At Kensho, we hire talented people and give them the autonomy and support needed to build amazing technology and products. To do this, we look for people who insist on a bias towards action to minimize unhelpful hierarchy and process. We collaborate using our teammates' diverse perspectives to solve hard problems. Our communication with one another is open, honest and efficient. We produce a suite of AI-powered solutions that solves the challenges of the largest, most successful businesses and institutions, helping them make sense out of a world full of messy data.
As a security focused engineer at Kensho you are a thoughtful, collaborative, and seasoned technologist who will be working closely with the Infrastructure team to ensure security across a number of systems and web applications. You will help us protect network boundaries, keep systems and network devices against attacks and provide security frameworks and processes to protect confidential data like passwords and client information.
At Kensho, we believe in flexibility-first, and give our employees the opportunity to work from where they feel most productive and engaged (must be in the United States). We also value in-person collaboration, so there may be times when travel to one of our Kensho hubs (NY/DC/MA) will be required for team meetings or company events.
What You'll Do:
- Design and implement security controls and policies across Kensho and provide oversight to ensure compliance
- Analyze and recommend security practices and tools for engineering teams to incorporate into the software development lifecycle
- Knowledge of e2e application frameworks to execute security reviews and uncover vulnerabilities
- Directly interface with customer infosec teams, lawyers, external security researchers as well as internal partners to ensure that Kensho maintains a best-in-class security envelope
- Design and implement policies for third party vendor screening and dependency management
- Implement procedures to respond to and recover from security incidents
- Monitor Kensho’s networks and systems for potential intrusions and investigate anomalous behavior
- Perform static and dynamic vulnerability assessments of applications using commercial and open source tools such as Fortify, Bandit, WebInspect and OWASP Zap
What We Look For:
- Three or more years of experience as a security engineer
- Experience securing modern web applications and distributed data infrastructure in a cross-team setting
- Strong understanding of cryptography and current best practices
- Experience with penetration testing tools, techniques and methodologies and understanding of common vulnerabilities and remediation strategies
- Prior experience working with enterprise security technologies such as firewalls, IDS/IPS, AntiVirus/EDR, or Security Information and Event Management systems
- Ability to apply risk management tools and methodologies
- Experience conducting or facilitating IT security audits
- Familiarity with security models for cloud providers such as AWS, Azure and GCP
How To Really Grab Our Attention:
- Experience securing services and applications running on Kubernetes
- Experience working with Jenkins, Terraform, LinkerD, Vault, or Okta
- Participation in CTFs or bug bounty programs
- Open source project contributions showing innovation and initiative
- Hedge fund or major financial institution trading experience
- Relevant research, publications, and patents
At Kensho, we pride ourselves on providing top-of-market benefits, including:
- Medical, Dental, and Vision insurance
- 100% company paid premiums
- Unlimited Paid Time Off
- 26 weeks of 100% paid Parental Leave (paternity and maternity)
- 401(k) plan with 6% employer matching
- Generous company matching on donations to non-profit charities
- Up to $20,000 tuition assistance toward degree programs, plus up to $4,000/year for ongoing professional education such as industry conferences
- Plentiful snacks, drinks, and regularly catered lunches
- Dog-friendly office (CAM office)
- In-office gyms and showers (CAM, DC)
- Bike sharing program memberships
- Compassion leave and elder care leave
- Mentoring and additional learning opportunities
- Opportunity to expand professional network and participate in conferences and events
Kensho uses machine learning, artificial intelligence, natural language processing and data visualization techniques to solve some of the hardest analytical problems and create breakthrough financial intelligence solutions for our parent company, S&P Global.
Kensho was founded in 2013 by Harvard & MIT alums and was acquired by S&P Global in 2018. Kensho continues to operate as a startup in order to maintain our distinct, independent brand and to promote our breakthrough, innovative culture. Our team of Kenshins enjoy a dynamic and collaborative work environment that runs autonomously from S&P, while leveraging the unparalleled breadth and depth of data and resources available as part of S&P Global. As Kenshins, we pride ourselves on maintaining an innovative culture that depends on diversity and inclusion.
We are an equal opportunity employer that welcomes future Kenshins with all experiences and perspectives. Kensho is headquartered in Cambridge, MA, with offices in New York City, and Washington D.C. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, or national origin.