Search jobs > New York, NY > Application security

Security Software Engineer, Associate - Application & Cloud Security

The Blackstone Group LP
New York, NY
$95K-$160K a year
Full-time

Blackstone is the world's largest alternative asset manager. We seek to create positive economic impact and long-term value for our investors, the companies we invest in, and the communities in which we work.

We do this by using extraordinary people and flexible capital to help companies solve problems. Our $1 trillion in assets under management include investment vehicles focused on private equity, real estate, public debt and equity, infrastructure, life sciences, growth equity, opportunistic, non-investment grade credit, real assets and secondary funds, all on a global basis.

Further information is available at www.blackstone.com. Follow redacted on LinkedIn, Twitter, and Instagram.

Blackstone Technology Innovations Profile :

Blackstone Technology and Innovations (BXTI) is the technology team at the core of each of Blackstone's businesses and new growth initiatives.

Serving both internal and external clients, we work to build the next generation of systems that manage risk, create efficiency, and improve transparency within the firm and across our broad community of investors and portfolio companies.

BXTI is nimble and entrepreneurial - our open, iterative design processes and rapid pace of development mean that everyone on the team has the opportunity to make an impact from day one.

We are problem solvers who can take projects from idea to implementation. We believe in active mentoring and developing excellence.

We collaborate to find the best answers for our customers and for Blackstone. We are critical to the firm maintaining its competitive edge.

Your Role :

Blackstone's Application & Cloud Security (AppSec) Team is responsible for empowering 500+ Developers to set and meet security goals by identifying and managing software risks while balancing security with efficiency.

You will join an ambitious and talented team of software and security engineers that are responsible for evolving how Blackstone "does security" as it continues to move to modern and next-generation architectures.

The AppSec team partners with Developers to build secure services, and with Engineers to build security into foundational platforms that developers build on.

Together, we also empower members of the broader Cybersecurity team to take on their responsibilities within these new patterns.

Responsibilities :

  • Build and own a distributed systems architecture used to scan code (SAST) and applications (DAST).
  • Understand and work towards a balanced approach for enabling Developers to reliably identify and fix security flaws while they actively Develop.
  • Communicate software vulnerabilities and mitigation options to stakeholders that balance business agility with security.
  • Partner with Developer teams to meet security objectives through training and integrating vendors or build your own solutions into software development processes.
  • Establish policies & standards to guide Developers to meet security requirements.

Qualifications :

  • 3+ years of experience in at least one software language, ideally Python but others are acceptable.
  • Experience implementing Application Security tooling such as static analysis (SAST, dynamic analysis (DAST), software component analysis tools (SCA), and / or web application firewalls (WAF)
  • Ability to perform secure code reviews and white box application penetration tests to find complicated business logic flaws.
  • Knowledge of software, cloud infrastructure, and containerized systems hardening standards.
  • Experience with CI / CD tools and concepts to embed security into DevOps pipelines (DevSecOps).
  • Experience with AWS and essentials services such as IAM, CloudTrail, EC2, S3, DynamoDB, Lambda, Config and GuardDuty
  • Has experience managing their work using agile methodologies including sprints and story estimation.
  • Knowledge of TCP / IP, HTTP, RESTful APIs and experience securing service-oriented, asynchronous, and distributed application architectures

The duties and responsibilities described here are not exhaustive and additional assignments, duties, or responsibilities may be required of this position.

Assignments, duties, and responsibilities may be changed at any time, with or without notice, by Blackstone in its sole discretion.

Expected annual base salary range :

$95,000 - $160,000

Actual base salary within that range will be determined by several components including but not limited to the individual's experience, skills, qualifications and job location.

For roles located outside of the US, please disregard the posted salary bands as these roles will follow a separate compensation process based on local market comparables.

Additional compensation : Base salary does not include other forms of compensation or benefits offered in connection with the advertised role.

Blackstone is committed to providing equal employment opportunities to all employees and applicants for employment without regard to race, color, creed, religion, sex, pregnancy, national origin, ancestry, citizenship status, age, marital or partnership status, sexual orientation, gender identity or expression, disability, genetic predisposition, veteran or military status, status as a victim of domestic violence, a sex offense or stalking, or any other class or status in accordance with applicable federal, state and local laws.

This policy applies to all terms and conditions of employment, including but not limited to hiring, placement, promotion, termination, transfer, leave of absence, compensation, and training.

All Blackstone employees, including but not limited to recruiting personnel and hiring managers, are required to abide by this policy.

If you need a reasonable accommodation to complete your application, please email Human Resources at HR-Recruiting-Americas redacted

Depending on the position, you may be required to obtain certain securities licenses if you are in a client facing role and / or if you are engaged in the following :

  • Attending client meetings where you are discussing Blackstone products and / or and client questions;
  • Marketing Blackstone funds to new or existing clients;
  • Supervising or training securities licensed employees;
  • Structuring or creating Blackstone funds / products; and
  • Advising on marketing plans prepared by a sales team or developing and / or contributing information for marketing materials.

Note : The above list is not the exhaustive list of activities requiring securities licenses and there may be roles that require review on a case-by-case basis.

Please speak with your Blackstone Recruiting contact with any questions.

To submit your application please complete the form below. Fields marked with a red asterisk

must be completed to be considered for employment (although some can be answered "prefer not to say"). Failure to provide this information may compromise the follow-up of your application.

When you have finished click Submit at the bottom of this form.

1 day ago
Related jobs
Promoted
VirtualVocations
The Bronx, New York

A company is looking for a Senior Cloud Administrator/Security Engineer. ...

Blackstone
New York, New York

Blackstone’s Application & Cloud Security (AppSec) Team is responsible for empowering 500+ Developers to set and meet security goals by identifying and managing software risks while balancing security with efficiency. You will join an ambitious and talented team of software and security engineer...

Promoted
Prosum
New York, New York

The Senior Security Engineer will work closely with the InfoSec team and the Enterprise Architecture and Service Delivery (EA&SD) team and contribute to enhancing the organization's internal and Cloud security framework. Implement and configure security systems under the CISO's guidance while suppor...

Kohler Co.
New York, New York

Software Engineer/Architect, as we build a best-in-class global multi-disciplinary team across artificial intelligence, machine learning, design, advanced software and hardware engineering, strategy, venture investments, sales, marketing, and partnerships. Software Engineer Security - Kohler Venture...

MMC Group
New York, New York

Job Description: The IT Security Operations Engineer will be part of Infrastructure Security group in Global Security team located in Greater New york. Job Requirements: -At least 6 years of technical experience in an IT related field-Knowledge of IT Security principles, techniques and technologies-...

NYC Health + Hospitals
New York, New York

The security engineer is expected to contribute to the corporate security strategy with security leadership and other senior security staffers and technologists. Recipients of the engineer’s implementations and management include IT infrastructure, application development, security operations, secur...

Stott and May
New York, New York

As an Operational Technology (OT) Security Engineer, you will be engaging directly with enterprise and regional OT operators and infrastructure resources to support critical infrastructure operations. Integrate cybersecurity requirements within production engineering and operational work processes, ...

Figma
New York, New York

Good understanding of at least two of Linux/Unix/Mac based systems security, AWS security, Cloud SaaS Security, and web application security. As a Security Engineer, you will help identify and drive impactful projects to improve the security of Figma's product, platform, and our IT systems. You will...

Equinix
New York, New York

DoD Military Skillbridge - Data Center Facility Engineer (HVAC, Mechanical, Electrician, Security Systems). Digital leaders harness Equinix's trusted platform to bring together and interconnect foundational infrastructure at software speed. Equinix is the world’s digital infrastructure company, oper...

Intelliswift Software Inc
New York, New York

Cloud Infrastructure Engineering Experience with AWS. Working knowledge of implementing cloud identity and access management solutions to enforce security guidelines. Engage with architects, developers, and technical support teams to achieve success in deployment of Cloud application services within...