Summary
✨ AI‑Generated
Join a security engineering team protecting digital assets and embedding security throughout the software development lifecycle. You will serve as a key security partner for engineering teams, conduct manual and tool-assisted code reviews, contribute to threat modeling and secure architecture, and help triage and remediate vulnerabilities identified by SAST and DAST tools. The role is designed to provide hands-on growth with guidance from experienced security engineers.
Highlights
Opportunity to grow under senior security engineers while gaining hands-on experience across product security, secure architecture, vulnerability management, and DevSecOps. The role provides broad collaboration with engineering teams and early involvement in the software development lifecycle.
Description
Job Purpose
The Security Engineer assists in implementing and maintaining security measures to protect the organization’s digital assets.
This role requires foundational knowledge of cybersecurity principles and the ability to learn and grow under the guidance of senior engineers.
Key Responsibilities
Act as the single point of contact between the security team and product/engineering teams for all product security matters.Perform security code reviews (manual and tool-assisted) across codebases to identify vulnerabilities, insecure patterns, and logic flaws before release.Review and contribute to security architecture for new and existing products, including threat modeling, secure design patterns, and risk assessments.Partner with engineering teams early in the SDLC to embed security requirements into design, development, and deployment stages (Secure SDLC / DevSecOps practices).Triage, validate, and help remediate vulnerabilities identified through code review, SAST/DAST tools, penetration tests, and bug bounty reports.Define and maintain secure coding standards, guidelines, and checklists tailored to the technology stacks in use.Support integration of security tooling into CI/CD pipelines (SAST, dependency/SCA scanning, secrets detection, container scanning).Provide security guidance on API design, authentication/authorization models, data protection, and third-party integrations.Track and report on product security posture, open findings, and remediation timelines to management.Stay current on emerging threats, vulnerability classes, and industry best practices (OWASP, CWE/SANS Top 25, etc.) relevant to the product portfolio.
Required Qualifications
Proven experience in security code review — able to read and analyze code (not just run automated scanners) to identify vulnerabilities such as injection flaws, broken authentication/authorization, insecure deserialization, business logic issues, etc.Solid understanding of security architecture principles — threat modeling, secure design patterns, defense-in-depth, zero trust concepts, and secure API/data flow design.Familiarity with the OWASP Top 10, CWE/SANS Top 25, and common vulnerability classes across web, API, mobile, and cloud-native applications.Working knowledge of SAST/DAST/SCA tools (e.g., Semgrep, SonarQube, Checkmarx, Snyk, or similar) and how to integrate them into CI/CD pipelines.Ability to communicate security findings clearly to both technical and non-technical stakeholders, and to build collaborative relationships with development teams.
Preferred Qualifications
Prior software development experience (e.g., as a developer or in a hybrid dev/security role) — hands-on experience writing production code in one or more languages (e.g., JavaScript/TypeScript, Python, Java, Go, .NET) is a strong plus.Experience with cloud platforms (AWS, Azure, or GCP) and container/orchestration security (Docker, Kubernetes) and on prem deployments alsoFamiliarity with DevSecOps practices and pipeline security (CI/CD security gates, IaC scanning).Relevant certifications such as OSWE or similar are a plus but not mandatory.Experience conducting or coordinating penetration tests and working with external security assessors.