Job Purpose: Serve as a senior individual contributor on the Security Engineering team with a primary focus on Application Security, while contributing to Security Operations and AI Security. Maintain the day-to-day technical relationship with the offshore security vendor — setting expectations, reviewing deliverables, and ensuring quality — and reduce application and operational security risk across the SDLC while helping mature the organization’s security practices.
- Application Security (primary): Lead application security reviews across the SDLC — threat modeling, secure design review, and secure code review for web, API, and cloud services. Triage and drive remediation of vulnerabilities from SAST, DAST, SCA, and penetration testing in partnership with engineering.
- Offshore Vendor Relationship: Serve as the primary day-to-day technical contact for the offshore security vendor — scoping work, reviewing deliverables for quality, coordinating across time zones, unblocking the team, and tracking commitments and risks.
- Security Operations (SecOps): Support detection, monitoring, alert investigation, and incident response. Help tune detections, reduce false positives, improve runbooks, and contribute to vulnerability management and infrastructure/endpoint hardening.
- AI Security: Help assess and secure AI/ML and LLM-based systems (prompt injection, data leakage, model abuse, supply-chain risk) and contribute to emerging AI security standards, review processes, and guardrails.
Education and Experience:
• Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent practical experience.
• 6+ years in security engineering with demonstrated hands-on application security experience (secure code review, threat modeling, vulnerability remediation).
• Practical experience with Security Operations — monitoring, detection, and/or incident response.
• Proven experience maintaining an offshore or third-party vendor relationship across time zones.
• Exposure to AI/ML or LLM security concepts, or a strong demonstrated drive to ramp up quickly.
• Relevant certifications (e.g., OSCP, GWAPT, CSSLP, CISSP, or cloud security) preferred.
Knowledge, Skills, and Attributes:
• Good application security fundamentals (OWASP, secure SDLC, common vulnerability classes).
• Familiarity with cloud security (AWS/Azure), CI/CD, and containerized environments.
• Scripting/automation skills (e.g., Python) a plus.
• Coachable and eager to learn, with a growth mindset and openness to feedback.
• Strong written and verbal communication; effective across engineering, operations, and external partners.
• Self-directed and collaborative, able to manage priorities with little day-to-day instruction.
Physical Requirements:
Standard office/remote work environment. Prolonged periods working at a computer. Occasional travel may be required.
Working Conditions:
Hybrid work arrangement during standard business hours, with periodic coordination across time zones to support the offshore vendor and occasional after-hours work during security incidents.