At Nielsen, we are passionate about our work to power a better media future for all people by providing powerful insights that drive client decisions and deliver extraordinary results. Our talented, global workforce is dedicated to capturing audience engagement with content - wherever and whenever it’s consumed. Together, we are proudly rooted in our deep legacy as we stand at the forefront of the media revolution. When you join Nielsen, you will join a dynamic team committed to excellence, perseverance, and the ambition to make an impact together. We champion you, because when you succeed, we do too. We enable your best to power our future. ABOUT THIS JOB: Nielsen, the leading company in advertising measurement and outcomes, is searching for an exceptional candidate to support assigned product lines as a Sr. Product Security Leader. As Nielsen constantly innovates to maintain its leadership in an ever-evolving marketplace, its Sr. Product Security Leader will ensure that Nielsen's platforms and applications are built securely. The Product Security Leader (PSL) facilitates secure software development and cloud security through strong integration and "shifting left" of best security practices in the DevSecOps lifecycle. This role will identify component and system level technical risks and evaluate critical failure points, determine technical security controls to mitigate risks, and work with cross functional teams to implement features according to product road maps. A strong candidate for this role will need to maintain a deep understanding of evolving business needs, build a culture of security in software engineering, and partner with DevOps teams to productize scalable security controls.
RESPONSIBILITIES:
The Sr. Product Security Leader will execute Nielsen’s security strategy for our go-to-market products and platforms. In joint collaboration with Product Leadership, DevOps, Engineering, and Data Science teams, the PSL is accountable for building security into assigned product lines including.
Identification and management of product security risks in the Nielsen product portfolio.
Working with the devops and systems teams to identify the right security architecture for implementing new solutions, products and modules.
Development, implementation, and maintenance of a product security strategy for key portions of the Nielsen product portfolio including.
Implementation of software security controls including static and dynamic security analysis measures throughout the software development lifecycle.
Partnership with the Security Operations Center (SOC) to establish visibility, logging, and monitoring capabilities.
Defining scalable Cloud Security architectural patterns and templates.
Enhancing Cloud Security posture through tooling, automation, and other means.
Developing Cyber risk profiles for each Nielsen product in the portfolio that include risk mitigation strategies.
Ensuring that product teams are effectively and actively managing vulnerabilities throughout the technology stack.
Providing expert cybersecurity consulting to internal Nielsen teams.
Build “security as code” that prevents and automates away common cloud misconfigurations based upon insights from Cloud Posture Management tools.
Build “Known Secure” reusable components (such as common authentication, for example) that enable engineering teams to quickly bring products to markets efficiently.
Maintain an open, collaborative, and consultative culture supported by outreach and education.
Earn trust for not only from internal organizations, but from clients and partners as it pertains to Nielsen’s cybersecurity practices and application security.
Partner with teams early and proactively.
Share knowledge and actively bridge relationships into other verticals in the Cybersecurity organization.
QUALIFICATIONS:
BS in a technical discipline with 7-10 years of experience or equivalent experience without a degree.
Experience with SAST, DAST, SCA and penetration testing tools.
In-depth experience identifying and protecting against web application and web service security vulnerabilities including those found in the OWASP Top 10, IoT Top 10, and CWE Top 25.
Meaningful experience in multiple programming languages.
Understanding of application and product architectures, programming languages, web application stacks, and SDLC pipelines.
Excellent written and verbal communication skills, with the ability to communicate security objectives and concepts to engineering and business teams.
Strong interpersonal skills; capable of understanding business needs and translating them into architectural standards/diagrams; able to translate complex data and architectural concepts and principles into easily-understanding information by LOBs; ability to design and deliver architectural presentations to IT, senior leadership, and business partners.
Must have proven experience communicating with, and influencing senior business and technology leaders.