Jobs and Careers
RI

Security Application Engineer

RingCentral
United Statesfull_timeVerifiedPosted 4 Jun 2024
💰 $170,000/yr($120,000/yr$170,000/yr)

About the role

Security Application Engineer, DAST Scanning (Belmont CA, Denver CO, Dallas TX) 


The RingCentral environment is dynamic, success-driven, team-oriented and committed to providing world class service for its customers. Do you have the ability to thrive in a fast-paced environment?  We are looking for candidates with an entrepreneurial spark!


We’re not a phone company; we’re a cloud business-solutions provider. We've thrown out the old PBX along with its rigid rules and eliminated the complexity and unnecessary expense of managing business communications the old way.
RingCentral fosters career development and provides leadership training, education, workshops, and coaching for all employees.

RingCentral promotes a healthy work-life balance by providing catered lunch and breakfast on a daily basis as well as a kitchen stocked with a variety of complimentary beverages and delicious snacks.


The RingCentral Application Security team is a part of a larger CISO team. The area of responsibility of the application security team includes enablement and support for RingCentral’s Security Development Lifecycle (SDL) program. This includes development of infosec governance artifacts i.e., policies, standards and procedures for secure software development at RingCentral, leading security architecture reviews and threat modelings, developing security requirements, SAST/DAST/SCA testing and integration of these tools into the build and deploy process, penetration testing, managing bug bounty program.


We are looking for a Security Application Engineer with a strong understanding of web and mobile application vulnerabilities, how they can be detected, exploited and remediated.


Responsibilities:
Consult developers on questions related to reports of security scanners*, which includes:
⦁    explain why an issue should be considered as a vulnerability
⦁    explain circumstances under which an issue might be exploitable
⦁    provide suggestions on how an issue can be remediated
Review and validate issues marked as potential false positives by developers; request additional clarifications where required.
Review and improve security scanners configurations:
⦁    review scanning rules in presets, make sure that important rules are enabled and irrelevant rules are disabled
⦁    make sure security scanners do not miss production code/applications, as well as do not scan testing-only code/applications
⦁    where possible and required, adjust scanning rules to improve their accuracy
⦁    collaborate with legal to make sure that license violation rules for open source software are configured correctly
Maintain access to security scanners.
Report breached security defects SLA.
Support risk exceptions process for the following cases:
⦁    violations of security defects SLA
⦁    deviations from security policies/standards (for example, releasing with a higher vulnerability level than defined as satisfactory)
Triage reports from the bug bounty platform, address them to responsible engineering teams
Triage reports from the external attack surface management platform, address them to responsible engineering teams
Maintain security scanners deployed in production environment, which includes:
⦁    deploy new versions
⦁    patch security vulnerabilities
⦁    make sure security hardening benchmarks are met (such as CIS or STIG)
⦁    make sure other requirements for production deployment are met (logging, monitoring, backups, etc.)
* - security scanners include, but are not limited to static application security testing (SAST), dynamic application security testing (DAST) and software composition analysis (SCA)

Qualifications:
⦁    Technical experience in product architecture, design, implementation
⦁    Expertise with product security design, review, implementation including threat modeling and risk assessment implications
⦁    U.S citizenship required
⦁    Extensive experience with web and mobile application testing- SAST/DAST, penetration testing
⦁    Secure design and implementation capabilities
⦁    Experience with open-source software including lifecycle management, vulnerability management tools
⦁    Excellent communication skills, both verbal and written; ability to condense complicated scenarios into simple, risk-based assessments, appropriately targeted for colleagues and upper management
⦁    Outstanding organizational and time management skills, desire to work within a highly collaborative team

Nice-To-Have:
⦁    Any WebRTC, Video and audio streaming
⦁    Video codecs
⦁    B.S. or equivalent in CS or EE

What we offer:
RingCentral offers all the work/life benefits you could ever want, (and none of the micromanagement.)
⦁    Comprehensive medical, dental, vision, disability, life insuranc

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

RingCentral

View company profile →