Sr. Security Engineer, Product Security

2 Months ago • 8 Years + • Cyber Security

Job Summary

Job Description

The Sr. Security Engineer, Product Security will provide technical leadership to a team securing Xerox's digital platforms. Responsibilities include assessing applications for vulnerabilities, implementing secure SDLC processes, performing secure code reviews, developing security automation tools, defining security requirements, conducting security training, reporting on security metrics, researching industry trends, and acting as a security evangelist. This role requires strong application security expertise and collaboration skills.
Must have:
  • Assess applications for vulnerabilities
  • Implement secure SDLC processes
  • Secure code reviews/static analysis
  • Develop security automation tools
  • Threat modelling, security design reviews
  • Security training for development teams
  • Report on product security metrics
  • 8+ years cybersecurity experience, 5+ in product security
Good to have:
  • Java, .Net, C#, C, C++ experience
  • Prior software development experience

Job Details

About the job


About Xerox Holdings Corporation

For more than 100 years, Xerox has continually redefined the workplace experience. Harnessing our leadership position in office and production print technology, we’ve expanded into software and services to sustainably power today’s workforce. From the office to industrial environments, our differentiated business solutions and financial services are designed to make every day work better for clients — no matter where that work is being done. Today, Xerox scientists and engineers are continuing our legacy of innovation with disruptive technologies in digital transformation, augmented reality, robotic process automation, additive manufacturing, Industrial Internet of Things and cleantech. Learn more at www.xerox.com and explore our commitment to diversity and inclusion.

Summary:

This position is part of the Xerox Cyber Security team that is responsible for driving security of Xerox digital platforms. The qualified candidate will provide technical leadership to a multidisciplinary product security team that is responsible for securing enterprise systems, applications, and products across a broad spectrum of technologies. The candidate must demonstrate a passion for application security and lead by example that fosters continued growth and technical expertise within the team.

Responsibilities include, but are not limited to:

  • Assess applications and products for security vulnerabilities and design flaws
  • Implement secure SDLC processes through effective collaboration
  • Manual and Automated Secure Code Review
  • Development of security automation tools
  • Develop and maintain secure coding practices and security engineering standards for the development team
  • Perform threat modelling, security design reviews of application or products and define security requirements as part of SDLC process
  • Security training for internal development teams
  • Track and report on product security metrics and communicate the security posture of products to stakeholders.
  • Research, analyze and report on security industry trends and products
  • Serve as a security evangelist for executive management and business stakeholders.

Knowledge and Skills Required:

  • Strong understanding of common vulnerabilities, attack vectors and corresponding mitigation techniques
  • Experience in performing secure code reviews/reviewing results of static analysis tools
  • In-depth understanding of secure coding practices and secure development life cycle principles.
  • Good understanding of SSDLC as well as development and integration of tools used as part of CI/CD process
  • Have good understanding of authentication and authorization standards and protocols (SAML, Oauth, LDAP etc.)
  • Strong exposure to popular application security standards including OWASP TOP 10, SANS TOP 25 etc.
  • Proficiency with at least one of the following programming languages desired: Java, .Net, C#, C, C++
  • Prior software development experience is a plus.
  • Strong interpersonal skills as well as excellent written and verbal communication skills
  • Uncompromising personal and professional integrity and ethics

Education and Experience Required:

  • B.S in computer science, information systems, engineering or related field.
  • Advanced degree preferred, i.e. MBA or MS
  • Over 8 years of experience in cybersecurity, with at least 5 years in product security
  • One or more Industry-standard security certifications (such as OSCP, OSWE, CWEE, OSED)

Similar Jobs

BigID - Data Engineering Team Lead

BigID

Tel Aviv-Yafo, Tel Aviv District, Israel (Hybrid)
2 Months ago
Nagarro - Principal Engineer, Hybris

Nagarro

India (Remote)
3 Months ago
Netflix - Data Engineering Intern, Summer 2025

Netflix

Los Gatos, California, United States (On-Site)
1 Month ago
Dun & Bradstreet - Northern Europe Technology Development Lead (R-16409)

Dun & Bradstreet

Solna, Stockholm County, Sweden (Hybrid)
4 Months ago
ByteDance - Senior Software Engineer, Multi Cloud CDN - San Jose / Seattle / Boston

ByteDance

Boston, Massachusetts, United States (On-Site)
1 Month ago
Barco - System Engineer - IT SecOps

Barco

Noida, Uttar Pradesh, India (Hybrid)
3 Months ago
Granicus - Senior Security Analyst

Granicus

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
Palo Alto Networks - Domain Consultant - Security Operations Transformation

Palo Alto Networks

New Haven, Connecticut, United States (Remote)
2 Months ago
Wind River Systems - Star Lab - Field Applications Engineer, System Architect

Wind River Systems

San Antonio, Texas, United States (Hybrid)
3 Months ago
Palo Alto Networks - Presales Manager - Network Security (Domain Consulting)

Palo Alto Networks

St. Gallen, St. Gallen, Switzerland (Remote)
2 Months ago

Get notifed when new similar jobs are uploaded

Similar Skill Jobs

PwC - AES-SAP-CPI-EDI-Associate

PwC

Hyderabad, Telangana, India (On-Site)
2 Months ago
Crunchyroll - Senior Engineering Manager, Membership

Crunchyroll

San Francisco, California, United States (Hybrid)
2 Months ago
Luxoft - Regular Android HMI Architect

Luxoft

Cairo, Cairo Governorate, Egypt (On-Site)
2 Months ago
PwC - SAP - CPI - Senior Associate- Bangalore

PwC

Bengaluru, Karnataka, India (On-Site)
1 Month ago
King - Senior Data Engineer

King

Barcelona, Catalonia, Spain (On-Site)
3 Months ago
Microsoft - Software Engineer

Microsoft

Prague, Prague, Czechia (On-Site)
2 Weeks ago
ION - Senior Java Developer - Italy

ION

Collecchio, Emilia-Romagna, Italy (On-Site)
4 Months ago
Qventus,  Inc  - QA Automation Engineer

Qventus, Inc

Noida, Uttar Pradesh, India (Hybrid)
3 Months ago
Nagarro - Associate Staff Engineer, Mobile Android

Nagarro

Cebu City, Central Visayas, Philippines (On-Site)
3 Months ago
Warner Bros Games - Staff Software Engineer

Warner Bros Games

(Hybrid)
1 Week ago

Get notifed when new similar jobs are uploaded

Jobs in Bengaluru, Karnataka, India

GoTo Group - Software Engineer - Comms Platform

GoTo Group

Bengaluru, Karnataka, India (On-Site)
3 Months ago
ALIV - Social Media Manager

ALIV

Pune, Maharashtra, India (On-Site)
5 Months ago
Zeta - Product Manager II (Credit on UPI)

Zeta

Mumbai, Maharashtra, India (On-Site)
3 Months ago
Telesign - Site Reliability Engineer (SRE) III

Telesign

Bengaluru, Karnataka, India (On-Site)
4 Months ago
Sporty Group - IN Associate - Customer Success (Gurugram)

Sporty Group

Delhi, India (On-Site)
6 Months ago
MiQ - Software Engineer II

MiQ

Bengaluru, Karnataka, India (Hybrid)
3 Months ago
Paytm - Sales Team Lead

Paytm

Tirupati, Andhra Pradesh, India (On-Site)
2 Months ago
Birdeye Australia - Motion Designer

Birdeye Australia

Gurugram, Haryana, India (On-Site)
4 Months ago
RASALAYA SCHOOL OF FILMS AND ARTS - Acting triner

RASALAYA SCHOOL OF FILMS AND ARTS

Vijayawada, Andhra Pradesh, India (On-Site)
4 Months ago
CloudHire - Business Analyst

CloudHire

Mumbai, Maharashtra, India (Hybrid)
3 Months ago

Get notifed when new similar jobs are uploaded

Cyber Security Jobs

PwC - Senior Associate, Infrastructure and Operations, Cybersecurity

PwC

Vaughan, Ontario, Canada (On-Site)
3 Weeks ago
PwC - IT Controls Consultant

PwC

Sofia, Sofia City Province, Bulgaria (Hybrid)
4 Months ago
ION - Network Security Engineer

ION

Italy (Hybrid)
4 Months ago
Canva - Engineering Manager (BE) - Security Platform Engineering (Remote across ANZ)

Canva

Sydney, New South Wales, Australia (Remote)
2 Months ago
Wind River Systems - Star Lab - Field Applications Engineer, System Architect

Wind River Systems

San Antonio, Texas, United States (Hybrid)
3 Months ago
Scorewarrior - Security Manager

Scorewarrior

Limassol, Limassol, Cyprus (On-Site)
1 Week ago
Rackspace Technology - SOC Lead (Sentinel experience required)

Rackspace Technology

India (Remote)
2 Weeks ago
PwC - Senior Consultant en Cybersécurité GRC | CDI | H/F

PwC

Neuilly-sur-Seine, Île-de-France, France (On-Site)
4 Months ago
Hitachi Digital Services - Container Security - Expert

Hitachi Digital Services

Bengaluru, Karnataka, India (Hybrid)
4 Months ago
PwC - Endpoint Engineer - US Client (Olivos/Barracas)

PwC

Olivos, Buenos Aires Province, Argentina (On-Site)
3 Months ago

Get notifed when new similar jobs are uploaded