Company Overview
10Pearls is a global, purpose-driven AI-Native digital engineering partner helping businesses re-imagine, digitalize, and accelerate. As an end-to-end digital technology partner, 10Pearls helps businesses create future-proof, transformative digital products that leverage emerging technologies. 10Pearls' clients include Global 2000 enterprises, high growth mid-size businesses, and some of the most exciting start-ups from industries like healthcare, fintech, energy, education, real estate, retail, and hi-tech. Headquartered in the Washington DC metro area, 10Pearls has product engineering and software development centers in North America, Latin America, Europe, and South Asia. To learn more, visit https://10pearls.com.
Role Overview
We are hiring for Senior Software Security Engineer at 10Pearls, the person will bring a strong background in software development, security and operations. This role supports the Digital Product Management team in embedding security requirements and best practices into new Digital Products and Services under the guidance of the Lead Software Security Engineer. They will work closely with Digital Product Management and IT Security to ensure the right security controls across the product lifecycle, using the established tooling and process to manage these controls.
Responsibilities
Collaborate with software development teams to integrate security into the SDLC, ensuring products are built securely.
Champion a DevSecOps mindset across squads assign to work closely with the various roles within these squads to ensure a security-first approach is taken while minimising impact to the end users experience.
Implement and manage security controls, tools and processes to secure applications and infrastructure.
Monitor and respond to security incidents and threats in a timely manner.
Work with the Lead Security Engineer to continually automate and shit left security testing and deployment processes to enable rapid, secure software delivery.
Update and maintain concise security documentation and training materials for engineering teams.
Work with the lead Security Engineer to ensure the selected application security tools are in grated within existing development processes and CI/CD pipelines.
Assist with the planning and execution of application penetration tests; track and support remediation.
Act as a subject-matter expert to squads on application security patterns and reviews.
Define pragmatic security non-functional requirements (NFRs) with product teams and verify they’re met.
Contribute to reporting on compliance with security standards and control effectiveness.
CI/CD and monitoring requirements as described in the Digital Product Management Target Operating Model.
Requirements
Strong 5+ years of experience in software development and application security, including secure design review and code-level mitigation.
Proficiency in scripting and configuration languages such as PowerShell, YAML and JSON.
Hands-on experience with vulnerability management and remediation, including responses to pen test findings and security assessments.
Experience conducting risk assessments and threat modelling for software systems; ability to advise engineering teams.
Solid understanding of Agile and DevSecOps practices.
Knowledge of security standards and secure development principles (e.g., NCSC Secure Development & Deployment Guidance, OWASP, NIST SSDF 800-218, Microsoft Azure secure development best practices, ISO 27001).
Experience with Azure cloud infrastructure, particularly Azure PaaS services; familiarity with Azure DevOps for CI/CD and backlog management.
Strong analytical and problem-solving skills, with excellent communication and interpersonal abilities.
Experience working with Security Operations Center (SOC) tools, including SIEM, Splunk, Wazuh, and Wiz.
Hands-on experience with SAST, DAST, and SCA tools.
Strong understanding of and experience identifying vulnerabilities related to the OWASP Top 10 and CWE Top 25.
Experience performing API security testing, including REST and SOAP APIs.
Familiarity with penetration testing tools such as Burp Suite, Qualys, Metasploit, Nmap, Maltego, Sonarqube, wireshark, invicti etc.

