*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))] dir=auto data-turn-id=request-WEB:4298153a-1fd0-4d8c-9ddf-b0b5951c8ff2-12 data-turn-id-container=request-WEB:4298153a-1fd0-4d8c-9ddf-b0b5951c8ff2-12 data-testid=conversation-turn-26 data-turn=assistant>Software Security Engineer – Engineer 3 | W2 Opportunity – C2C candidates are not eligible.
For this role, we need candidates with 9+ years of experience only.
Position Overview
We are seeking a Software Security Engineer to help ensure the security of software products throughout the development lifecycle. This role will partner closely with Product, Software Development, Architecture, DevOps, and Cybersecurity teams to integrate security tools and practices into development processes and ensure compliance with industry standards and regulations.
Key Responsibilities
- Perform security plan reviews and secure code reviews for flagship services, products, and partner applications.
- Guide development teams in triaging and remediating findings from SAST, DAST, SCA, bug bounty programs, and vulnerability assessments.
- Develop automation scripts and tools to identify and remediate security vulnerabilities.
- Act as a security advocate within development teams and promote secure software development practices.
- Integrate security throughout the SDLC and CI/CD pipelines in collaboration with Software Architects, Developers, and DevOps teams.
- Provide guidance on secure architecture, API security, IAM, logging, encryption, data protection, and secure coding practices across Azure, Google Cloud Platform, and AWS environments.
- Define and maintain security best practices based on current threats and vulnerabilities.
- Ensure access controls, data encryption, and data anonymization requirements are followed.
- Partner with Incident Response teams during security incidents and incorporate lessons learned into product and system hardening.
- Work with engineering teams to ensure vulnerabilities are addressed within established SLAs.
- Support software supply-chain security, SBOM requirements, technical debt, and upgrade planning.
- Maintain security requirements, test plans, and other cybersecurity documentation.
- Support cybersecurity compliance activities, risk assessments, and related security requirements.
- Communicate complex technical risks clearly to both technical and business stakeholders.
Required Skills
- Cybersecurity / Application Security
- Software Development and Secure SDLC
- Scripting and Automation
- Web Applications and Web Technologies
- TCP/IP and Network Fundamentals
- Software Development Lifecycle
- Troubleshooting and Problem Solving
- Data Integrity and Data Modeling
- Security Vulnerability Remediation
- Experience working with Developers and DevOps teams
- Proficiency in at least two programming languages, or advanced proficiency in one
- Strong communication and analytical skills
Preferred Skills
Experience with:
- Java, JavaScript, Python
- Spring Security, Spring Boot
- Linux
- React
- REST / API Security
- IAM
- Cloud Computing
- Azure, Google Cloud Platform, AWS
- Burp Suite
- Dynatrace
- Salesforce
- Pega
- Apache Tomcat
- Penetration Testing
- Network Security
- Risk Management
- ISO 27001
- Configuration Management
- Security Compliance
Experience & Qualifications
- Engineer 3 level
- 6+ years of IT experience
- 4+ years of software development experience
- Practical experience with two coding languages or advanced practical experience in one
- Experience in Application Security, Cybersecurity, or Secure Software Development preferred
- Experience supporting cybersecurity compliance activities is a plus
- CISSP, CISA, CISM, or similar certifications are highly valued
Education
- Bachelor’s degree required
- Master’s degree preferred
Ideal Candidate
The ideal candidate will have broad experience across software development, cybersecurity, cloud, DevOps, and IT. This role is well suited for a technical professional who can bridge the gap between software development and security.
The successful candidate should be comfortable translating security risks into practical solutions, helping developers remediate vulnerabilities, automating security processes, and supporting cybersecurity compliance activities.
Keywords
Application Security | Cybersecurity | Secure SDLC | Software Security | DevSecOps | SAST | DAST | SCA | Vulnerability Management | Cloud Security | AWS | Azure | Google Cloud Platform | API Security | IAM | Python | Java | JavaScript | Spring Boot | Spring Security | DevOps | CI/CD | Penetration Testing | Network Security | ISO 27001 | SBOM