Haystack
← Back to Jobs
Technology
C3

Security Engineer

Codeforce 360New York, NY🇺🇸United StatesPosted Oct 5, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
New York, NY, United States
Posted
18 hours ago
OWASPC++JavaPython

Job Description

About Us:

CodeForce 360 is a trusted global IT talent partner helping Fortune 500 companies, system integrators, and enterprise organizations build high-performing technology teams. With over 16 years of industry expertise, we combine speed, precision, and market intelligence to deliver exceptional talent across today's most in-demand technologies.

About the Job- We are looking for an experienced Security Engineer to join one of our enterprise client engagements. The ideal candidate should have strong expertise in C++, Go, Java, Python along with experience working in fast-paced enterprise environments.

Job Description:

  • The pod will act as the operational bridge between automated security scanning/remediation systems and product code owners.
  • Their mission is to streamline threat modeling, eliminate triage noise, validate exploitability, verify automated patches, and drive open security issues to verified resolution.

Core Workstreams & Responsibilities

  • #
  • Workstream
  • Key Responsibilities
  • Primary Deliverables

Threat Modeling & Asset Profiling

  • Document trust boundaries, data flows, and architectural entry points for high-priority services.
  • Maintain up-to-date threat profiles in centralized repositories.
  • Standardized threat model documentation.
  • Service risk classification tags.

Vulnerability Triage & Policy Management

  • Review and filter findings generated by automated source and endpoint scanners.
  • Classify severity and evaluate exception requests against security compliance policies.
  • Bug tracking queue hygiene.
  • Policy-compliant severity assignments.
  • Documented exception reviews.

Reproduction & PoC Validation

  • Construct minimal test environments and reproduction harnesses.
  • Validate whether reported findings represent viable vulnerabilities vs. false positives.
  • Confirmed reproduction steps/notes attached to issue tickets.
  • Fast-closed false positives.

Automated / Agentic Fixer Oversight & QA

  • Supervise and validate code patches generated by automated remediation agents.
  • Execute unit and integration tests, inspect diffs for unintended regressions, and verify fix efficacy.
  • QA-approved, tested patch change lists ready for code owner review.

Product Team Coordination & Closure

  • Route validated patches to designated product team code owners.
  • Shepherd fixes through code review and verify end-to-end deployment to production.
  • SLA-compliant issue closures.
  • Production fix verification notes.
  • Skill Breakdown by Operational Workstream
  • Workstream

Must-Have Technical Skills

  • Nice-to-Have / Advanced Skills
  • Threat Modeling
  • Understanding of architectural trust boundaries, attack surfaces, and data flows.
  • Familiarity with structured threat modeling frameworks (e.g., STRIDE, PASTA).
  • Experience conducting threat model reviews for large distributed / microservice systems.
  • Ability to translate abstract system designs into concrete threat scenarios.

Triage & Policy Management

  • Working knowledge of common vulnerability classifications (CWE, CVE, OWASP Top 10).
  • Ability to interpret vulnerability scoring matrices and map findings to strict remediation SLAs.
  • Experience managing vulnerability queues and reviewing compliance exception requests.
  • Familiarity with automated static/dynamic scanning tools.

Vulnerability Reproduction

  • Proficiency in reading and writing code in at least two core languages (C++, Go, Java, Python).
  • Ability to set up local test harnesses, mock dependencies, and build minimal PoCs.
  • Practical experience with fuzz testing, unit test frameworks, and sandbox execution.
  • Debugging complex runtime or logic errors across service boundaries.

Automated / Agentic Fixer QA

  • High attention to detail during code reviews (spotting hallucinations, regressions, off-by-one errors).
  • Understanding of secure coding standards (input validation, boundary checking, safe memory access).
  • Experience debugging and prompt-tuning automated code generation tools.
  • Familiarity with automated patch validation and differential testing.

How To Apply

Job ID: JPC - 237555

Contact:

Name: Sreekar Konapuram

Email:

Phone:

  

CodeForce 360 proudly provides equal employment opportunities to all employees and applicants and prohibits discrimination and harassment of any kind without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable federal, state, or local laws.

Similar jobs