
Security Engineer
Posted Aug 12

Posted Aug 12
This is a fully remote position, open to applicants in United States.
• Oversee the remediation of application security vulnerabilities across various development teams.
• Manage tools for SAST, DAST, SCA, and dependency scanning.
• Triage, validate, prioritize, and coordinate the remediation of identified vulnerabilities.
• Offer guidance on OWASP Top 10 and secure coding practices.
• Integrate security scanning tools with ticketing systems and CI/CD pipelines.
• Generate metrics for AppSec, along with management reports and dashboards.
• Administer vulnerability management platforms and oversee exceptions, risk acceptances, aging, and SLA compliance.
• Develop detection rules mapped to MITRE ATT&CK, including alert triage workflows, hunting queries, and incident reports.
• Construct and maintain scripted, cloud-based automation pipelines for AI-driven security operations.
• Create and refine AI agent prompts, verdict logic, disposition rules, integrations, enrichment, and reporting workflows.
• Manage and fine-tune EDR, SIEM, and IAM platforms.
• Lead investigations and responses for Tier 2/3 security incidents.
• Assist with penetration testing, red team activities, WAF/CDN audits, and security architecture decisions.
• Draft and review security policies and procedures, along with conducting framework gap analyses.
• Analyze and integrate threat intelligence, implementing IOC blocking and detection rules.
• Engage in security design reviews, product vulnerability meetings, ISACs, customer security calls, and project security reviews.
• Serve as an escalation point for Security Analysts.
• Support the sales team by addressing security-related questionnaires.
• A Bachelor's degree in Computer Science, Information Security, Engineering, or a related technical field, or equivalent professional experience.
• 5–7 years of experience in security engineering, with expertise across multiple security domains, including application security.
• Extensive knowledge of vulnerability management platforms.
• Proficient in MITRE ATT&CK mapping for detection rules and incident response.
• Strong experience with SAST, DAST, and SCA tools.
• In-depth understanding of OWASP Top 10, injection flaws, XSS, and authentication bypasses.
• Practical experience in building cloud-based automation using serverless functions, event-driven pipelines, and secrets management.
• Experience with or keen interest in AI agent engineering and tool-integration protocols for security operations.
• Proficient in administering EDR platforms and experienced with SIEM administration.
• Familiarity with IAM platforms and concepts related to federation/SSO.
• Expertise in cloud security across AWS, Azure, or GCP.
• Understanding of WAF configuration and auditing processes.
• Proficiency in scripting and automation; Python is required, PowerShell is a plus.
• Familiarity with DevSecOps and secure CI/CD practices.
• Practical experience with AI-powered security tools, including LLM-based agents, and an understanding of prompt injection and tool/agent security risks.
• Ability to create dashboards and reports for both technical and executive audiences.
• Experience with SIEM, security automation/orchestration, vulnerability management, EDR, DLP, GRC, SAST, DAST, SCA, cloud security, threat intelligence, ticketing, and collaboration platforms.
• Strong analytical thinking and problem-solving skills.
• Exceptional communication skills for both technical and business audiences.
• Strong proficiency in Agile methodologies and the ability to integrate security into sprint planning.
• Experience collaborating with development teams on secure coding practices.
• Ability to translate technical vulnerability findings into actionable remediation strategies.
• Proficient written communication skills for security documentation, audit responses, and questionnaires.
• Capability to act as an escalation point for Security Analysts and participate in customer security calls.
• Preferred certifications and experience include CySA+, cloud security certifications, GIAC GSEC, CEH, GIAC GWEB, CompTIA PenTest+, GIAC GCTI, SIEM certification, DevSecOps, SSDLC, SOC 2, ISO 27001, security audits, vendor risk assessments, threat intelligence, coordination of penetration testing, security awareness training, LLM-based agents, and container/Kubernetes security.
• Flexible and generous Paid Time Off.
• Paid Volunteer Days.
• 401k Employer Match.
• Comprehensive Healthcare Benefits.
• Up to 12 weeks of paid maternity leave based on tenure.
• Wellness & Tuition Reimbursement.
• Flexible Work Arrangements.
• SambaSafety swag.
• Participation in SambaSafety Events.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.