
Senior Product Application Security Engineer
Posted Aug 5

Posted Aug 5
This is a fully remote position, open to applicants in United States.
• Act as a proactive product security engineer for Enterprise products, collaborating with teams in cybersecurity, product management, software development, DevOps, infrastructure, systems, and program stakeholders.
• Convert policies, customer needs, threat data, and compliance requirements into actionable product security specifications and engineering advice.
• Conduct threat modeling, attack-surface evaluations, security architecture and design assessments, as well as targeted reviews of code or configurations.
• Conceptualize, integrate, and enhance automated security measures within CI/CD pipelines.
• Establish, automate, and verify secure configurations for Linux, Kubernetes, containers, databases, identity services, networking, and platform services.
• Create and validate hardened baselines utilizing DISA STIGs, SRGs, CIS Benchmarks, customer specifications, and industry best practices.
• Evaluate vulnerabilities, analyze technical risks, prioritize issues, offer remediation advice, coordinate with responsible teams, and confirm corrective measures.
• Assist with authentication, authorization, RBAC, encryption, secrets and certificate management, audit logging, service-to-service communication, and data protection mechanisms.
• Design reusable security tools, scripts, pipeline templates, configuration baselines, reporting functionalities, and secure implementation strategies.
• Develop and maintain security engineering documentation and technical evidence for NIST, CMMC, RMF, DHS, TSA, DISA, customer-specific, and international standards.
• Execute security testing and technical validation of releases and architectural or platform modifications, including targeted penetration tests when necessary.
• Present findings, remediation options, residual risks, and technical trade-offs to both technical and nontechnical stakeholders while advocating for secure development practices.
• Bachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Software Engineering, Information Systems, or a related technical field with 8+ years of relevant experience; or a master's degree with 6+ years of relevant experience.
• Additional relevant experience may be taken into account in place of a degree where applicable.
• Practical experience in product, application, software, DevSecOps, platform, or related cybersecurity engineering.
• Proven experience in embedding security throughout the software development lifecycle.
• Familiarity with threat modeling, application or API security assessments, security architecture evaluations, or secure design assessments.
• Experience integrating SAST, SCA, secret scanning, container scanning, or infrastructure-as-code analysis into CI/CD workflows.
• Background in securing Linux systems, containerized applications, or Kubernetes environments.
• Experience conducting vulnerability assessments, analyzing results, formulating remediation strategies, and communicating technical risks.
• Proficiency in developing automation using Python, Bash, PowerShell, or another relevant programming language.
• Sound understanding of OWASP application security risks and security frameworks or baselines such as NIST SP 800-53, NIST SP 800-171, CMMC, RMF, DISA STIGs, or CIS Benchmarks.
• Capability to work autonomously across various technical fields while collaborating with engineering, cybersecurity, program, and customer stakeholders.
• Excellent written and verbal communication skills, including the ability to document technical decisions and elucidate security risks and trade-offs.
• Ability to obtain and maintain the public trust or security clearance required by assigned programs.
• Current certification that meets relevant DoD 8140 or customer requirements, or the capacity to achieve the necessary certification within 6 months of employment.
• Competitive compensation
• Health and Wellness programs
• Income Protection
• Paid Leave
• Retirement
Avnet
Teradyne
Intetics
New Charter Technologies
Get handpicked remote jobs straight to your inbox weekly.