Logo
IBM

Software Engineering Security Lead Engineer Professional San Jose, US

IBM, San Jose, California, United States, 95199


IntroductionA career in IBM Software means you’ll be part of a team that transforms our customer’s challenges into solutions.

Seeking new possibilities and always staying curious, we are a team dedicated to creating the world’s leading AI-powered, cloud-native software solutions for our customers. Our renowned legacy creates endless global opportunities for our IBMers, so the door is always open for those who want to grow their career.

We are seeking a skilled back-end developer to join our IBM Software team. As part of our team, you will be responsible for developing and maintaining high-quality software products, working with a variety of technologies and programming languages.

IBM’s product and technology landscape includes Research, Software, and Infrastructure. Entering this domain positions you at the heart of IBM, where growth and innovation thrive.Your Role and Responsibilities

Our mission is to revolutionize customer service by developing and deploying the latest conversational artificial intelligence (AI) technology in IBM’s industry-leading conversational AI products. We are proud of our state-of-the-art, secure and scalable application infrastructure, where data confidentiality, performance and security are the primary requirements. We believe in open architectures and open standards, and we run our cutting-edge AI on every cloud.

We are passionate about designing elegant APIs, microservices, Hybrid Cloud based AI applications and databases with huge datasets. If you share our passion for great software secure engineering, working in cross-functional teams, and fast-paced challenging projects, this is the job for you!This position is for the Security and Compliance lead on our team, who will take on varied responsibilities in assuring the security and compliance of IBM watsonx Assistant and watsonx Orchestrate. The candidate should have a passion for working with engineering teams daily on security related issues, has a willingness to learn, and recognizes and fills gaps related to defined security controls that must be implemented as part of our defined business processes. You will also work closely with the broader IBM Security subject matter experts, Product Managers and Customers. If you thrive in a fast-paced environment, think like both an attacker and defender, please get in touch with us!The candidate should have a general background in information technology and be willing to gain experience on the job while working across the organization, hand in hand with peer security focal points. You will help create solutions that balance business requirements with company information and IBM security requirements. We value security related technical knowledge in any of the following fields: Cryptography, Network, Infrastructure, Software Security, CICD Pipelines, Virtualization, Cloud-Native Technologies and Cloud Infrastructure, Application Security, Malware Analysis, Security Operations, and Incident Response.Key Responsibilities

Ensures IBM software meets regulatory and security compliance requirementsStrive to reduce risk and maintain compliance to IBM’s IT Security StandardsIdentify security design gaps in existing and proposed architectures, and provide recommendations on security related decisions and improvementsSupports other compliance focal points by participating in security reviews/audits and providing compliance evidence, as requiredAssist in coordination to address vulnerabilities and penetration type testing activitiesAct as a primary security contact for IBM watsonx Assistant and watsonx OrchestrateRequired Technical and Professional Expertise

Experience working in security areas dealing with secure engineering, security controls, vulnerabilities, and audits, etc.Working knowledge of cloud technologies with the ability to describe security concerns and what the impact might be for an organization.Good communication and critical thinking skills.Preferred Technical and Professional Expertise

Kubernetes/Containers experience, command line knowledge.External audit standards and process knowledge (ISO 27K, HIPAA, PCI-DSS, SOC 2, FedRAMP).General development, scripting knowledge and use of APIs for utilities, comfortable with GitHub and ZenHub, experience with code scanning and analysis of results.Familiarity with IBM Cloud, Red Hat OpenShift Platforms or other Public Cloud platforms.

#J-18808-Ljbffr