Apply

Security Engineer

Posted 2024-09-29

View full description

💎 Seniority level: Middle, 3 - 5+ years

📍 Location: United States, PST, NOT STATED

💸 Salary: $97,000 - $106,000 per year

🔍 Industry: Cybersecurity

🏢 Company: Bugcrowd👥 501-1000💰 $30.0m Series D on 2020-04-09CrowdsourcingPenetration TestingSecurityCyber Security

🗣️ Languages: English

⏳ Experience: 3 - 5+ years

🪄 Skills: AWSPythonBashGitKotlinRubyRuby on RailsJiraGolang

Requirements:
  • Bachelor's Degree in a relevant field or commensurate experience
  • 3 - 5+ years of professional experience in a similar role or its equivalent
  • Experience with writing IR plans and operating within an IR practice
  • Working knowledge of Threat Intelligence and its use in creating security controls
  • Familiarity with Pentesting techniques and OWASP Top 10
  • Ability to understand and work with developers to patch vulnerabilities
  • Scripting knowledge in at least one: Bash, Python, JavaScript, Ruby
  • Self-motivated and organized
  • Cloud security experience or holds AWS cloud certifications
  • Experience with Identity and Access Management (IAM) controls
  • Familiarity with git
  • Familiarity with a ticketing system / issue tracking system (e.g.: Jira)
Responsibilities:
  • Aiding within the Incident Response process
  • Threat hunting
  • Developing patches and security controls within Ruby on Rails, Golang, and Kotlin applications
  • Communicating technical knowledge to multiple audiences
  • Significant familiarity with AWS and network security controls
  • Identifying vulnerability root causes
  • Performing basic risk assessments and triaging
  • Educating developers on security best practices
  • Architecting solutions with developers to remediate security concerns
  • Performing basic red team assessments
  • Testing new features within the platform and services
  • Automating security tasks to increase workflow efficiency
  • Mentoring other team members
Apply

Related Jobs

Apply

📍 Little Rock / Northwest Arkansas

🧭 Full-Time

🔍 Information Security

🏢 Company: GuidePoint Security

  • Must live in the Little Rock / Northwest Arkansas area.
  • 2-3 years in an enterprise-level security consultative, vendor, or operational role.
  • Prior client-facing presales or consultative role experience.
  • Deep proficiency in multiple security technologies including Network Security, Cloud Security, Vulnerability Management, and SIEM.
  • Expertise in architecting and designing enterprise-scale security solutions.
  • Proficiency in various client and server operating systems (Windows, Linux, OSX).
  • Experience with AWS, Azure, or GCP.
  • Working knowledge of advanced security concepts like Defense in Depth and Zero Trust.

  • Focus on driving new business by working with Account Executives within territory.
  • Provide direction for engineering cyber-security solutions.
  • Make design and configuration recommendations for clients' environments.
  • Listen to clients to understand issues and gaps in their security programs and provide solutions.
  • Articulate complex technical content to technical and non-technical audiences.
  • Work with teams to create new service offerings and supporting collateral.
  • Research and engage emerging vendors and technologies.
  • Author comprehensive business and technical collateral.
  • Position GuidePoint’s Information Assurance Service Offerings.

AWSCybersecurityGCPAzureLinux

Posted 2024-11-21
Apply
Apply

📍 United States

🧭 Full-Time

💸 127350 - 203760 USD per year

🔍 Security technology

🏢 Company: Axon

  • A fundamental understanding of how modern, distributed cloud-based applications function.
  • Demonstrated experience in security best practices or an interest in building that knowledge.
  • Experience responding to and investigating information security events and incidents.
  • 1+ year(s) of experience using SOAR and SIEM solutions.
  • Fluency in development languages like Python or Go, and shell scripting (bash/powershell).
  • Experience interacting with cloud platforms like Azure and AWS via APIs.
  • Working competency with GitOps.
  • Strong problem-solving skills.
  • Strong written and verbal communication skills.
  • Bachelor’s degree or higher, or equivalent experience.

  • Design, develop, implement, and maintain tooling to improve Axon’s ability to detect and respond to security events.
  • Participate in an on-call rotation to investigate and remediate escalated security events.
  • Evaluate and integrate new security tools and technologies into the SOC.
  • Partner with teams throughout the company to build secure solutions.
  • Write run books and draft incident reports for leadership.
  • Engineer solutions for current security attack methods.
  • Contribute to enhancing the overall Information Security Program.
  • Stay current on security industry trends through educational opportunities.

AWSPythonBashAzureGoCommunication SkillsProblem Solving

Posted 2024-11-21
Apply
Apply

📍 United States

🧭 Full-Time

💸 100000 - 120000 USD per year

🔍 Technology-enabled healthcare services

🏢 Company: Urrly

  • 3-5 years of hands-on experience in security engineering.
  • Experience deploying and managing IAM, SIEM, firewalls, anti-malware, and vulnerability scanning systems.
  • Strong ability to manage security technologies in AWS and enterprise environments.
  • Familiarity with SOC 2, HITRUST, and HIPAA frameworks.
  • Strong documentation skills for developing policies, procedures, and security configurations.
  • Proven success in identifying, remediating, and preventing security threats.

  • Design, implement, and maintain security measures, tools, and frameworks to protect systems and sensitive data.
  • Install, configure, and manage security controls in AWS environments such as firewalls and intrusion detection systems.
  • Monitor infrastructure for potential threats and conduct incident response.
  • Lead compliance initiatives with frameworks like SOC 2, HITRUST, and HIPAA, including audit support and documentation.
  • Perform risk evaluations, vulnerability assessments, and enhance overall security posture.
  • Collaborate with cross-functional teams to align security policies with business goals.

AWSBashCybersecurityAmazon Web ServicesLinuxDocumentationCompliance

Posted 2024-11-21
Apply
Apply

📍 United States

🧭 Full-Time

💸 188000 - 230000 USD per year

🔍 Mental health care technology

  • 5+ years of experience in security and/or software engineering roles.
  • Demonstrated history of working on security-related projects.
  • Strong cross-functional experience with team collaboration.
  • Technical depth in building secure platforms and products.
  • Ability to tackle ambiguous problems in a fast-paced environment.
  • Focus on innovation in security and privacy technologies.
  • Results-driven and motivated by the mission to increase access to quality mental health care.

  • Partner with Product and Engineering for secure new product launches.
  • Engage in implementation efforts, security reviews, product design decisions, and auditing vulnerabilities.
  • Develop automated tooling for product security capabilities.
  • Define application guardrails for secure development practices.
  • Assist in ongoing security operations, including incident response and vulnerability management.

AWSPythonKafkaTypeScriptFastAPIPostgresProduct designRedisReactSpark

Posted 2024-11-21
Apply
Apply

📍 United States

🔍 Data and technology

  • 5+ years experience in security engineering or site reliability engineering.
  • Excellent Terraform skills required.
  • Experience working with and developing CI/CD pipelines for Infrastructure as Code required.
  • Knowledge of programming/scripting fundamentals (python/golang) required.
  • Expertise in performing ETL onboarding for diverse log feed technologies required.
  • Experience supporting a Splunk platform administration, new content dashboards, applications, and use cases.
  • Hands-on experience developing Rest API's to capture data from external sources.
  • Experience with Agile methodologies.
  • Understanding of multiple log formats and source data for SIEM Analysis.
  • Solid background with Windows and Linux platforms (security or system administration).
  • Experience with technical concepts including networking and several cyber attacks.

  • Understand data feeds of multiple security tools and logs that feed the SIEM & UEBA technologies.
  • Identify capabilities and quality of these feeds and recommend improvements.
  • Create new content use cases based on threat intelligence, analyst feedback, available log data, and previous incidents.
  • Perform daily activities of the content life cycle including creating, testing, tuning, and maintaining associated documentation.
  • Improve vulnerabilities across different application environments.
  • Work with other security teams and product SMEs to identify capability gaps.
  • Develop parsers and field extractions to support content development.
  • Develop custom scripts to enhance default SIEM functionality.
  • Participate in root cause analysis on security incidents and provide recommendations for new data sources and enrichment.

PythonAgileETLGolangREST APICI/CDLinuxTerraformDocumentation

Posted 2024-11-21
Apply
Apply

📍 United States

🧭 Full-Time

💸 157250 - 185000 USD per year

🔍 Healthcare technology

🏢 Company: Cedar

  • You’re an application security engineer who prioritizes addressing security challenges with technology, not process.
  • You have a demonstrated history of enabling software developers with actionable security guidance.
  • You’re comfortable communicating security risks and controls to technical and non-technical partners.
  • You have experience with security code review, threat modeling or security architecture reviews.
  • You can identify vulnerability paths, explain how they could be exploited, and are familiar with options for mitigation.
  • You have a working proficiency with a general-purpose programming language (ideally Python).

  • Support services and tools that help product and platform engineers build, deploy, and maintain Cedar products safely and efficiently.
  • Serve as a Security Partner for multiple engineering teams across the SSDLC, evangelizing security and helping threat model features, bake security into designs, and review code and implementations.
  • Contribute to security automation projects, such as static analysis, vulnerability management, and asset inventory.

Software Development

Posted 2024-11-19
Apply
Apply

📍 U.S.

🧭 Full-Time

🔍 Cybersecurity

🏢 Company: GuidePoint Security

  • 6 or more years of IT experience or related field.
  • At least 4 years of experience administering and supporting Azure/Office/M365 technologies.
  • Minimum 2 years of experience with M365 security suite such as Defender for Cloud apps and Conditional Access.
  • Minimum 2 years of experience with Azure capabilities like Defender for Cloud and Sentinel.
  • Microsoft certification such as Microsoft 365 Security Administrator or Azure Security Engineer Associate required within 3 months of hire.

  • Use knowledge of Microsoft Azure, M365, and EM+S products to design and make recommendations on Microsoft Cloud Security.
  • Communicate compliance management for M365 or Azure products and implement best practices for security.
  • Contribute to technical design sessions and prepare documentation for architectural reviews.
  • Manage Microsoft Entra ID and identity life-cycle management.
  • Conduct security assessments using established cloud security standards.
  • Document findings and recommendations for clients and demonstrate strong communication skills.

Cloud ComputingCybersecurityMicrosoft AzureSharePointAzureCommunication SkillsCollaborationDevOpsTerraformDocumentationCompliance

Posted 2024-11-19
Apply
Apply

📍 Brazil, US

🔍 Open Banking Payments

  • Relevant expertise in information security
  • Knowledge of compliance practices in information security
  • Ability to work effectively in a diverse and collaborative team environment

  • Ensuring information security across the organization
  • Enhancing security measures for payment processing
  • Supporting compliance with established security policies and regulations

CybersecurityCommunication SkillsAnalytical SkillsCollaborationProblem SolvingAttention to detailOrganizational skillsPresentation skillsTime ManagementWritten communicationMultitasking

Posted 2024-11-15
Apply
Apply

📍 Brazil, US, Sweden

🔍 Open Banking Payments

  • Demonstrated experience in information security practices and technologies.
  • In-depth knowledge of compliance frameworks and their implementation.
  • Strong analytical skills and problem-solving abilities.

  • Develop and implement information security strategies to protect key assets.
  • Conduct risk assessments to identify vulnerabilities and recommend mitigation solutions.
  • Monitor security systems and respond to incidents effectively.
  • Ensure compliance with industry standards and regulations related to information security.

CybersecurityCommunication SkillsAnalytical SkillsCollaborationProblem SolvingMentoringAttention to detailOrganizational skillsWritten communicationDocumentation

Posted 2024-11-15
Apply
Apply

📍 US

💸 166000 - 207500 USD per year

🔍 People success platform

🏢 Company: Lattice

  • 5+ years of experience in security operations, auditing, or IT focused on IAM systems and compliance.
  • Strong expertise in managing IAM tools and controls within platforms like Okta, Zscaler, and CrowdStrike.
  • Demonstrated ability to assess IAM configurations and recommend security improvements.
  • Knowledge of compliance frameworks (SOC2 preferred) and authentication protocols.

  • Conduct in-depth audits of systems for IAM configurations, ensuring compliance with security standards.
  • Review and enhance IAM security controls across systems like Okta, Zscaler, and CrowdStrike.
  • Collaborate with IT and engineering teams to optimize IAM configurations for secure access.
  • Lead compliance initiatives, including SOC2 audits, preparing documentation and ensuring evidence is accessible.
  • Manage IAM-related security alerts and optimize alert rules and thresholds.
  • Develop and maintain detailed documentation for IAM processes and controls.

CybersecurityLDAPOAuthCommunication SkillsAnalytical SkillsCollaborationProblem SolvingLinuxAttention to detailOrganizational skillsTime ManagementWritten communicationDocumentationCompliance

Posted 2024-11-14
Apply