Haystack
← Back to Jobs
Technology
TS

Senior Security Engineer

Tixy Services LLCUnited States🇺🇸United StatesPosted Sep 16, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
19 hours ago
AWSEncryptionOWASPSAMLSOC 2SplunkAgileAzureBashCloudFormationGoogle CloudHIPAAJiraKubernetesPowerShellPrismaPythonTerraform

Job Description

Job Title: Security Engineer

 

  • JD: The Security Engineer designs and implements controls that protect customer applications, cloud environments, and data.

 

  • The Mid Security Engineer owns security workstreams end-to-end: threat modeling on new services, hardening cloud infrastructure, integrating security tooling into CI/CD pipelines, tuning detection, and leading remediation work with developers and platform teams. They translate security requirements into engineering work and operate as a trusted technical contributor inside delivery teams.

 

  • **Core Responsibilities**
  • - Conduct threat modeling and security design reviews on new and existing applications and services.
  •   - Mid: Owns threat models for assigned services and translates findings into actionable engineering tickets.
  • - Design and implement IAM, encryption, network, and logging controls in cloud environments (AWS, Azure, Google Cloud Platform).
  •   - Mid: Builds reusable IAM, KMS, and network security patterns in infrastructure-as-code.
  • - Integrate and tune security tooling (SAST, DAST, SCA, secret scanning, IaC scanning, CSPM) in CI/CD pipelines.
  •   - Mid: Owns tool configuration, false-positive tuning, and policy-as-code rule development.
  • - Build and tune detection content in SIEM and cloud-native security tools; participate in incident response.
  •   - Mid: Authors detection rules, writes runbooks, and leads triage on routine security incidents.
  • - Lead vulnerability management and remediation work across application, infrastructure, and container environments.
  •   - Mid: Owns the remediation backlog and partners with engineering teams on prioritization and fixes.
  • - Map controls compliance frameworks (SOC 2, HIPAA, PCI, ISO 27001, NIST) and support audit evidence collection.
  •   - Mid: Maintains control mappings and produces audit-ready evidence for assigned scope.
  • - Collaborate with developers, platform engineers, and architects to embed security into delivery practices.
  •   - Mid: Pairs with engineering teams, runs secure-coding sessions, and influences design decisions early.
  • - Use agentic AI tools (e.g., Claude, Cursor, GitHub Copilot, Coco, or similar) in real delivery work, following and the client's agentic AI operating model and usage guidelines.
  •   - Mid: Independently incorporates agentic AI tools into day-to-day delivery work, follows and client's operating model for responsible use (review, validation, disclosure where required), and can speak to where they've caught or corrected AI-introduced errors.

 

  • **Experience**
  • - Mid: 4-7 years owning security engineering work across cloud, application, and infrastructure domains
  • - Experience designing and implementing IAM, encryption, network, and logging controls in AWS, Azure, or Google Cloud Platform
  • - Experience integrating security tooling (SAST, DAST, SCA, IaC scanning, CSPM) into CI/CD pipelines
  • - Experience leading threat modeling and security design reviews
  • - Experience contributing to incident response, detection engineering, and vulnerability management
  • - Hands-on experience using agentic AI tools in real delivery work, evaluated on demonstrated proficiency and judgment rather than tenure

 

  • **Skills**
  • - Strong cloud security expertise in AWS, Azure, or Google Cloud Platform (IAM, KMS, VPC, Security Hub/Defender/SCC)
  • - Application security expertise (OWASP Top 10, secure coding, threat modeling, secure SDLC)
  • - Deep familiarity with vulnerability management (Wiz, Prisma Cloud, Tenable, Qualys) and SAST/DAST/SCA tools (Snyk, Checkmarx, Veracode, Semgrep)
  • - Infrastructure-as-code (Terraform, CloudFormation, Bicep) with IaC security scanning (Checkov, tfsec)
  • - Container and Kubernetes security (image scanning, admission controllers, network policies, RBAC)
  • - Detection engineering and SIEM content (Splunk, Sentinel, Chronicle) including KQL/SPL/YARA-L
  • - Identity protocols (OAuth2, OIDC, SAML) and IdP configuration (Okta, Entra ID, Auth0)
  • - Scripting in Python, Bash, or PowerShell for automation and tooling
  • - Understanding of compliance frameworks (SOC 2, HIPAA, PCI, ISO 27001, NIST CSF, FedRAMP) and ability to map controls
  • - Incident response participation including triage, investigation, and post-incident reviews
  • - Strong communication skills for working with developers and platform teams

 

  • **Delivery Methods**
  • - Agile or hybrid project delivery models
  • - Leads security workstreams within sprint cadence and partners with engineering teams on remediation

 

  • **Tools**
  • AWS, Azure, Google Cloud Platform, Wiz or Prisma Cloud, Snyk or Checkmarx, Splunk or Sentinel, Terraform, Checkov or tfsec, Burp Suite, Nessus or Qualys, Okta or Entra ID, GitHub or GitLab, JIRA or ADO, AI Tools (Claude, Cursor, GitHub Copilot)

 

  • **Certifications (Preferred)**
  • AWS Certified Security — Specialty, Azure SC-200/SC-100, Google Cloud Platform Professional Cloud Security Engineer, CISSP (in progress acceptable), OSCP, CKS
 

Similar jobs