
Security Engineer
Posted Jul 15

Posted Jul 15
This is a fully remote position, open to applicants in United States.
• Design, implement, and maintain security protocols and practices throughout the organization.
• Collaborate closely with Engineering, DevOps, IT, Compliance, and the broader Information Security team to identify risks and enhance the security posture.
• Lead application security efforts, including architecture reviews, threat modeling, code reviews, and coordination of penetration testing.
• Integrate security measures and testing into the Software Development Life Cycle (SDLC) and Continuous Integration/Continuous Deployment (CI/CD) pipelines.
• Work alongside development teams to address vulnerabilities and promote secure coding practices.
• Advocate for secure design principles across web, mobile, API, and cloud-native applications.
• Assist in the implementation and operation of security testing tools such as SAST, DAST, SCA, and secrets detection.
• Conduct and facilitate threat modeling sessions to identify potential attack vectors and prioritize associated risks.
• Perform risk assessments and provide actionable recommendations to mitigate application-level security risks.
• Clearly communicate risk findings, balancing technical details with business implications.
• Design, implement, and maintain security controls across cloud environments, infrastructure, applications, and enterprise systems.
• Evaluate and implement security technologies that enhance the organization's security posture.
• Support identity and access management initiatives, including authentication, authorization, and privileged access controls.
• Assess cloud environments for security vulnerabilities and recommend remediation strategies.
• Assist with security investigations, incident response efforts, and post-incident reviews.
• Bachelor’s degree or equivalent practical experience.
• 5-8 years of experience in cybersecurity, information security, cloud security, application security, infrastructure engineering, or related technical fields.
• Strong understanding of security principles across applications, cloud platforms, infrastructure, networks, and enterprise systems.
• Significant experience conducting security assessments and risk evaluations across applications, cloud platforms, and infrastructure.
• Familiarity with security frameworks and standards such as NIST CSF, CIS Controls, OWASP, ISO 27001, and HIPAA.
• Experience with vulnerability management and remediation processes.
• Understanding of security monitoring, incident response, and threat detection concepts.
• Experience working within AWS and Azure environments.
• Strong knowledge of authentication, authorization, encryption, and identity management principles.
• Excellent communication and stakeholder management abilities.
• Extensive application security experience, including threat modeling, secure code reviews, penetration testing coordination, and secure SDLC practices.
• Various health and medical coverage options.
• Dental and vision coverage.
• Disability and life insurance coverage.
• Medical waiver allowance.
• Remote-first work environment.
• Flexible paid time off, including Summer Fridays.
• Employer-matched 401k plan.
• Monthly phone stipend.
• First Stop Health membership benefit providing virtual care solutions.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.