Security Engineer

Seyfarth Shaw LLP

$118K — $135K *
Miami, FL 33186In-Person
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in cybersecurity, security engineering, or related IT role
  • Strong grasp of common application vulnerabilities and attack methods
  • Understanding of software supply-chain risks related to software updates and dependencies
  • Familiarity with offensive security methodologies
  • Experience in evaluating applications' security aspects like permissions and architecture
  • Knowledge of modern identity and authentication technologies (e.g. SSO, OAuth)
  • Understanding of Windows and cloud security concepts
  • Able to use security tools like SIEMs and vulnerability scanners

Responsibilities

  • Conduct technical security assessments for applications and SaaS platforms
  • Evaluate application architecture and data access controls
  • Identify potential attack vectors from compromised applications
  • Review security documentation and threat intelligence for risk assessment
  • Examine authentication configurations for vulnerabilities
  • Collaborate across teams to find security design gaps
  • Audit deployed applications for business needs and vulnerabilities
  • Assist in managing application inventories to eliminate security risks

Benefits

  • Paid time off
  • Medical, dental, and vision insurance
  • 401(k) retirement plan
  • Annual merit increase and bonus eligibility
Full Job Description
The Opportunity

As a Security Engineer - Application Security & Technology Risk, you will help evaluate and protect the Firm's technology environment by assessing the security risks associated with applications, SaaS platforms, browser extensions, integrations, and other technologies proposed for use within the Firm.

A significant part of this role will involve understanding how a technology works, the access and permissions it requires, the data it can access or process, how it integrates with the Firm's environment, and how it could potentially be abused or compromised. You will evaluate these technologies from both a defensive and adversarial perspective, considering vulnerabilities, software supply-chain risk, authentication and authorization controls, configuration weaknesses, and the ways an attacker could leverage a compromised application or integration.

The successful candidate will combine strong technical security knowledge with the ability to translate security findings into practical, risk-based recommendations for application owners, IT teams, and Firm leadership.

The Day-To-Day

On any given day, you will work with Security, IT, application owners, project teams, vendors, and other stakeholders on a variety of technology assessments and security initiatives. You will:

  • Perform technical security assessments of software applications, SaaS platforms, browser extensions, integrations, AI-enabled technologies, and other technologies proposed for use within the Firm.
  • Evaluate application architecture, permissions, data access, administrative controls, authentication methods, APIs, OAuth integrations, third-party dependencies, logging capabilities, and security configuration.
  • Assess how compromised or malicious applications could be leveraged as an attack vector, including credential theft, data exposure, persistence, privilege escalation, lateral movement, command and control, and software supply-chain compromise.
  • Review vendor and application security documentation, vulnerability information, threat intelligence, software dependencies, and publicly available security research to identify potential risks.
  • Evaluate authentication and authorization configurations including SSO, SAML, OAuth/OIDC, MFA, Microsoft Entra ID integrations, Conditional Access policies, service principals, application registrations, API permissions, and privileged access requirements.
  • Work with infrastructure, endpoint, cloud, identity, networking, and application teams to identify security design or configuration gaps and recommend practical remediation or compensating controls.
  • Review existing deployed applications to determine business need, usage, software versions, support status, known vulnerabilities, available updates, and potential security exposure.
  • Assist with application inventory and software lifecycle initiatives designed to identify unnecessary, obsolete, vulnerable, or unauthorized applications within the environment.
  • Validate approved application deployments to confirm that software, security controls, permissions, integrations, and configurations were implemented according to approved requirements.
  • Use vulnerability management, endpoint security, SIEM, identity, network, asset discovery, and other security telemetry to understand application behavior and identify potential security concerns.
  • Support Security Operations with threat hunting, security investigations, incident response, and other operational security activities as needed.
  • Clearly document findings, risk, technical impact, and recommended controls for both technical and non-technical audiences.
  • Exercise independent judgment, curiosity, and initiative when investigating unfamiliar technologies and security risks.


You Have

  • At least three years of experience in cybersecurity, security engineering, application security, vulnerability management, penetration testing, security operations, or a related technical information technology role.
  • Strong understanding of common vulnerabilities, attack techniques, and the ways attackers compromise applications, endpoints, identities, cloud services, and enterprise environments.
  • Strong understanding of software supply-chain risk, including compromised software updates, malicious dependencies, third-party libraries, browser extensions, package repositories, software signing, and vendor compromise.
  • Familiarity with offensive security and penetration testing methodologies and the ability to apply an attacker mindset when evaluating new technologies.
  • Experience evaluating applications or SaaS platforms from a security perspective, including permissions, architecture, integrations, authentication, authorization, data access, and administrative controls.
  • Working knowledge of modern identity and authentication technologies including SSO, SAML, OAuth 2.0, OpenID Connect, MFA, Microsoft Entra ID, enterprise application registrations, and Conditional Access.
  • Understanding of Windows and cloud security concepts, endpoint security controls, networking, APIs, and common enterprise application deployment models.
  • Experience working with security technologies such as vulnerability scanners, endpoint detection and response platforms, SIEM platforms, identity security tools, network security platforms, or application security testing tools.
  • Familiarity with tools such as Qualys, CrowdStrike Falcon, Microsoft Sentinel, Microsoft Entra ID, Burp Suite, or comparable security platforms is preferred.
  • Ability to research unfamiliar technologies, understand how they operate, identify meaningful security concerns, and distinguish theoretical risk from realistic enterprise risk.
  • Strong analytical and troubleshooting skills with attention to technical detail.
  • Ability to communicate security findings clearly and work collaboratively with technical teams, application owners, vendors, and business stakeholders.
  • Scripting, API, or automation experience with PowerShell, Python, or similar technologies is preferred.
  • A strong desire to continuously learn about emerging technologies, vulnerabilities, attack techniques, and changes in the cyber threat landscape.


Location Specific Language

The salary range for this role is $118,000 to $135,000 annually, which is based on a 40 hour work week. This range is only applicable for jobs to be performed in Chicago. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee's pay within the salary range will be based on numerous factors including, but not limited to, relevant education, qualifications, experience, skills, and business or organizational needs. This job is also eligible for an annual merit increase and bonus pay.

We offer a comprehensive package of benefits including paid time off, medical/dental/vision insurance, and 401(k).

#LI-Remote

This position is based in Atlanta, GA 30309

This position is based in Charlotte, NC 28202

This position is based in Chicago, IL 60606

This position is based in Dallas, TX 75201

This position is based in Houston, TX 77002

This position is based in Miami, FL 33131

  • At least three years of experience in cybersecurity, security engineering, application security, vulnerability management, penetration testing, security operations, or a related technical information technology role.
  • Strong understanding of common vulnerabilities, attack techniques, and the ways attackers compromise applications, endpoints, identities, cloud services, and enterprise environments.
  • Strong understanding of software supply-chain risk, including compromised software updates, malicious dependencies, third-party libraries, browser extensions, package repositories, software signing, and vendor compromise.
  • Familiarity with offensive security and penetration testing methodologies and the ability to apply an attacker mindset when evaluating new technologies.
  • Experience evaluating applications or SaaS platforms from a security perspective, including permissions, architecture, integrations, authentication, authorization, data access, and administrative controls.
  • Working knowledge of modern identity and authentication technologies including SSO, SAML, OAuth 2.0, OpenID Connect, MFA, Microsoft Entra ID, enterprise application registrations, and Conditional Access.
  • Understanding of Windows and cloud security concepts, endpoint security controls, networking, APIs, and common enterprise application deployment models.
  • Experience working with security technologies such as vulnerability scanners, endpoint detection and response platforms, SIEM platforms, identity security tools, network security platforms, or application security testing tools.
  • Familiarity with tools such as Qualys, CrowdStrike Falcon, Microsoft Sentinel, Microsoft Entra ID, Burp Suite, or comparable security platforms is preferred.
  • Ability to research unfamiliar technologies, understand how they operate, identify meaningful security concerns, and distinguish theoretical risk from realistic enterprise risk.
  • Strong analytical and troubleshooting skills with attention to technical detail.
  • Ability to communicate security findings clearly and work collaboratively with technical teams, application owners, vendors, and business stakeholders.
  • Scripting, API, or automation experience with PowerShell, Python, or similar technologies is preferred.
  • A strong desire to continuously learn about emerging technologies, vulnerabilities, attack techniques, and changes in the cyber threat landscape.


On any given day, you will work with Security, IT, application owners, project teams, vendors, and other stakeholders on a variety of technology assessments and security initiatives. You will:
  • Perform technical security assessments of software applications, SaaS platforms, browser extensions, integrations, AI-enabled technologies, and other technologies proposed for use within the Firm.
  • Evaluate application architecture, permissions, data access, administrative controls, authentication methods, APIs, OAuth integrations, third-party dependencies, logging capabilities, and security configuration.
  • Assess how compromised or malicious applications could be leveraged as an attack vector, including credential theft, data exposure, persistence, privilege escalation, lateral movement, command and control, and software supply-chain compromise.
  • Review vendor and application security documentation, vulnerability information, threat intelligence, software dependencies, and publicly available security research to identify potential risks.
  • Evaluate authentication and authorization configurations including SSO, SAML, OAuth/OIDC, MFA, Microsoft Entra ID integrations, Conditional Access policies, service principals, application registrations, API permissions, and privileged access requirements.
  • Work with infrastructure, endpoint, cloud, identity, networking, and application teams to identify security design or configuration gaps and recommend practical remediation or compensating controls.
  • Review existing deployed applications to determine business need, usage, software versions, support status, known vulnerabilities, available updates, and potential security exposure.
  • Assist with application inventory and software lifecycle initiatives designed to identify unnecessary, obsolete, vulnerable, or unauthorized applications within the environment.
  • Validate approved application deployments to confirm that software, security controls, permissions, integrations, and configurations were implemented according to approved requirements.
  • Use vulnerability management, endpoint security, SIEM, identity, network, asset discovery, and other security telemetry to understand application behavior and identify potential security concerns.
  • Support Security Operations with threat hunting, security investigations, incident response, and other operational security activities as needed.
  • Clearly document findings, risk, technical impact, and recommended controls for both technical and non-technical audiences.
  • Exercise independent judgment, curiosity, and initiative when investigating unfamiliar technologies and security risks.

Similar Jobs

More Jobs at Seyfarth Shaw LLP

  • Security Engineer
    $118K — $135K *
    Charlotte, NC 28269 (Mecklenburg County)
    Information Technology
    In-Person
  • Security Engineer
    $118K — $135K *
    Houston, TX 77084 (Harris County)
    Information Technology
    In-Person
  • Security Engineer
    $118K — $135K *
    Miami, FL 33186 (Miami-Dade County)
    Information Technology
    In-Person
  • Security Engineer
    $118K — $135K *
    Dallas, TX 75217 (Dallas County)
    Information Technology
    In-Person
  • Security Engineer
    $118K — $135K *
    Atlanta, GA 30349 (Fulton County)
    Information Technology
    In-Person

More Information Technology Jobs

Find similar Security Engineer jobs: