POSITION: Senior Security Engineer DATE: September 2026
DEPARTMENT: Information Technology FLSA: Exempt
REPORTS TO: Director, Information Security
SUMMARY OF POSITION
The Senior Security Engineer designs, implements, operates, and continuously improves OF's security technologies and controls across applications and supporting platforms. Primary focus is Application Security-embedding security into the SDLC and CI/CD pipelines, strengthening web/API protections, and enabling proactive detection, while contributing broadly to Security Engineering capabilities (identity, cloud/on prem security platforms, logging/telemetry, and automation). The role partners closely with development, DevOps, and operations teams to build secure-by-default applications and services.
PRINCIPAL RESPONSIBILITIES
• Develop and maintain software application security policies and procedures
• Implement software application security controls
• Partner with DevOps in developing a secure CI/CD pipeline
• Design and operate web application firewall (WAF) and API protections; tune rules, reduce false positives, and automate policy updates
• Identify application security vulnerabilities and issues, perform risk assessments and provide mitigations
• Develop security monitoring for application stack
• Conduct technical investigations of application security incidents
• Interface with senior stakeholders across the IT leadership team to proactively interpret risks and priorities.
• Support the OF's diversity and inclusion strategy by following policies and procedures that ensure opportunities for employees and diverse business partners.
• Assist with other job duties as assigned.
PRINCIPAL JOB REQUIREMENTS
• A minimum [TF4.1]of 6 to 8 years of experience in Application Security (designing, implementing, and operating security controls in enterprise application environments).
• Hands-on experience with web application security, including OWASP Top 10 vulnerabilities
• Hands-on experience with WAF/API security (policy design, rule tuning, automation), container security (runtime hardening, image scanning, vulnerability risk assessments)
• Hands-on experience with conducting web application security scans, vulnerability assessments and/or penetration testing
• Experience in investigating problems and processes within established methodologies and best practices.
• Experience working with Authentication and Authorization services like OAuth and OpenID
• Experience in operating on-prem or cloud based security platforms
• Ability to troubleshoot security and network-related issues and communicate technical findings effectively
• Ability to listen and integrate ideas from diverse groups of individuals, build and maintain respectful relationships, collaborate with others, and resolve conflicts constructively.
• Bachelor's Degree in Information Security or Computer Science or Computer/Electrical Engineering, and/or equivalent field experience.
• Proof of eligibility to work in the United States.
This position has an annualized salary range of $140,441 - $202,303. The final salary offered within this range is dependent on various factors, including but not limited to the responsibilities of the position, the experience, skill set and other relevant qualifications of the applicant and internal pay equity.