Genesys

Principal Cloud Application Security Engineer

Genesys

Ireland, England, United Kingdom · Full Time

Be the first to apply

Experience
10+ yrs
Salary
—
Openings
1
Posted
1 day ago
Work mode
In office
Resume
Required to apply

Where you'll work

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

About the Role

Join Genesys to build AI-enhanced customer experiences that matter, supporting technology impacting over 8,000 organizations globally. As a Principal Cloud Application Security Engineer on the Genesys Cloud Product Security team, you will lead application security efforts across a complex, evolving multi-tenant SaaS platform. Your expertise will be key in managing the technical direction of a focused Application Security team, balancing hands-on vulnerability analysis, detection engineering, vulnerability triage, and cloud security responsibilities.

Key Responsibilities

  • Lead and mentor a small Application Security team, enhancing engineering judgment and security standards through active leadership.
  • Oversee the complete application security operating model, optimizing detection coverage and managing vulnerability assessment workload to prioritize exploitable risks.
  • Develop broad detection strategies including SAST, SCA, DAST, secrets scanning, mobile application security testing, and cloud security posture management, collaborating on tool management and tuning.
  • Enhance security visibility over web applications, APIs, mobile apps, cloud environments, AI features, and software supply chains to uncover systemic risks beyond individual tools.
  • Define and monitor impactful security coverage metrics reflecting both discovered issues and attack surface evaluations.
  • Evaluate exploitability across automated detection, bug bounty, penetration tests, internal reviews, and AI analyses considering potential impacts on data and platform integrity.
  • Implement consistent vulnerability triage using evidence-based procedures to distinguish true risks from false positives and accepted risks.
  • Lead high-risk security incident investigations involving cross-tenant access, authentication/authorization flaws, data exposure, and public cloud resource security.
  • Advance AI and automation tools to enhance security team efficiency in triage, report analysis, false positive identification, and gap detection.
  • Set policies on AI-assisted security decision-making, ensuring human verification where context demands it and adapting controls as technology evolves.
  • Improve vulnerability intake and tracking processes across multiple detection sources for scalability and traceability.
  • Manage the bug bounty program and coordinate customer penetration testing workflows liaising with various internal and external stakeholders.
  • Produce clear and actionable security findings and communications understandable by engineers, account teams, and customers.
  • Collaborate across security and product teams to convert recurring vulnerabilities into preventive, scalable controls.
  • Shape the long-term application security strategy by integrating detection data, vulnerability trends, and emerging threats into platform security roadmaps.

Required Qualifications

  • Over 10 years of experience in application security, product security, penetration testing, vulnerability management, or cloud security engineering with strong recent focus on web and API security.
  • Expertise in assessing exploitability of vulnerabilities including authorization/authentication weaknesses, injection attacks, SSRF, business logic flaws, sensitive data risks, and multi-tenant isolation issues.
  • Hands-on experience with security technologies such as SAST, SCA, DAST, secrets scanning, mobile app security testing, or cloud security posture management.
  • Proven track record of building or expanding security detection capabilities with balanced judgment on coverage, false positives, operational costs, and effort.
  • Demonstrated experience developing automation to boost security team effectiveness while recognizing when human oversight is vital.
  • Deep understanding of multi-tenant cloud architectures, attack vectors, trust boundaries, identity, and authorization at scale.
  • Strong expertise in cloud security, preferably AWS, including controls, identity management, attack path analysis, and infrastructure security.
  • Leadership skills evidenced by guiding small teams, mentoring engineers, spearheading complex projects, or setting technical direction.
  • Excellent verbal and written communication skills to convey vulnerability severity, exploitability, and remediation advice across diverse audiences.
  • Ability to collaborate effectively with security, engineering, DevOps, and product stakeholders maintaining accountability and productive relationships.
  • Respect for confidentiality when handling sensitive vulnerability data, customer reports, and security communications.

Preferred Qualifications

  • Strong AWS cloud security expertise or similar skills gained in Azure or GCP environments.
  • Knowledge of OWASP API Security Top 10, Web Security Testing Guide, and mobile security practices.
  • Experience with secure SDLC, CI/CD security, threat modeling, secure design, or security architecture.
  • Background in creating or managing AI/LLM-driven security workflows.
  • Hands-on skills with Android/iOS security or cloud security posture management for large distributed environments.
  • Familiarity with software supply chain security including dependency risk, malicious package detection, SBOM, and build integrity.
  • Understanding of compliance frameworks such as SOC 2, PCI DSS, FedRAMP, or HIPAA impacting security controls.
  • Proficiency in programming languages like Python, TypeScript, Bash, or Go for security tooling and automation development.
  • Experience securing REST APIs, OAuth frameworks, microservices, and event-driven SaaS systems.
  • Involvement with bug bounty programs, vulnerability disclosure, and remediation processes.

Working at Genesys

  • Engage in enterprise-scale AI development supported by over 150 annual new AI features and used by thousands globally.
  • Enjoy a flexible-first workplace culture designed to empower high performance and work-life balance.
  • Access growth opportunities via mentorship, continuing education, leadership programs, and learning initiatives.
  • Benefit from paid volunteer time, special well-being programs, and globally recognized workplace standards.
  • Work for a globally certified Great Place to Work®, with a strong employee pride culture.

Additional Information

The hiring process includes multiple stages such as application review, Zoom interviews, and meetings with managers and team members, all designed to be efficient and respectful of candidates’ time. Genesys evaluates every applicant thoroughly and keeps candidates informed throughout. Accommodations are available to ensure accessibility for all applicants.

How they work

Communication Teamwork & Collaboration Leadership Integrity

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer