What You'll Do:We are seeking an experienced Security Engineer to join our growing security team in a multifaceted role that combines vulnerability management, application security, MITRE ATT&CK-based threat detection, AI-driven security automation, and security engineering expertise. This position requires a technical security professional with knowledge spanning cloud security, identity and access management (IAM), endpoint detection and response (EDR), SIEM administration, and hands-on scripting for automation development. The successful candidate will work closely with development teams, infrastructure teams, vendors, and internal stakeholders to optimize our security posture and manage enterprise risk.
Key Responsibilities:Application Security & Vulnerability Remediation
- Lead application security vulnerability remediation efforts across development teams
- Administer SAST tooling
- Administer DAST tooling
- Administer SCA and software composition / dependency scanning tools
- Triage and validate vulnerability findings to reduce false positives
- Provide remediation guidance to development teams on OWASP Top 10 and secure coding practices
- Integrate scanning tools with ticketing systems and CI/CD pipelines
- Generate AppSec metrics and reports
- Provide security code review support
Vulnerability Assessment & Management
- Administer vulnerability management platforms
- Configure scan policies, schedules, and asset groups
- Validate and prioritize vulnerability findings using risk-based prioritization (CVSS + context)
- Conduct expert analysis and risk scoring of vulnerabilities
- Coordinate remediation with IT and development teams
- Manage vulnerability exceptions and risk acceptances
- Track vulnerability aging and SLA compliance
- Generate management reports and dashboards
- Participate in product vulnerability management meetings
- Participate in Security by Design reviews
MITRE ATT&CK & Threat Detection
- Develop detection rules mapped to ATT&CK techniques
- Implement ATT&CK-based alert triage workflows
- Configure SIEM correlation rules using ATT&CK
- Conduct gap analysis of ATT&CK coverage
- Integrate threat intelligence feeds with ATT&CK mapping
- Build ATT&CK-based hunting queries
- Create ATT&CK-mapped incident reports
AI-Driven Security Automation & Agent Engineering
- Build and maintain scripted, cloud-based automation pipelines supporting the team's AI-driven security operations platform
- Develop and tune AI agent prompts, verdict logic, and disposition rules for automated alert triage
- Extend the team's internal tool-integration framework connecting security platforms for AI-assisted operations
- Integrate automation with SIEM, EDR, and ticketing systems
- Build automated enrichment and reporting workflows
- Monitor and tune agent/automation performance and disposition accuracy
- Develop custom integrations using APIs and cloud-native services
- Maintain observability for automated security workflows
Security Engineering & Architecture
- Lead Tier 2/3 security incident investigation and response
- Administer EDR, SIEM, and IAM platforms
- Implement and tune detection rules and alerts
- Manage cloud security configurations
- Support penetration testing and red team activities
- Conduct WAF/CDN rule audits and configuration reviews
- Provide security engineering expertise for infrastructure and application architecture decisions
- Support complex security investigations requiring deep technical analysis
- Contribute to security design reviews and technical security standards
Policy & Threat Intelligence
- Draft and review security policies and procedures
- Conduct policy gap analysis against frameworks
- Analyze threat intelligence from multiple sources
- Integrate threat feeds into detection and automation workflows
- Implement IOC blocking and detection rules
- Participate in information sharing communities (ISACs)
- Create threat intelligence reports
Required Qualifications: Education & Experience
- Bachelor's degree in Computer Science, Information Security, Engineering, or related technical field, or equivalent professional experience
- 5-7 years of experience in security engineering with demonstrated expertise in multiple security domains, including application security
Technical Skills
- Expert knowledge of vulnerability management platforms
- Proficient in MITRE ATT&CK mapping for detection rules and incident response
- Strong experience with SAST, DAST, and SCA tooling for application security
- Deep understanding of application vulnerabilities (OWASP Top 10, injection flaws, XSS, authentication bypasses)
- Hands-on scripting experience building cloud-based automation (serverless functions, event-driven pipelines, secrets management)
- Experience with, or strong interest in, AI agent engineering and tool-integration protocols for security operations
- Proficiency administering EDR platforms
- Experience with SIEM administration
- Solid understanding of IAM platforms and federation/SSO concepts
- Proficiency in cloud security (AWS, Azure, or GCP)
- Solid understanding of WAF configuration and audit
- Proficiency in scripting and automation (Python required; PowerShell a plus)
- Understanding of DevSecOps and secure CI/CD practices
- Practical experience with AI-powered security tooling, including building or operating LLM-based agents, and awareness of emerging AI threats (prompt injection, tool/agent security risks)
- Ability to produce dashboards and reporting for technical and executive audiences
Platform & Domain Experience- SIEM administration
- Security automation/orchestration, including AI agent-based automation
- Vulnerability management platforms
- EDR platforms
- DLP platforms
- GRC platforms
- SAST tooling
- DAST tooling
- SCA / dependency scanning tooling
- Cloud security (AWS, Azure, or GCP)
- Threat intelligence platforms
- Ticketing and collaboration platforms
Soft Skills & Experience- Strong analytical thinking and problem-solving capabilities
- Excellent communication skills for technical and business audiences
- Strong Agile proficiency with ability to integrate security into sprint planning
- Experience collaborating with development teams and partnering on secure coding
- Ability to translate technical vulnerability findings into actionable remediation guidance
- Strong written communication skills for security documentation, audit responses, and questionnaire completion
- Act as escalation point for Security Analysts
- Participate in project security reviews
- Support sales team with security questionnaires
- Participate in customer security calls
Preferred Qualifications:Certifications- CySA+ (CompTIA)
- Cloud Security certification (AWS, Azure, or GCP)
- GIAC GSEC
- Certified Ethical Hacker (CEH)
- GIAC GWEB (Web Application Penetration Tester)
- CompTIA PenTest+ (optional)
- GIAC GCTI (Cyber Threat Intelligence) (optional)
- SIEM Platform Certification (optional)
Additional Experience- DevSecOps experience integrating SAST/DAST into CI/CD pipelines
- Secure software development lifecycle (SSDLC) implementation experience
- Compliance experience with SOC 2, ISO 27001, or industry-specific regulations
- Experience with security audit preparation and vendor risk assessment programs
- Threat intelligence analysis and integration experience
- Experience coordinating third-party penetration testing
- Security awareness training development and delivery
- Experience building or integrating LLM-based agents/automation for security operations
- Experience with container and Kubernetes security concepts
Benefits and Perks:- Flexible and generous Paid Time Off and Paid Volunteer Days
- 401k Employer Match
- Generous Healthcare Benefits
- Up to 12 weeks paid time off for maternity leave based on tenure
- Wellness &Tuition Reimbursement
- Flexible Work Arrangements
- Lots of SambaSafety swag & SambaSafety Events