Application Security Engineer

VICE Media

Multiple Locations

0 year(s)

Job Description
<p><strong>ABOUT VICE MEDIA GROUP</strong></p>
<p><a href=""><span style="font-weight: 400;">VICE Media Group</span></a><span style="font-weight: 400;"> is the world’s largest independent youth media company.  Launched in 1994, VICE has offices in 35 cities across the globe with a focus on five key businesses:, an award-winning international network of digital content; VICE STUDIOS, a feature film and television production studio; VICE, an Emmy-winning international television network; a Peabody award-winning NEWS division with the most Emmy-awarded nightly news broadcast; and VIRTUE, a global, full-service creative agency with 21 offices around the world.  VICE's content has been recognized by the Academy of Television Arts &amp; Sciences, Peabodys, Golden Globes, Sundance Film Festival, George Polk, Scripps Howard, PEN Center, Cannes Lions, Knight Foundation, American Society of Magazine Editors, LA Press Club, James Beard and Webbys, among others. </span></p>
<p><strong><span style="font-weight: 400;">VICE Media Group’s portfolio includes</span><a href=""> <span style="font-weight: 400;">Refinery29</span></a><span style="font-weight: 400;">, the leading global media and entertainment company focused on women;</span><a href=""><span style="font-weight: 400;">  </span><span style="font-weight: 400;">PULSE Films</span></a><span style="font-weight: 400;">, a London-based next-generation production studio with outposts in Los Angeles, New York, Paris and Berlin; </span><a href=""><span style="font-weight: 400;"> </span><span style="font-weight: 400;">i-D</span></a><span style="font-weight: 400;">, a global digital and bimonthly magazine defining fashion and contemporary culture; and</span><a href=""> <span style="font-weight: 400;">Garage</span></a><span style="font-weight: 400;">, a digital platform and biannual publication converging the worlds of art and design.</span></strong></p>
<p><strong>Application Security Engineer</strong></p>
<p><span style="font-weight: 400;">VICE Media is seeking an application security engineer to join our security team. At it's core you'll be responsible for working alongside the engineering teams to develop and implement security mechanisms as well as break or circumvent them. Additional responsibilities include reducing attack surface, triaging vulnerabilities, and assisting the engineering team in developing and deploying a secure product.</span></p>
<p><span style="font-weight: 400;">This is a technical position, where the candidate will be expected to understand the intricacies of browsers, the protocols used by them, and how this relates to developing a secure product. Knowing the current best practices is a start, but being ahead of the curve in terms of research and techniques is also valued. You'll need to be able to turn theory into practicality. You should be able to not only spot a SQLi, but show a developer how to exploit it.</span></p>
<p><span style="font-weight: 400;">Soft skills are valued just as highly. For example, you'll work alongside colleagues who may not know the difference between authZ and authN. You will need to clearly communicate these concepts, and effectively describe risks and available mitigations linked to security decisions.</span></p>
<p><strong>Responsibilities</strong><span style="font-weight: 400;">: </span></p>
<li>Work alongside both engineering and product teams to make more secure products, from architecture reviews to manual code review and penetration testing</li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Design and develop tools to automate or improve security practices</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Develop a solid understanding of our applications to provide first response and remediation to security incidents</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Assess third party services and integrations and the risk impact associated with their use</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Develop relationships and become a resource for information security to both technical and non-technical colleagues</span></li>
<p> <strong>Qualifications</strong><span style="font-weight: 400;">:</span></p>
<li>Prefer a minimum of 6 months experience working in a security or software engineering capacity</li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Experience in PHP and JavaScript is a must, and iOS/Android experience are bonuses</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Understanding of web applications, their protocols, and web application security and microservice architecture</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">You can write in at least one programming language</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Understanding security controls in AWS</span></li>
<li style="font-weight: 400;"><span style="font-weight: 400;">Bachelor's Degree in related field is a plus</span></li>
<p><span style="font-weight: 400;">We want to find people who believe in our goals and feel inspired enough to grow while they’re here to fill the role, rather than someone who checks the boxes but isn’t invested. We encourage you to apply and show us what you’ve got. </span></p>
<p><span style="font-weight: 400;">If you require reasonable accommodation during the application and selection process, please let us know.  We will work together to best meet your needs.</span></p>
<p><strong>Working at VICE</strong></p>
<p><span style="font-weight: 400;">VICE prioritizes the ideas and people that other media companies miss. We believe that innovation is a direct result of diverse, inclusive cultures so we don’t just “tolerate” differences, we celebrate it and see it as essential to our staff, culture, and business. To learn more read the</span><a href=""> <strong>VICE Guide to VICE</strong></a></p>
<p><span style="font-weight: 400;"><strong>Agencies: </strong>VICE Media Group is not partnering with agencies nor accepts unsolicited resumes and will not be responsible for any fees or expenses related to such unsolicited resumes