Product Security Architect/Lead
With electric vehicles expected to be nearly 30% of new vehicle sales by 2025 and more than 50% by 2040, electric mobility is becoming a reality. ChargePoint (NYSE: CHPT) is at the center of this revolution, powering one of the world’s leading EV charging networks and a comprehensive set of hardware, software and mobile solutions for every charging need across North America and Europe. We bring together drivers, businesses, automakers, policymakers, utilities and other stakeholders to make e-mobility a global reality.
Since our founding in 2007, ChargePoint has focused solely on making the transition to electric easy for businesses, fleets and drivers. ChargePoint offers a once-in-a-lifetime opportunity to create an all-electric future and a trillion-dollar market.
At ChargePoint, we foster a positive and productive work environment by committing to live our values of Be Courageous, Charge Together, Love our Customers, Operate with Openness, and Relentlessly Pursue Awesome. These values guide how we show up every day, align, and work together to build a brighter future for all of us.
Join the team that is building the EV charging industry and make your mark on how people and goods will get everywhere they need to go, in any context, for generations to come.
Discover what it’s like to help build the fueling network of the future - check out our Engineering Blog.
Senior Director, Information Security
What You Will Be Doing
ChargePoint is looking for a Sr. Staff – Product Security engineer who will help develop our product security strategy, implement tools, architect our product security roadmap, develop process, perform threat assessment and security reviews, and work with different team leaders to implement a security by design culture as part of our product lifecycle. This role will be responsible for providing guidance, advice, oversight, and implementation of controls on product security matters.
As a Product Security engineer, you will design security controls and help validate that our services, applications, stations, and emerging technologies are designed and implemented to the highest security standards. You will be responsible for analyzing the security of applications and services, discovering, and addressing security issues, designing security automation, and decisively taking action to mitigate emerging threats throughout a full secure development life cycle (SDLC). This role will provide career growth opportunities as you gain new security skills in the course of your work. You have an opportunity to experiment, learn, build tools, and work with teams building new technology and services at massive scale in the EV charging space.
What You Will Bring to ChargePoint
- Experience building relationships with key stakeholders across the business to understand their current and planned product activities (application and embedded)
- Experience developing processes and policies to mitigate key product risks
- Performing security assessments, identifying, and mitigating risks through effective tools, processes, training, and guidance. Managing product risk assessments and remediation plans
- Supporting the integration of security standards, controls, policies into the SDLC
- Developing and managing a comprehensive product security training program and promoting security awareness throughout the product team agenda
- Leading internal product meetings to present key product security metrics and risks to senior leadership
- Influence decision-makers and stakeholders to achieve a consistently high security bar
- Lead security projects (including security reviews, tool development, and creation of new security practices) with end-to-end ownership
- Experience working with engineering teams to design and implement security controls
- Support for mentoring, team building and recruiting activities
- Eight (8) + years of dedicated working knowledge, and real-world experience of product security best practice across multiple functions and geographies
- Experience working with security requirements and regulations related
- Experience building, reviewing, and managing threat models / assessments
- Experience implementing security by design culture
- Experience with one or more programming languages (such as Java, C++, PHP, others) for the purpose of code review
- An understanding of networking and communication protocols (such as TCP/IP, UDP, SSL/TLS, IPSEC, HTTP, HTTPS, BGP)
- Ability to lead through influence within a secure development life cycle for multiple products and technologies, meeting customer expectations for security
- Demonstrate ability to clearly identify business and regulatory implications of analysis and findings and propose strategic solutions
- Customer and organizational data literacy on processing, usage, management
- Ability to manage multiple stakeholders, understand technology and commercial concepts quickly
- Strong relationship’s skills / ability to communicate effectively both in writing and verbally
- Ability to identify and mitigate product security risks with the ability to understand materiality of risks and prioritize / differentiate response accordingly
Remote location in U.S.
ChargePoint is committed to fair and equitable compensation practices.
The targeted US salary range for roles at this operating level is $82,500 to $225,000. This range represents base salary and does not reflect equity, benefits or variable pay where applicable. Actual base salaries are based on several factors unique to each candidate, including but not limited to skill set, experience, certifications and specific work location.
We are committed to an inclusive and diverse team. ChargePoint is an equal opportunity employer. We do not discriminate based on race, color, ethnicity, ancestry, national origin, religion, sex, gender, gender identity, gender expression, sexual orientation, age, disability, veteran status, genetic information, marital status or any legally protected status.
If there is a match between your experiences/skills and the Company needs, we will contact you directly.
ChargePoint is an equal opportunity employer.
Applicants only - Recruiting agencies do not contact.