Product Security Engineer
Lam ResearchAbout the role
The Group You’ll Be A Part Of
The Global Information Systems Group is dedicated to the success of Lam through providing best-in-class and innovative information system solutions and services. Together, we support users globally with data, information, and systems to achieve their business objectives.
The Impact You’ll Make
Lam Information Security is looking for a security engineer to work with our software development teams. The application security engineer will specialize in the building security into existing and new CI/CD pipelines for Lam software. We are looking for an engineer who understands best practices and tools utilized in secure development and building security into the application.
The application security engineer will also support the broader information security strategy to safeguard Lams information systems infrastructure, business systems, and Operational Technology (OT) systems in Lam including engineering/manufacturing Labs.
What You’ll Do
- Contribute to the overall objectives of the Security Engineering team
- Design and guide the implementation of secure software development life cycle practices including threat modeling, code review, static and dynamic code analysis, secured GIT/CVS/SVN, peer review, and vulnerability assessment
- Develop DevSecOps capabilities including identifying security scanning tools (SAST, DAST, IAST,SCA) to be integrated into SDLC processes
- Guide and evangelize the organization in establishing end to end strong secure SDLC/DevOps policies and standards to foster security of CI/CD pipeline
- Research, evaluate and implement new security prototypes to meet an ever-evolving security risk posture
- Design, implement, deploy and maintain security architectures and countermeasures to protect products
- Assess the security of products to discover potential vulnerabilities on products
- Provide subject matter expertise to product engineering teams, advocating for better security process throughout LAM
Who We’re Looking For
- Bachelors degree in Computer Science, Information Security, IT management or related field
- 5+ years of experience in Information Security - related field
- Possess in-depth knowledge of OWASP top 10 and other similar frameworks to lead a team of product security analysts
- Demonstrated experience in product security, including hardware and software
- Experience working with Agile framework
- Ability to drive product and program conversations to negotiate tradeoffs between tactical and strategic goals
- Experience with security activities throughout the software development lifecycle – design reviews, threat modeling, code reviews, tooling, penetration testing
- Experience working with Static/Dynamic/Interactive Application Security Tools and Run-time Application Security Protection tools
- Hands on experience working with tools (Jenkins/Bitbucket/Artifactory)
- CISSP, CompTIA Security+, SANS professional certifications preferred
- Strong people and team/relationship building skills, work with cross functional global teams
Preferred Qualifications
- Experience within a global semiconductor company or equivalent industry experience preferred Breakdown and understand complex problems and the ability to develop a plan and innovative ways to address them
- Experience working in Azure cloud environment, utilizing Microsoft DevOps tools to architect secured coding to protect sensitive data
Our Commitment
We believe it is important for every person to feel valued, included, and empowered to achieve their full potential. By bringing unique individuals and viewpoints together, we achieve extraordinary results.
Lam Research ("Lam" or the "Company") is an equal opportunity employer. L
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s