Lead Product Security Engineer

We believe work is not a place, but rather a thing you do. Our technology revolves around this core philosophy. We are relentlessly committed to helping people work and play from anywhere, on any device. Innovation, creativity and a passion for ever-improving performance drive our company and our people forward. We empower the original mobile device:  YOU!

What we’re looking for:

Does the opportunity to work on product security across the broad portfolio of Citrix products and cloud services for 100 million users excite you?

You’ll be part of a team that ensures our products remain secure and free from vulnerabilities that might affect our customers. Alongside highly experienced security engineering experts at our Cambridge site you’ll play a key role in a range of security activities including architectural and design reviews, secure code reviews, security test automation and penetration testing.

If you have experience in one or more of these areas then we would love you to join our team!

The Cambridge team works closely with Product Security team members across the world. Together we cover the entire portfolio of Citrix products and services. This includes:

  • Web applications
  • Mobile applications
  • Windows/Mac/Linux software which integrates deeply into the operating system
  • VPN and network devices
  • Virtualization and hypervisor
  • Cloud services, using the latest technologies from providers such as Microsoft Azure and Amazon Web Services.

As a security engineer at Citrix you will get wide exposure to groundbreaking and multifaceted technologies, working across the entire software development lifecycle from supporting agile development including systems design and architecture, through to penetration testing and finding vulnerabilities in live systems.

What you will be doing as Security Engineer at Citrix:

  • Architectural and design review using techniques such as threat modelling to identify risks and put in place remediation activities during the early design stages.
  • Secure code review of diverse platforms in a wide variety of programming languages and technologies such as .NET, C, C++, Java, Javascript, and Python.
  • Security automation such as fuzzing, dynamic and static analysis.
  • Penetration testing of Citrix cloud services and Enterprise software solutions.
  • Provide security training and advice to engineering teams on all aspects of security, working with them to review security fixes.

Experience and Qualifications:

We’d like you to have a background in: Penetration testing, secure code review, security automation, cryptography, and architectural design review.

A good knowledge of common software security vulnerabilities and experience of finding them in at least one of the following: Web applications, operating systems, mobile apps, networking, virtualization and cloud.

We believe you’ll also have the team and person skills to be able to work and collaborate effectively across the organization including developers, architects, product managers and engineering leadership.

Qualifications (Knowledge, Skills, Abilities)

  • Specialist in at least 3 of these areas in security – System, Web, Network, Mobile, Cloud, Windows, Cryptography
  • Capable of writing exploits for identified vulnerabilities in the area of expertise.
  • Proven understanding of most common software vulnerabilities and standard secure coding practices.
  • Excellent capabilities to identify security vulnerabilities and root cause analysis.
  • Proficiency in a programming language(s) (e.g. C, C++, Python)
  • Proficiency in System Internals (Windows or Unix)
  • Demonstrated understanding of Computer Science fundamentals (OS, Networks).

What you’re looking for:

Our technology is built on the idea that everyone should be able to work from anywhere, at any time, and on any device. It’s a simple philosophy that guides everything we do — including how we work.  If you’re an engineer, we’ll give you plenty of ways to test your skills on cutting edge technology. We want employees to do what they do best, every day.

Be bold. Take risks. Imagine a better way to work. If this sounds like you then we’d love to talk.

Functional Area:

Security Engineering

Share this job