
Staff Application Security Engineer – Blue Team
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in California.
• Design, implement, and sustain defensive security measures across applications, cloud platforms, data systems, and network environments.
• Develop and enforce security standards, policies, and best practices for applications and data on an enterprise-wide scale.
• Integrate security controls into SDLC processes, CI/CD pipelines, and automation frameworks for deployment.
• Lead security architecture evaluations and establish governance frameworks for security.
• Collaborate with Engineering, Infrastructure, Architecture, and Business teams to promote secure-by-design practices.
• Act as a trusted advisor and technical leader in Application Security, Cloud Security, and Secure Development.
• Monitor, detect, investigate, and respond to security events, vulnerabilities, threats, and incidents.
• Oversee vulnerability assessments, remediation planning, risk prioritization, and validation processes.
• Conduct security assessments, threat modeling, and architecture evaluations.
• Implement advanced security solutions across multi-cloud, colocation, and enterprise environments.
• Participate in an on-call rotation for 24x7 support, including off-hours, nights, weekends, and holidays.
• Lead incident response efforts including investigation, containment, eradication, recovery, and post-incident reviews.
• Develop and enhance incident response, detection, escalation, and recovery playbooks.
• Mentor and coach engineers in secure coding, security engineering, and defensive operations.
• Research emerging threats, vulnerabilities, attack methodologies, and security technologies.
• Evaluate and recommend security tools, platforms, and defensive capabilities.
• Automate security operations utilizing code and Security-as-Code principles.
• Contribute to the long-term security strategy, architecture roadmaps, technology planning, and enterprise security objectives.
• Partner with leadership to prioritize security investments and risk reduction initiatives.
• Over 7 years of experience in security engineering, application security, cloud security, or defensive security operations.
• At least 3 years of experience securing cloud platforms such as AWS, Azure, and GCP.
• Minimum of 3 years of experience with Docker, Kubernetes, Infrastructure-as-Code, and Security-as-Code practices.
• A minimum of 3 years of experience with programming or scripting languages like Python, Java, C#, JavaScript, Shell, or PowerShell.
• At least 3 years of experience in networking, identity management, authentication, authorization, and threat mitigation techniques.
• Experience in designing and operating defensive security controls in cloud-native, containerized, and distributed application settings.
• Familiarity with data protection controls and regulatory/compliance frameworks such as GDPR, CCPA, or similar regulations.
• Proven experience in designing and implementing enterprise-scale security controls and automation solutions.
• Understanding of networking, SDN, zero-trust architectures, and cloud security models.
• Experience with threat modeling, security architecture evaluations, and secure design assessments.
• Ability to develop and interpret network, sequence, application architecture, and data flow diagrams.
• Familiarity with security and compliance frameworks such as NIST, PCI DSS, HIPAA, HITRUST, ISO 27001, SOC 2, or CSA.
• Experience securing enterprise data platforms, analytics environments, and data warehouses, including Snowflake or similar technologies.
• Experience defining and implementing strategies for cyber resilience, business continuity, backup, redundancy, and recovery.
• Relevant industry certifications, including CISSP, CCSP, GSEC, GIAC, AWS Security Specialty, Azure Security Engineer Associate, or equivalent.
• A bachelor’s degree from an accredited college or university, or a comparable combination of education and relevant work experience (High School Diploma/GED plus 4 years of related experience).
• Medical coverage.
• Dental coverage.
• Vision coverage.
• Paid time off.
• Retirement savings options.
• Wellness programs.
• Additional resources supporting physical, emotional, and financial well-being.
• CVS Health bonus, commission, or short-term incentive program.
• Equity award program.
Ontrac Solutions
Nebius Group
Xcellent Technology Solutions (XTS)
S&P Global
Get handpicked remote jobs straight to your inbox weekly.