Security Engineer

hace 4 horas


Ciudad de México, Ciudad de México PepsiCo Deutschland GmbH A tiempo completo
Job Description

About the Role
PepsiCo Deutschland GmbH is seeking an experienced Application Security Engineer to join our team. As an Application Security Engineer, you will play a critical role in driving the integration of automated security tools into our CI/CD pipelines and ensuring continuous monitoring to identify and manage security risks.

Key Responsibilities

  1. Implementing and managing automated security tools within CI/CD pipelines, ensuring seamless integration and enhanced security posture.
  2. Integrating and operating a centralized findings management system to efficiently manage and track security vulnerabilities and remediation efforts.
  3. Defining and implementing strategies to configure automated security tools for optimal performance, establishing and monitoring KPIs to measure effectiveness and drive continuous improvement.
  4. Developing and maintaining greenfield automation solutions and full-stack applications to support and enhance application security.
  5. Tuning rule sets and detections for automated security tools to improve detection capabilities and reduce false positives.
  6. Providing expert guidance in triaging and remediating security vulnerabilities, and mentoring team members and engineering teams in understanding and addressing security issues.
  7. Fostering a collaborative environment that promotes knowledge sharing, and mentoring junior engineers to build a skilled security team.
  8. Continuously researching and presenting new concepts to improve the business's application security posture, staying up to date with the latest security trends and practices.
  9. Developing technical documentation such as system designs, architecture diagrams, data flows, and functional specifications.
  10. Contributing to the future state of cybersecurity by conducting technical assessments between the current and desired states across security tools and services.
  11. Developing program metrics to continuously measure progress and impact, and driving improvements.
  12. Collaborating with senior leadership and cross-functional teams, including DevOps, development teams, security operations, data & analytics, enterprise architecture, platform teams, and sector functions.
  13. Executing projects, objectives, and deliverables in alignment with the team's vision, mission, and goals.
  14. Engaging in knowledge transfer sessions, technical design reviews, security reviews, and business review meetings.

Requirements

  1. Deeply experienced in at least one programming language (Java, C#, Go) and scripting language (Python, Bash, PowerShell).
  2. Highly skilled in at least one database management system and query language (e.g., MSSQL, PostgreSQL).
  3. Strong experience in developing full-stack applications and rapid prototyping to support automated data collection, aggregation, and analysis.
  4. Skilled in integrating and managing automated security tools within CI/CD pipelines.
  5. Expertise in application security vulnerabilities and remediation techniques (e.g., OWASP Top Ten).
  6. Experience with application security testing tools (e.g., Synopsys, OpenText Fortify, Snyk, Semgrep).
  7. Familiarity with modern CI/CD tools and practices (e.g., Jenkins, Azure DevOps, GitHub Enterprise, Circle CI, Heroku).
  8. Experience with public cloud services (e.g., Azure, AWS, Alibaba).

Nice-to-Have

  1. Experience writing custom vulnerability detection patterns/rules.
  2. Experience implementing and managing Web Application Firewalls (e.g., Fortinet, Imperva, Cloudflare, Akamai, Azure WAF, AWS WAF).
  3. Experience with CMS security (e.g., WordPress, Drupal, Joomla, OpenText TeamSite, Concrete CMS).
  4. Familiarity with generative AI technologies.
  5. Information Security certifications (e.g., CISSP, OSCP, GPEN, GWAPT, GXPN, GSE).
  6. Experience with Centralized Findings Management Systems (e.g., Azure DevOps, Jira, ServiceNow VR/AVR, PlexTrac, DefectDojo, ThreatFix).
  7. Proficient in developing and monitoring metrics and KPIs to measure security effectiveness.

Soft Skills

  1. Demonstrated ability to innovate and drive continuous improvement.
  2. Ability to handle high-pressure situations with a calm and methodical approach.
  3. Strong organizational skills, with the ability to prioritize tasks and manage time effectively.
  4. Experience collaborating with globally dispersed teams to achieve unified outcomes.
  5. Strong decision-making skills, with the ability to weigh costs/benefits/trade-offs and find optimal resolutions.


  • Ciudad de México, Ciudad de México Lyft A tiempo completo

    Secure the Future of TransportationAt Lyft, we're revolutionizing the way people move around the world. As a Software Security Engineer, you'll play a critical role in ensuring the security of our systems and protecting our users' data.We're looking for a talented engineer with a passion for security to join our team. You'll work closely with our engineering...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleWe are seeking a highly skilled Senior Security Engineer to join our team at Thomson Reuters. As a key member of our Information Security and Risk Management (ISRM) Product Security team, you will play a critical role in ensuring the security and integrity of our products and services.Key ResponsibilitiesWork closely with cross-functional teams...

  • Cloud Security Engineer

    hace 2 semanas


    Ciudad de México, Ciudad de México Cognizant A tiempo completo

    We are seeking a talented Cloud Security Engineer to join our team at Cognizant. As a Cloud Security Engineer, you will play a key role in ensuring the security and integrity of our clients' data in the cloud.Key Responsibilities:Design and implement secure cloud architectures using Google Cloud Platform (GCP) servicesConduct security assessments and...

  • Cloud Security Engineer

    hace 3 semanas


    Ciudad de México, Ciudad de México Adenza A tiempo completo

    At Adenza, we are seeking a highly skilled Cloud Security Engineer to join our team. The ideal candidate will have a strong background in cloud security, with experience in designing and implementing secure cloud architectures.Responsibilities:Identify vulnerabilities and weaknesses in our cloud infrastructure and provide recommendations to mitigate...

  • Security Engineer

    hace 4 semanas


    Ciudad de México, Ciudad de México Cover Genius A tiempo completo

    About the RoleWe are seeking a highly skilled Security Engineer to join our team at Cover Genius. As a Security Engineer, you will be responsible for designing and implementing secure cloud infrastructure, assessing and mitigating security risks, and developing comprehensive security processes.Key ResponsibilitiesDesign and implement secure cloud...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleWe are seeking a highly skilled Senior Security Engineer to join our Information Security and Risk Management (ISRM) Product Security team. As a key member of our team, you will play a critical role in ensuring the security of our applications and systems.Key ResponsibilitiesWork closely with cross-functional teams to foster a security-centric...


  • Ciudad de México, Ciudad de México Factorial HR A tiempo completo

    Job Title: DevSecOps EngineerJob Description:We're seeking a talented and experienced DevSecOps Engineer to join our Security Operations Team. As a key member of our team, you'll be responsible for safeguarding our systems and data.The Role:Develop and manage security tooling to ensure accurate threat detection and swift response in different...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    As a Principal Cybersecurity Engineer within the Information Security and Risk Management (ISRM) Product Security team, you will play a pivotal role in our commitment to deliver seamless and ongoing security to our engineering teams, who are dedicated to developing our products with a focus on secure practices. We assure you that our ambitious security...


  • Ciudad de México, Ciudad de México Johnson Controls International A tiempo completo

    Job Title: Global Cyber Security Network EngineerAbout the Role:We are seeking a highly skilled Global Cyber Security Network Engineer to join our team at Johnson Controls International. As a key member of our global team, you will be responsible for assisting in the development of network cyber security standards and governance of network...


  • Ciudad de México, Ciudad de México Johnson Controls A tiempo completo

    Job Title: Global Cyber Security Network EngineerAbout the Role:We are seeking a highly skilled Global Cyber Security Network Engineer to join our team at Johnson Controls. As a key member of our global team, you will be responsible for assisting in the development of network cyber security standards and governance of network implementations.Key...

  • Security Engineer

    hace 3 semanas


    Ciudad de México, Ciudad de México Cover Genius A tiempo completo

    About the RoleWe are seeking a highly skilled Cloud Security Engineer to join our team at Cover Genius. As a key member of our security team, you will be responsible for designing and implementing secure cloud infrastructure, ensuring compliance with industry standards and regulations, and collaborating with cross-functional teams to drive security...


  • Ciudad de México, Ciudad de México Medallia A tiempo completo

    Job OverviewMedallia, the pioneer and market leader in Experience Management, is seeking a skilled Product Security Engineer to join our team. Our award-winning SaaS platform, Medallia Experience Cloud, is designed to understand and manage experience for various stakeholders. As a Product Security Engineer, you will play a crucial role in building customer...

  • Security Test Engineer I

    hace 3 semanas


    Ciudad de México, Ciudad de México oilandgas A tiempo completo

    Product Security Test EngineerAt Honeywell, we're innovating to solve the world's most important challenges. As a Product Security Test Engineer, you'll be part of our global product development team, responsible for performing Firmware Verification and Cybersecurity Release on Fire Alarm control panels and devices.Key Responsibilities:Manage the...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the Role: We are seeking a highly skilled Cyber Security Platform Engineer to join our team at Thomson Reuters. As a key member of our cyber defense team, you will be responsible for delivering high-quality solutions across various cyber security functions, including threat detection, cyber threat intelligence, network security, incident response, and...


  • Ciudad de México, Ciudad de México Thomson Reuters A tiempo completo

    About the RoleWe are seeking a highly skilled Senior Cyber Security Platform Engineer to join our team. As a key member of our cyber security function, you will be responsible for delivering high-quality solutions across various cyber security functions, including threat detection, cyber threat intelligence, network security, incident response, and more.Key...

  • Endpoint Security Expert

    hace 1 semana


    Ciudad de México, Ciudad de México Baker Hughes Gruppe A tiempo completo

    Job Title: Sr Endpoint Security EngineerWe are seeking a highly skilled Sr Endpoint Security Engineer to join our team. The successful candidate will be responsible for implementing and maintaining endpoint security solutions to protect our systems and data.About the RoleImplement and maintain endpoint security solutions, including antivirus software and...


  • Ciudad de México, Ciudad de México TeleTech A tiempo completo

    About the RoleWe are seeking an experienced Information Security Principal Engineer to join our team. As a key member of our Information Security team, you will be responsible for providing security guidance and support to our sales and proposal teams.Key ResponsibilitiesProvide security guidance and support to sales and proposal teamsConduct security...

  • Windows Security Engineer

    hace 2 semanas


    Ciudad de México, Ciudad de México Kal A tiempo completo

    We are seeking a skilled professional to fill the role of Windows Security Engineer at Kal in Mexico City. The ideal candidate will have hands-on experience with Windows Defender Application Control (WDAC), AppLocker, and BitLocker, and will be responsible for designing and developing secure Windows-based applications and tools.Key ResponsibilitiesDevelop...

  • Security Engineer

    hace 3 semanas


    Ciudad de México, Ciudad de México Lyft A tiempo completo

    At Lyft, our mission is to improve people's lives with the world's best transportation. To achieve this, we need a strong security team that can ensure our systems are secure and worthy of our users' trust. We're looking for a skilled Security Engineer to join our Application Security Team.The ideal candidate will have experience in penetration testing...


  • Ciudad de México, Ciudad de México Travel + Leisure Co A tiempo completo

    Network Security Services Engineer RoleTravel + Leisure Co. seeks a skilled Network Security Services Engineer to maintain the daily security and operation of our global enterprise data network. This position involves supporting the maintenance, implementation, and configuration of network and security infrastructure and associated services, including...