FICO
analytics software
ProductSecurityTestingEngineer
Neural analysis suggests this role is
optimal for Senior candidates.
“Product Security Testing Engineer at FICO. Skills: Product Security Testing, Penetration Testing, Security Automation, AWS Infrastructure, Cybersecurity Principles, Secure Coding, DAST, API Security. Collaborate with engineers, consultants, and leadership to identify security risks and recommend mitigations within the Secure Development Lifecycle (SDLC). Perform activities such as secure code reviews, security testing, and vulnerability triage across various applications”
What You'll Achieve.
Ensure that our technical growth remains aligned with our risk appetite and strategy in a data-driven analytics environment; Improve the overall security posture of applications/infrastructure
Industry & Context.
analytical and problem-solving skills; keen attention to detail
What They're Looking For.
Must Have
Bachelor's degree in Computer Science, Cybersecurity, or a related field, Proven experience of at least 5+ years in product security, pen testing and security automation, understanding of AWS infrastructure and cloud security principles, In-depth knowledge of cybersecurity principles, methodologies, frameworks and best practices. (OSI, NIST, OWASP, SANS, PCI etc), Knowledge of secure coding principles and experience with code review processes and tools, Experience with Pen testing - WebApp, APIs, infrastructure as a code scan reviews and dynamic application security testing (DAST) methodologies and tools, analytical and problem-solving skills with a keen attention to detail, written and oral communication skills with the ability to convey complex security concepts to non-technical stakeholders, organizational and interpersonal skills
Nice to Have
Relevant cyber security certifications (e. g. , CEH, CCSP, CISSP, OSCP etc), Knowledge and experience in CI/CD, shift left security and exposure to testing analytical models, AI/ML security testing will be a plus
What You'll Do.
Collaborate with engineers
and leadership to identify security risks and recommend mitigations within the Secure Development Lifecycle (SDLC)
Perform activities such as secure code reviews
and vulnerability triage across various applications
Develop understanding of business functionality and apply testing methodology as appropriate to technologies and risks
draw conclusions from results
and develop targeted exploit examples
Document root cause and risk analysis of findings
Develop and test effective functional security testing strategies for newerging product security requirements
Suggest improvements to existing processes/tooling; ideate and implement automation where possible
Take ownership of the functionality
and continuous improvement of DAST and API security tools
How You'll Work.
Team & Collaboration
Collaborate with engineers, consultants, and leadership; Regularly interact with internal and external customers on security-related projects and operational tasks; Champion product security testing process and be an advocate for secure development practices, fostering a culture of collaboration and continuous improvement across engineering and product teams; Collaborate with other teams to improve the overall security posture of applications/infrastructure
Communication Scope
written communication skills; oral communication skills; ability to convey complex security concepts to non-technical stakeholders
Full Job Description
**FICO (NYSE: FICO)** is a leading global analytics software company, helping businesses in 100+ countries make better decisions. Join our world-class team today and fulfill your career potential! **The Opportunity** "_You will act as a partner between FICO internal security standards and our expanding global supply chain. In this high-impact role, you will lead the charge in supporting multiple audits across both our internal IT landscape and third parties. You will act as a trusted advisor to FICO senior leadership, ensuring that our technical growth remains aligned with our risk appetite and strategy in a data-driven analytics environment_ "\- Cyber Security, Director **What You 'll Contribute ** * Collaborate with engineers, consultants, and leadership to identify security risks and recommend mitigations within the Secure Development Lifecycle (SDLC). * Perform activities such as secure code reviews, security testing, and vulnerability triage across various applications. * Regularly interact with internal and external customers on security-related projects and operational tasks. * Develop understanding of business functionality and apply testing methodology as appropriate to technologies and risks. * Analyse test results, draw conclusions from results, and develop targeted exploit examples. * Clearly and professionally document root cause and risk analysis of findings. * Champion product security testing process and be an advocate for secure development practices, fostering a culture of collaboration and continuous improvement across engineering and product teams. * Collaborate with other teams to improve the overall security posture of applications/infrastructure. * Stay current on security best practices, vulnerabilities, and attacker tactics, techniques, and procedures. * Develop and test effective functional security testing strategies for new/emerging product security requirements. * Suggest improvements to existing processes/tooling; ideate and implement a
Applying for this Product Security Testing Engineer role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Workday
- Workday has a multi-step form — save your progress after every section.
- "Apply With LinkedIn" can fail or lose data; manual entry is more reliable.
- Watch for the "Submit for Review" final step — hitting "Save" alone does not submit.
- Job requisition numbers are useful when following up with HR by email.
ANONYMOUS · UNFILTERED
What do employees actually say about FICO?
Real rants from real employees. Read before you apply.