Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
19 hours ago
OWASPScrumAgileJavaPython
Job Description
- **Remote but must be located in Irving, TX, Chicago, IL, Peoria, IL, or Broomfield, CO***
Required Skills for the Cybersecurity Engineer
- 5-7 years of hands-on application security/DevSecOps experience
- Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding
- Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
- Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts
- OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques
- Cloud security, identity and access management, and modern application architectures
- Safe and effective use of AI-assisted development and security tools
- Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance
- Security metrics, coverage reporting, and executive dashboard development
- Excellent communication, stakeholder management, presentation, and documentation skills
- Ability to work independently across multiple applications, teams, portfolios, and technology stacks
- Strong problem-solving mindset — balances security, usability, operational impact, and business objectives
- Collaboration and influence — negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders
- Coaching and knowledge sharing — champions a security-first culture
- Comfortable operating within Scrum/Agile delivery and managing own work items
Cybersecurity Engineer Responsibilities
- Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams
- Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
- Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity
- Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio
- Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends
- Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and ‘must-win’ business outcomes
Typical task breakdown
- Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impact
- Daily: manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review
- Daily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closure
- Weekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defects
- Weekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controls
- Monthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvement
- Ongoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks
Similar jobs
- CS
CYBERSECURITY ENGINEER
NewComTec Solutions LLC
Rochester, NY🇺🇸Hybrid19 hours agoMicrosoft OfficeVMwareTechnology - RB
Cybersecurity Analyst with Security Clearance
NewRBR-Technologies
Fort Meade, MD🇺🇸On-site19 hours agoSQLHTTPPowerShell+3Technology - CP
Cyber Range Operations Engineer with Security Clearance
NewCommand Post Technologies Inc
Destin, FL🇺🇸On-site19 hours agoLESSVMwareTechnology - CP
Cyber Security Evaluation Team (CSET) Member with Security Clearance
NewCommand Post Technologies Inc
Patuxent River, MD🇺🇸On-site19 hours agoBashLESSPenetration Testing+2Technology - SE
Exploitation Analyst EA Level 14 with Security Clearance
Sentar Inc
Annapolis Junction, MD🇺🇸Hybrid4 days agoMental HealthPenetration TestingRecruiting - SO
Computer Network Defense Analyst (CNDA) with Security Clearance
Set of X
Annapolis Junction, MD🇺🇸$120k - $210k/yrHybrid4 days agoIoTPenetration Testing