To learn more about how Dell Technologies is supporting our communities, customers, partners and team members, please visit our COVID-19 response site.
Secure Development Lifecycle Engineer
Primary Location: Hopkinton, Massachusetts
Annapolis Junction, Maryland, United States; Apex, North Carolina, United States; Atlanta, Georgia, United States; Austin, Texas, United States; Bethesda, Maryland, United States; Cambridge, Massachusetts, United States; Charlotte, North Carolina, United States; Chesterbrook, Pennsylvania, United States; Chicago, Illinois, United States; Columbia, Maryland, United States; Columbia, South Carolina, United States; Columbus, Ohio, United States; Conshohocken, Pennsylvania, United States; Coral Gables, Florida, United States; Dallas, Texas, United States; Durham, North Carolina, United States; Eden Prairie, Minnesota, United States; El Paso, Texas, United States; Farmington Hills, Michigan, United States; Franklin, Massachusetts, United States; Houston, Texas, United States; Independence, Ohio, United States; Jacksonville, Florida, United States; Lisle, Illinois, United States; Louisville, Colorado, United States; Louisville, Kentucky, United States; McLean, Virginia, United States; Miami, Florida, United States; Minneapolis, Minnesota, United States; Nashua, New Hampshire, United States; Needham, Massachusetts, United States; Pittsburgh, Pennsylvania, United States; Plymouth, Minnesota, United States; Providence, Rhode Island, United States; Remote - Arizona, United States; Remote - Florida, United States; Remote - Georgia, United States; Remote - Illinois, United States; Remote - Louisiana, United States; Remote - Massachusetts, United States; Remote - Michigan, United States; Remote - Minnesota, United States; Remote - New Hampshire, United States; Remote - North Carolina, United States; Remote - Ohio, United States; Remote - Pennsylvania, United States; Remote - Rhode Island, United States; Remote - South Carolina, United States; Remote - Texas, United States; Remote - Washington, United States; Research Triangle Park, North Carolina, United States; Reston, Virginia, United States; Richardson, Texas, United States; Richmond, Virginia, United States; Round Rock, Texas, United States; San Antonio, Texas, United States; Scottsdale, Arizona, United States; Seattle, Washington, United States; St Louis, Missouri, United States; Tampa, Florida, United States; Vienna, Virginia, United States; Washington, DC, District of Columbia, United States
Secure Development Lifecycle Engineer
Location: Remote - United States
The Dell Security & Resiliency organization (SRO) manages the security risk across all aspects of Dell’s business. We are currently experiencing incredible growth in order to meet the security needs of the world’s largest technology company. With team members located in over 15 countries, you will have an excellent opportunity to influence the security culture at Dell and further develop your career.
Dell’s Product and Application Security team builds and delivers world-class capabilities which infuses security into the development processes and instills a security culture among Dell developers. They enable Dell and our Customers to securely engage in digital transformation by providing Dell development teams the knowledge and capabilities required to ensure that the code developed and integrated in Dell products, applications and services is inherently secure throughout its lifecycle; and they promptly respond to reported vulnerabilities to keep deployed products and applications secure.
As an SDL Engineer you will play a crucial role in ensuring the security of our products and applications using industry best practices. You will join Dell’s Product and Application Security Organization as a member of our Secure Development Lifecycle (SDL) team which is responsible for a strategic program to build demonstrably resilient software across Dell’s diverse product and technology portfolio. In this role you will have the opportunity to partner with Dell engineering teams to help them secure innovative products built with a wide range of technologies. You will have the chance to apply your skills to help teams secure everything from firmware to cloud deployments.
- Act as a trusted advisor to product teams, providing practical advice on secure design, coding and testing.
- Create threat models for new and existing software. Assess potential threats and provide mitigation recommendations to product engineering teams.
- Provide subject matter expertise on creating resilience in products to current attack techniques
- Conduct security assessments on infrastructure and platforms and provide detailed assessment report to engineering teams along with the remediation steps.
- Communicate security risk in layman terms to executives and business stakeholders
- Lead secure design, coding and/or testing workshops to teach other engineers at Dell how to efficiently apply security development practices
- As required conduct research into emerging technologies and security engineering practices in order to better advise product teams
- Act as a Secure Development Lifecycle (SDL) evangelist across Dell as the subject matter expert and contribute to the broader industry security community.
- Solid understanding of BIOS, Root of Trust (RoT), Secure Boot, Trusted Platform Module, PKI, Code Signing
- Strong communication skills are a must as you need to be able to communicate to and influence both engineers and managers. As is the ability to work with diverse and global teams
- A passion and a track record for product security engineering
- A demonstrable understanding of modern infrastructure and cloud technologies
- An understanding and ability to communicate the techniques, tactics and practices of an attacker.
- Bachelor’s degree in Computer Science, Computer Engineering or related field with 8+ years relevant experience; or Master’s degree with 6+ years relevant experience; or equivalent experience
- Understanding of common security vulnerabilities as described in the OWASP Top 10 and SANS 25 as well as their remediation.
- A proven track record in secure development practices such as: threat modeling, secure design, secure coding, and the use of static and dynamic analysis tools
- An understanding of the specific challenges in securing cloud-based solutions
- Competency in secure coding in multiple languages, including at least one scripted and one compiled language
- Master's degree in Information Security or similar technical field
- Industry certifications: GIAC, CISA and/or CISSP, CSSLP
Dell Technologies is a unique family of businesses that helps organizations and individuals build their digital future and transform how they work, live and play—providing customers with the industry’s broadest and most innovative technology and services portfolio. We value our customers, winning together, innovation, results and integrity. Grow your career with a highly competitive salary, bonus programs, world-class benefits and unparalleled learning and development opportunities— all at a company that is proud to be diverse and inclusive. Learn more on how we are closing the diversity gap.
Dell is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment. All employment decisions at Dell are based on business needs, job requirements and individual qualifications, without regard to race, color, religion or belief, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV Status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past or present military service, family medical history or genetic information, family or parental status, or any other status protected by the laws or regulations in the locations where we operate. Dell will not tolerate discrimination or harassment based on any of these characteristics. Dell encourages applicants of all ages. Read the full Employment Opportunity Policy here.
LIPRIORITYJob ID: R072284