Nissan is a pioneer in Innovation and Technology. With a focus on Mobility, Operational Excellence, Value to our Customers and Electrification of vehicles, you can expect to be part of a very exciting journey here at Nissan.
Nissan is going after a massive Digital Transformation backed by leading technologies across the organization globally. We are committed to building a diverse, entrepreneurial organization, and our current team is a strong evidence of that. Our people are what drive the business forward. At Nissan Digital, you will be part of a dynamic team with ample opportunities to grow and make a difference
What are We Looking For?
Vulnerability and Threat Management is a global team of Security practitioners dedicatedly working towards implementing and managing enterprise vulnerability tools and processes in on-premise and cloud environments, to reduce technical risks due to vulnerabilities. This includes identifying and evaluating vulnerabilities and supporting remediation activities.
Development Security Analyst proactively support work force diversity. The best candidate shall be selected based on their skills and ability to work within the Vulnerability and Threat Management Team regardless of their gender, age, religion, race or education. As a Development Security Analyst, your duties are to work with DevOps team to help Source Code scanning at different stages of code development and guide them to remediate security risks.
Key Responsibilities:
- Participate in DevSec program (Static analysis Security Testing, Container Security)
- Periodically executing penetration testing of web and mobile applications (Android, iOS, Windows)
- Developing, implementing, and operating a container security solution.
- Experience in automated solutions to help incorporate Security in all stages of the DevOps pipeline (app and infra). This includes (but not limited to) SAST, DAST and Container scanning
- Experience with container security tools on AWS (ECS, Fargate)
- Build secure pathways, which make it easier for developers to write secure code. This includes building security-first libraries, frameworks and blueprints
- Experience with Tools like BurpSuite - Professional & Enterprise, Nessus, Prisma Cloud, Clair, Trufflehog, Defect Dojo, Veracode and DAST/SAST scanners
- Ready to work with a global, multicultural team spread across time zones and geographies.
Mandatory Skills & Technical Competencies:
- Proficient in written and verbal communication with technical and non-technical audiences
- Knowledge of computer networks and protocols
- Microsoft, LINUX, and Macintosh operating systems
- Virtualization software tools
- Familiarity with scripting languages such as PHP, Perl, Python, PowerShell or Bash. Cybersecurity principles
- Manual and automated vulnerability assessment tools and techniques
- Conducting vulnerability scans and recognizing vulnerabilities in security systems
- Cybersecurity threats and vulnerabilities
- Operational impact of cybersecurity lapses.
- Identifying vulnerabilities and evaluating risk
- Secure source code analysis.
- Use of penetration testing tools and techniques
- Technologies and fundamentals of securing container applications
Experience & Expertise:
- 5+ years of Cybersecurity experience
- 2-3 years of work Secure SDLC and Container Security experience
- Cyber Security Certification (CISSP, CEH, etc.) are added advantage
- Application development
- Windows and Linux server operation
- AWS and Azure cloud environments (ECS, Fargate, etc…)
- Application Container technology (Docker)
- CI/CD Pipeline (Jenkins, BitBucket, etc…
You'd Make an Ideal Candidate if You:
- Get genuinely excited about leveraging technology to find simple solutions to really hard, complex problems
- Enjoy working with, and leading a passionate, multi-disciplinary team in an agile, fast-paced environment
- Are data-driven and analytical in your approach, and are able to effectively keep the big picture in perspective while still being extremely detail-oriented when it comes to your product
- Love being the underdog and cherish the opportunity to compete with the established behemoths in your domain (Amazon, Facebook, Google etc.)
- Have had your share of failures and take pride in sharing the lessons you've learned from those experiences
Drive your career forward and join the company leading the technology and business evolution in the automotive industry