Source description
About the role
As an Engineer, Product Security at Omnicom Global Solutions, you will play a crucial role in supporting secure software development, risk mitigation, and product security best practices across automated platforms and infrastructure-as-code environments. You will collaborate with development and DevOps teams to embed security into all stages of the product lifecycle, ensuring secure, scalable, and compliant services across Omnicom's digital ecosystem. Key Responsibilities: - Assist in implementing secure software development standards and practices. - Support integration of security measures into automated service platforms and infrastructure-as-code. - Conduct regular security assessments and vulnerability scans for applications and infrastructure. - Analyse and report on security risks and vulnerabilities; provide mitigation recommendations. - Collaborate with the incident response team on investigations and real-time threat intelligence. - Monitor and manage security tools to detect and respond to application and infrastructure threats. - Continuously monitor cloud environments and SaaS platforms for emerging security threats. - Work closely with development, QA, and IT teams to support secure software delivery. - Prepare and present security metrics, reports, and summaries to Product Security Leads and stakeholders. - Deliver security awareness training on secure software development and SecDevOps practices. - Contribute to the maintenance of security documentation and internal guidelines. Qualifications Required: - 3-5 years of experience in cybersecurity, software engineering, or DevOps with a focus on product security. - Familiarity with security assessment tools (e.g., SAST, DAST scanners) and CI/CD environments. - Basic understanding of secure coding, cloud security, and infrastructure-as-code practices. - Hands-on experience with tools such as GitHub, AWS, Terraform, Jenkins, Docker, etc. - Understanding of IT governance frameworks (e.g., SDLC, ITIL) is a plus. - Strong analytical, documentation, and troubleshooting capabilities. - Bachelor's degree in Cybersecurity, Computer Science, IT, or related field. - Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security, SIEM, and risk analysis. - Certifications such as Security+ or CEH are a plus. Note: Preferred qualifications include AppSec depth (CSSLP, eWPT), Cloud specialization (AWS Security), Foundational credibility (Security+), CEH, and experience with cloud security frameworks and zero trust architecture. As an Engineer, Product Security at Omnicom Global Solutions, you will play a crucial role in supporting secure software development, risk mitigation, and product security best practices across automated platforms and infrastructure-as-code environments. You will collaborate with development and DevOps teams to embed security into all stages of the product lifecycle, ensuring secure, scalable, and compliant services across Omnicom's digital ecosystem. Key Responsibilities: - Assist in implementing secure software development standards and practices. - Support integration of security measures into automated service platforms and infrastructure-as-code. - Conduct regular security assessments and vulnerability scans for applications and infrastructure. - Analyse and report on security risks and vulnerabilities; provide mitigation recommendations. - Collaborate with the incident response team on investigations and real-time threat intelligence. - Monitor and manage security tools to detect and respond to application and infrastructure threats. - Continuously monitor cloud environments and SaaS platforms for emerging security threats. - Work closely with development, QA, and IT teams to support secure software delivery. - Prepare and present security metrics, reports, and summaries to Product Security Leads and stakeholders. - Deliver security awareness training on secure software development and SecDevOps practices. - Contribute to the maintenance of security documentation and internal guidelines. Qualifications Required: - 3-5 years of experience in cybersecurity, software engineering, or DevOps with a focus on product security. - Familiarity with security assessment tools (e.g., SAST, DAST scanners) and CI/CD environments. - Basic understanding of secure coding, cloud security, and infrastructure-as-code practices. - Hands-on experience with tools such as GitHub, AWS, Terraform, Jenkins, Docker, etc. - Understanding of IT governance frameworks (e.g., SDLC, ITIL) is a plus. - Strong analytical, documentation, and troubleshooting capabilities. - Bachelor's degree in Cybersecurity, Computer Science, IT, or related field. - Strong technical skills relevant to Information Security such as secure coding standards, ethical hacking techniques, network security, SIEM, and risk analysis. - Certifications such as Security+ or CEH are a plus. *Note: Prefe
More at Annalect