At a Glance
- Tasks: Join our Cyber Security team to embed security in the Software Development Lifecycle.
- Company: Boomi, a fast-growing tech company making a global impact.
- Benefits: Competitive salary, inclusive culture, and opportunities for personal growth.
- Why this job: Make a real difference by ensuring top-notch security for innovative products.
- Qualifications: Experience in product security and proficiency with security testing tools.
- Other info: Diverse and inclusive environment with a focus on authenticity.
The predicted salary is between 28800 - 48000 £ per year.
About Boomi and What Makes Us Special
Are you ready to work at a fast-growing company where you can make a difference? Boomi aims to make the world a better place by connecting everyone to everything, anywhere. Our award-winning, intelligent integration and automation platform helps organizations power the future of business. At Boomi, you’ll work with world-class people and industry-leading technology. We hire trailblazers with an entrepreneurial spirit who can solve challenging problems, make a real impact, and want to be part of building something big.
How You'll Make An Impact
- You will join the Cyber Security Engineering job family, focusing on embedding security into the entire Software Development Lifecycle (SDLC) for Boomi's product suite.
- You will collaborate closely with development and QA teams to perform threat modeling, conduct security assessments, and manage vulnerability remediation efforts.
- Your primary goal is to ensure that Boomi's award-winning technology maintains the highest standards of security, reducing product risk before deployment.
Role Responsibilities:
- Focus on embedding security into the entire Software Development Lifecycle (SDLC) to reduce product risk before deployment.
- Collaborate with development and QA teams to perform threat modeling, security assessments, and manage vulnerability remediation efforts.
- Work collaboratively to integrate security controls into CI/CD pipelines, supporting the team's goal of maintaining high security standards for Boomi’s product suite.
- Translate complex compliance requirements (such as SOC, FedRAMP, and ISO) into specific technical implementation details for cloud and on-premises systems.
- Serve as a technical bridge between security, engineering, and product teams to ensure cohesive security implementation.
Requirements:
- Several years of experience in product security, application security, or a similar role.
- Proficiency with application security testing tools (SAST, DAST, IAST) and vulnerability management.
- Experience performing manual and automated code reviews in common languages (e.g., Java, Python, JavaScript).
- Strong understanding of the OWASP Top 10, common application security vulnerabilities, and defensive coding practices.
Preferred Education:
- Bachelor’s Degree in Computer Science or a related technical discipline.
- CISSP or similar product security certifications.
Preferred Requirements:
- Experience with security in CI/CD pipelines (DevSecOps).
We take pride in our culture and core values and are committed to being a place where everyone can be their true, authentic self. Our team members are our most valuable resources, and we look for and encourage diversity in backgrounds, thoughts, life experiences, knowledge, and capabilities.
All employment decisions are based on business needs, job requirements, and individual qualifications. Boomi strives to create an inclusive and accessible environment for candidates and employees. If you need accommodation during the application or interview process, please submit a request.
Product Security Analyst employer: Boomi
Contact Detail:
Boomi Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Product Security Analyst
✨Tip Number 1
Network like a pro! Reach out to folks in the industry, especially those at Boomi. A friendly chat can open doors and give you insights that a job description just can't.
✨Tip Number 2
Prepare for the interview by brushing up on your technical skills. Dive into the OWASP Top 10 and be ready to discuss how you've tackled security challenges in past roles.
✨Tip Number 3
Show your passion for security! Share examples of how you've embedded security into the SDLC in previous jobs. This will demonstrate your commitment to maintaining high standards.
✨Tip Number 4
Don't forget to apply through our website! It’s the best way to ensure your application gets noticed. Plus, it shows you're genuinely interested in being part of the Boomi team.
We think you need these skills to ace Product Security Analyst
Some tips for your application 🫡
Tailor Your CV: Make sure your CV speaks directly to the role of Product Security Analyst. Highlight your experience with application security, threat modelling, and any relevant tools you've used. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about security in the SDLC and how you can contribute to Boomi's mission. Keep it concise but impactful – we love a good story!
Show Off Your Technical Skills: Don’t shy away from showcasing your technical expertise. Mention specific tools like SAST, DAST, or IAST that you’ve worked with, and give examples of how you've tackled vulnerabilities in the past. We’re keen to see your hands-on experience!
Apply Through Our Website: We encourage you to apply through our website for the best chance of getting noticed. It’s super easy, and you’ll be able to keep track of your application status. Plus, it shows us you’re genuinely interested in joining our team!
How to prepare for a job interview at Boomi
✨Know Your Stuff
Make sure you brush up on your knowledge of application security, especially the OWASP Top 10. Be ready to discuss how you've applied this knowledge in past roles, particularly in relation to threat modelling and vulnerability management.
✨Show Your Collaborative Spirit
Since the role involves working closely with development and QA teams, be prepared to share examples of how you've successfully collaborated in the past. Highlight any experiences where you integrated security into CI/CD pipelines or worked as a bridge between teams.
✨Get Technical
Familiarise yourself with the specific tools mentioned in the job description, like SAST, DAST, and IAST. If you have experience with manual and automated code reviews, be ready to discuss your approach and any challenges you faced.
✨Understand Compliance Requirements
Be prepared to talk about how you've translated complex compliance requirements into technical implementations. Knowing about SOC, FedRAMP, and ISO will give you an edge, so make sure you can explain these concepts clearly.