Senior Security Engineer

Stravexa — United States · Posted ~3 hours ago

Senior Contract

Skills

application security product security threat modeling vulnerability assessment CVE CWE OWASP Top 10 secure coding source code review programming C++ Go Java Python OWASP

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A senior security engineering position focused on application protection, vulnerability analysis, and secure software development practices. The role involves threat modeling, validating security issues, building security tools, and partnering with development teams to resolve risks.

Highlights

A security engineering role focused on improving software security through threat analysis, vulnerability management, automation, and collaboration with engineering teams. The position offers challenging security projects and technical impact.

Description

Job Title: Security Engineer Duration: 12+ Months Contract with Possible Extension Project Details We are looking for Senior Security Engineers to support a security engineering project focused on bridging automated security scanning/remediation systems with product engineering teams. The team will be responsible for threat modeling, vulnerability triage, exploitability validation, automated patch QA, and driving security issues through production closure. Required Skills Strong hands-on experience in Application/Product Security Engineering. Experience with Threat Modeling, including trust boundaries, attack surfaces, data flows, STRIDE/PASTA. Strong knowledge of CWE, CVE, OWASP Top 10, vulnerability severity, and remediation SLAs. Ability to reproduce vulnerabilities, build PoCs, and create test harnesses. Strong programming skills in at least 2 of: C++, Go, Java, Python. Strong debugging and source-code review experience. Knowledge of secure coding practices, input validation, boundary checking, and safe memory access. Experience validating automated/AI-generated security patches, including code-diff review and regression testing. Ability to work directly with product engineering teams and drive vulnerabilities through verified resolution. Nice to Have SAST/DAST and automated security scanning experience. Fuzz testing and differential testing. Experience with distributed/microservice architectures. Experience with AI/agentic code-generation or automated remediation tools. Prompt tuning/debugging of automated coding agents.