,000
We recognize that attracting the best talent is key to our strategy and success as a company. As a result, we aim for flexibility in structuring competitive compensation offers to ensure we are able to attract the best candidates. The quoted salary range represents our good faith estimate as to what our ideal candidates are likely to expect, and we tailor our offers within the range based on the selected candidate's experience, industry knowledge, location, technical and communication skills, and other factors that may prove relevant during the interview process.
Pay-for-performance is a key element in our strategy to attract, engage, and motivate talented people to do their best work. Similarly to salary, for bonus eligible roles, targets are set based on a variety of factors including competitive market practice.
For benefits eligible roles, in addition to cash compensation, the company provides a comprehensive and highly competitive benefits package, with a variety of physical health, retirement and savings, caregiving, emotional wellbeing, transportation, and other benefits, including "elective" benefits employees may select to best fit the needs and personal situations of our diverse workforce.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, protected veteran status, or disability status. EEO/AA/M/F/Disabled/Vets
Job Description :
Job Description
Product Security Engineer
Location: NYC - 3 days a week in office
Job Description:We have an exciting role for a Product Security Engineer who will be responsible for the design,development, and strategy to secure digital products within NewsCorp supporting the NY POST.
The successful applicant will contribute expertise, embrace emerging trends, and provide overall guidance onsecurity best practices across all of News Corp businesses and technology groups. Thesuccessful candidate will possess excellent interpersonal and communication skills required topartner with other leaders across the global business to identify opportunities and risks. Theposition will require the ability to multitask and work independently, as well as workcollaboratively with teams, some of which may be geographically distributed.
Key responsibilities include:•Build, maintain and execute a strategy to secure our application ecosystem•Provide technical consultation and direction on secure application design, architecture andsystem security•Perform security reviews, code reviews and threat models of our products; identify any securityissues and develop guidance and plans to remediate•Work with software engineers to design preventative and/or detective controls for specificsecurity issues•Partner with engineering teams to build reusable security components•Facilitate penetration tests and code reviews for applications (web/mobile)•Validate and triage vulnerabilities submitted by researchers from the News Corp bug bountyprogram•Identify security risks and exposures, determine the causes of security violations and suggestsprocedures to prevent future incidents•Help proliferate the use of automated security tools into development workflows to identifysecurity issues quickly•Participate in teaching secure development practices to software engineers
Qualifications and Skills:•Degree in Technology, Computer Science/Engineering, Cybersecurity, a related field orequivalent experience•Demonstrated experience in one or more of the following languages/frameworks: Node.js, PHP,Java, and/or Python•Knowledge of OWASP TOP 10 and CWE Top 25 and how to mitigate them and can explain howto resolve the issues to developers.•Proficient in cloud best practices and security - AWS, GCP and Azure•Experience with Static and Software Composition Analysis tools such as Checkmarx and theirimplementation within CICD build pipelines.•Familiar with container technologies (Docker/Kubernetes etc) and use of cloud services•Expertise on modern web and mobile application security practices and trends•Dev tools experience (Github, Terraform, CircleCI, Jenkins, etc.)
•Working knowledge of common and industry standard cloud-native/cloud-friendly authenticationmechanisms (OAuth, OpenID, AWS IAM etc)•Excellent communication and presentation skills. Ability to effectively communicate, both orallyand in writing, through all levels of the organization•Any additional training, security certifications, or history of responsible disclosure is preferredbut not required
Location: NYC - 3 days a week in office
News Corp is a global diversified media and information services company focused on creatingand distributing authoritative and engaging content to consumers throughout the world. Thecompany comprises businesses across a range of media, including: news and informationservices, book publishing, digital real estate services, cable network programming in Australia,and pay-tv distribution in Australia.Headquartered in New York, the activities of News Corp are conducted primarily in the UnitedStates, Australia, and the United Kingdom.
Job Category:
Pay Range: 80,000 - 100,000
We recognize that attracting the best talent is key to our strategy and success as a company. As a result, we aim for flexibility in structuring competitive compensation offers to ensure we are able to attract the best candidates. The quoted salary range represents our good faith estimate as to what our ideal candidates are likely to expect, and we tailor our offers within the range based on the selected candidate's experience, industry knowledge, location, technical and communication skills, and other factors that may prove relevant during the interview process.
Pay-for-performance is a key element in our strategy to attract, engage, and motivate talented people to do their best work. Similarly to salary, for bonus eligible roles, targets are set based on a variety of factors including competitive market practice.
For benefits eligible roles, in addition to cash compensation, the company provides a comprehensive and highly competitive benefits package, with a variety of physical health, retirement and savings, caregiving, emotional wellbeing, transportation, and other benefits, including "elective" benefits employees may select to best fit the needs and personal situations of our diverse workforce.