Cybersecurity Engineer
Contract W2
Contract Corp To Corp
12 Months
No Travel Required
Remote
$50 - $55/hr


Goldenpick Technologies LLC
Fitment
Dice Job Match Score™
🔢 Crunching numbers...
Job Details
Skills
- CYBERSECURITY
- DEVSECOPS
- SECURITY
- CODEQL
- SAST
- SCA
- SECRET SCANNING
Summary
***Remote but must be located in Irving, TX, Chicago, IL, Peoria, IL, or Broomfield, CO***
Required Skills for the Cybersecurity Engineer:
- 5-7 years of hands-on application security/DevSecOps experience
- Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding
- Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
- Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts
- OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques
- Cloud security, identity and access management, and modern application architectures
- Safe and effective use of AI-assisted development and security tools
- Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance
- Security metrics, coverage reporting, and executive dashboard development
- Excellent communication, stakeholder management, presentation, and documentation skills
- Ability to work independently across multiple applications, teams, portfolios, and technology stacks
- Strong problem-solving mindset — balances security, usability, operational impact, and business objectives
- Collaboration and influence — negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders
- Coaching and knowledge sharing — champions a security-first culture
- Comfortable operating within Scrum/Agile delivery and managing own work items
Cybersecurity Engineer Responsibilities:
- Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams
- Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
- Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity
- Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio
- Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends
- Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and ‘must-win’ business outcomes
Typical task breakdown:
- Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impact
- Daily: manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review
- Daily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closure
- Weekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defects
- Weekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controls
- Monthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvement
- Ongoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks
Required Skills for the Cybersecurity Engineer:
- 5-7 years of hands-on application security/DevSecOps experience
- Secure SDLC, DevSecOps, Agile, and Scrum methodologies — strong working understanding
- Security tooling: Burp Suite, GitHub Advanced Security, CodeQL, SAST, SCA, secret scanning, dependency analysis, and CI/CD security tooling
- Ability to read, analyze, test, and modify production application code in Java, Python, to validate security findings and support remediation efforts
- OWASP Top 10, API Security Top 10, authentication/authorization controls, secure coding principles, and common attack techniques
- Cloud security, identity and access management, and modern application architectures
- Safe and effective use of AI-assisted development and security tools
- Vulnerability triage and validation — exploitability, business impact, severity, compensating controls, and remediation guidance
- Security metrics, coverage reporting, and executive dashboard development
- Excellent communication, stakeholder management, presentation, and documentation skills
- Ability to work independently across multiple applications, teams, portfolios, and technology stacks
- Strong problem-solving mindset — balances security, usability, operational impact, and business objectives
- Collaboration and influence — negotiates priorities and removes blockers with architects, developers, DevOps, product owners, and business stakeholders
- Coaching and knowledge sharing — champions a security-first culture
- Comfortable operating within Scrum/Agile delivery and managing own work items
Cybersecurity Engineer Responsibilities:
- Embeds application security into the SDLC by defining and improving security processes, standards, workflows, and Definition of Done criteria used by delivery teams
- Performs AI-assisted and traditional security assessments of applications, APIs, cloud workloads, repositories, and supporting infrastructure
- Manages repository scanning coverage — source code analysis, secret scanning, dependency analysis, and infrastructure review — and triages findings by exploitability, business impact, and severity
- Drives remediation from discovery through verified closure, and reduces security debt, dependency vulnerabilities, and software supply chain exposure across the application portfolio
- Builds security metrics, coverage reporting, and executive dashboards that give leadership visibility into remediation status and security posture trends
- Champions a security-first culture through coaching, knowledge sharing, and documented best practices, helping application teams hit security objectives and ‘must-win’ business outcomes
Typical task breakdown:
- Daily: review and triage new security findings from SAST, SCA, secret scanning, and dependency analysis; validate exploitability and prioritize by business impact
- Daily: manual validation and security testing using Burp Suite, browser developer tools, API testing platforms, and secure code review
- Daily/Weekly: drive remediation — create and groom backlog items, assign ownership, retest fixes, collect evidence, and verify closure
- Weekly: participate in Scrum ceremonies (stand-up, backlog refinement, sprint planning, review) and maintain Agile work items, user stories, tasks, and defects
- Weekly: partner with application teams on code fixes, configuration changes, infrastructure updates, and compensating controls
- Monthly/Ongoing: security assessments of applications, APIs, and cloud workloads; metrics, coverage reporting, and executive dashboards; process and standards improvement
- Ongoing: use AI tooling responsibly to accelerate analysis, threat modeling, code review, and documentation within governance controls; track emerging threats and AI-related security risks
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
- Dice Id: 91164342
- Position Id: 946-36890-1788270452
- Posted 2 hours ago
Company Info
About Goldenpick Technologies LLC
GoldenPick Technologies is a cutting-edge career search and leadership hiring firm that leverages innovative recruitment solutions to deliver exceptional talent. With over 20 years of industry expertise, we provide our clients with a high-caliber resource pool through our intelligent search and selection process. Our robust internal processes ensure precise candidate matching for current and future requirements. We prioritize client satisfaction, delivering prompt solutions with diligence, continuous feedback, and personal accountability.

Create job alert
Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs