Tech Security Engineer
Core
Hands-on engineering role embedding security into the software development lifecycle for applications, platforms, and cloud environments.
Role type
Application Security Engineer (IC)
Builds
Secure software development practices, secure applications, and cloud security controls
Domain
Software Engineering / Application Security / Cloud Security
Required skills
Application security concepts, web technologies, API security, security testing tools, authentication protocols, scripting, cloud environments
Preferred skills
CI/CD integration, containerization, IAM concepts, security frameworks
Technologies
Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode, SAML, OAuth 2.0, OpenID Connect, AWS, Azure, GCP, Docker, Kubernetes
Responsibilities
Perform application security reviews including design reviews, threat modeling, and code analysis; Conduct static and dynamic security testing (SAST/DAST) and vulnerability assessments; Partner with engineering teams to remediate vulnerabilities and implement secure coding practices; Support secure software development lifecycle (SDLC) practices and integrate security tooling into CI/CD pipelines; Evaluate and implement security tools and platforms; Provide guidance on authentication, authorization, and secure integration patterns; Support cloud security efforts across AWS, Azure, or GCP environments; Develop automation and tooling to improve security testing and remediation workflows
Seniority
Mid-level, hands-on IC