Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
Rivian manufactures emissions-free Electric Adventure Vehicles and focuses on sustainable transportation solutions. The company challenges conventional industry standards by reframing complex problems and developing innovative, secure-by-design technologies.
задачи
Review source code and application architectures to identify and communicate security vulnerabilities to development teams;
Drive the adoption of Software Bill of Materials (SBOM) to ensure software supply chain visibility, license compliance, and vulnerability tracking;
Implement and manage automated Software Composition Analysis (SCA) to identify and remediate vulnerabilities in open-source and third-party libraries;
Develop and support automated security tooling and agentic security workflows within CI/CD pipelines;
Work closely with the penetration testing team to identify and implement remediations for security vulnerabilities;
Support the implementation of security configurations and countermeasures based on emerging threats and industry trends.
требования
4+ Years of application security experience;
Proficiency with GraphQL, AWS, React, Java, Node.js, Python, and containerization technologies like Docker and Kubernetes;
Hands-on experience with reviewing and remediating common SAST and SCA vulnerabilities;
Strong hands-on coding or scripting skills for building security utilities and automation;
Strong problem-solving and decision-making capabilities;
Nice to have: Experience in the automotive, manufacturing, or technology industries, experience with cloud native and Kubernetes hosted applications, experience with Gitlab CI/CD or other DevOps technologies, experience identifying and mitigating AI-specific vulnerabilities.