Aspen Technology→
Product Security Engineer at Aspen Technology in Twin Cities Area
Entry LevelHybridFull-timeTwin Cities Area$82k–$102k/yr
Skills
product secure development lifecyclevulnerability managementinformation security frameworksindustrial control systemssecurity documentationautomation skillsrisk assessmentcommunication skills
Job Description
Summary: Aspen Technology is a leading company that drives innovation in the field of digital grid management. They are seeking a Product Security Engineer to join their Research & Development department, focusing on protecting clients and ensuring secure development practices within the organization.
Responsibilities:
- Responsible for supporting the design, implementation, and oversight of Product Secure Development Lifecycle. Including aspects such as security requirements, secure architecture/design, risk assessment, threat models, security scanning, triage, vulnerability management, security design reviews, and product security validation/verification
- Assist in the administration of product security practices to product teams, technology, and security champions across the organization
- Drive Product Security efforts to resolve challenges, enable automation, and impact organization security culture
- Monitor information security best practices, standards, regulations, industry threats and risks for improvements to product security practices
- Maintain a deep understanding of current issues in the realm of information security. Maintain awareness of major industry changes and trends and assess the impact of all emerging issues on systems and practices at AspenTech Digital Grid Management
- Monitor security bulletins and alert from all AspenTech information system vendors. Evaluate vulnerability impact and formulate and execute risk mitigation plans for product security
- Member of the AspenTech Security Emergency Response Team (ASERT) providing expert analysis of security customer reported security incidents. Works with information resource owners during and after security incidents; work with product teams for analysis; recommends best practices and solutions. Where appropriate, work with product teams, technology teams, client support, and customer contacts
Required Qualifications:
- Bachelor's degree in computer science, computer engineering, electrical engineering, or related technical field
- 1-3+ years of experience in Industrial Control Systems required
- Knowledge of information security regulatory requirements for privacy, secure by design, secure by default and defense in depth
- Demonstrated ability to plan, design, develop, deploy, and maintain application security best practices
- Ability to create automations of typical vulnerability management and other security processes
- Ability to write security material for in house and customer consumption in a concise manner that is appropriate for the audience
- Maintains a broad understanding of information security including ISO27001/2, NIST 800, NERC CIP and information security frameworks and regulations
Required Skills: Product Secure Development Lifecycle, Vulnerability management, Information security frameworks
Important Skills: Industrial Control Systems, Security documentation
Nice-to-Have Skills: Automation skills, Risk assessment, Communication skills
Benefits: Paid time off, Charitable giveback day, Medical/dental/vision insurance, Retirement benefits
Benefits
Paid time off
Charitable giveback day
Medical/dental/vision insurance
Retirement benefits