Security Engineer
Core
Perform application security testing, vulnerability remediation, and DevSecOps automation to secure hybrid cloud and on-premise infrastructure.
Role type
Senior IC Security Engineer (AppSec & DevSecOps)
Builds
Secure hybrid cloud environments, containerized workloads, and CI/CD pipelines for clients in healthcare and fintech.
Domain
Cybersecurity, Cloud Security, DevSecOps
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Penetration testing, red teaming, manual code reviews, SAST/DAST/SCA, vulnerability remediation, threat modeling, AWS security, hybrid infrastructure hardening, CI/CD pipeline automation, secrets management, OWASP Top 10, SBOM tracking
Preferred skills
OSCP, OSWE, CISSP, GWAPT, AWS Certified Security – Specialty, HIPAA, HITRUST, PCI-DSS compliance, legacy system refactoring, container security (Docker, Kubernetes/EKS), AI tooling proficiency
Technologies
Burp Suite Professional, OWASP ZAP, Wiz, Snyk, Qualys, SonarQube, GitHub Actions, AWS KMS, HashiCorp Vault, Docker, Kubernetes/EKS, React, .NET, Java
Responsibilities
Perform dynamic and static application security testing (SAST/DAST/SCA), red team exercises, and penetration testing; execute code-level patches and infrastructure configuration fixes across .NET, Java, and React stacks; configure and optimize enterprise security scanners; embed automated SAST/SCA scanning and secret management into CI/CD pipelines; conduct architecture security reviews and threat modeling; secure and harden hybrid AWS, containerized, and on-premise infrastructure
Seniority
Senior, hands-on IC