Cybersecurity Engineer

Chicago, IL, US • Posted 1 day ago • Updated 1 day ago
Contract Independent
Contract W2
12 Months
Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Microsoft Azure
  • Defect Management
  • DevOps
  • Fluency
  • Cloud Computing
  • Computer Science
  • Cyber Security
  • Application Development
  • CISSP
  • Cisco Certifications
  • .NET
  • Accountability
  • Agile
  • Amazon Web Services
  • OWASP
  • Onboarding
  • SANS
  • Security Engineering
  • Penetration Testing
  • Product Development
  • Information Security
  • Software Security
  • Security QA
  • Soft Skills
  • Software Development
  • Java
  • JavaScript
  • Web Application Security
  • Management
  • Python
  • Vulnerability Management
  • Web Services

Summary

Position’s Contributions to Work Group: 
As a Lead Cybersecurity Engineer, you will be responsible for understanding and contributing to Security by Design practices, secure application software development lifecycle practices, security testing and assessment, and the integration of Security with DevOps.  This role is responsible for security engineering of the cloud (AWS, Azure) environments and vulnerability management of both Infrastructure as Code (IaC) and application development (SAST/DAST).  Engineers will spend their time helping development teams identify and track security risks to remediation while embracing concepts of agile delivery and DevOps.

Typical task breakdown:

  • Security Defect Management - Analyzing, validating, communicating, and consulting on security defects identified by both automated and manual sources such as CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty, etc. In other words, our security engineers are partners to software engineers who require accurate information on why a vulnerability exists and what they can do about it. 
  • Engineering Consulting – Serving as a “best friend” to software engineers, architects, product owners, and leaders, provide contextually-aware guidance to help these groups make good decisions, document · those decisions and resulting architectures, and navigate relevant review & approval processes (where necessary) when implementing new features and remediating existing issues. 
  • Tool Enablement - Enabling and monitoring automated defect detection tooling (CodeQL, Rapid7, etc.) at the repository or application level according to established process. 
  • Security Test Onboarding & Management – Collecting and communicating required scope and access information for penetration testing and security assurance assessments, as well as handling the output of these assessments via our Defect Management Process. 

Interaction with team: 

  • Accountable for a dedicated set of applications to work directly with development teams.  Part of a larger security engineering team that sets standards and ways of working for interacting with development teams.
  • Security Engineers will help development teams identify security gaps in their applications and services and assist in coming up with solutions to close those gaps and make services compliant to enterprise security requirements.

Education & Experience Required:

  • Bachelor’s degree in computer science or a related field with 8+ or more years in information security
  • Master’s Degree must have 6+ years’ experience

Required Technical Skills 

  • Application security expertise understanding vulnerabilities and remediation solutions (OWASP, CWE/CVE, SANS 25)
  • Experience with a wide variety of information security processes and principles, such as:
  • Enterprise security architecture
  • Threat modeling
  • Vulnerability assessment
  • Risk analysis
  • Defense in depth
  • SDLC and product development processes
  • Identity and access management
  • API security
  • SCA/SAST/DAST
  • Cloud security experience with MS Azure and/or AWS
  • Professional certification (CISSP, CCSP, GWAPT, GWEB, AWS SA / Certified Security, etc.)
  • Development experience (Java, Python, .Net, JS, or equivalent)
  • Implementation of automation and scripting
  • AI Fluency is preferred.

Desired: Web services security Desired: Professional information security certification (CISSP, CCSP, CSSLP, GISCP, GWAPT, GWEB etc) ; Strong understanding and experience with information security technologies

Required Soft Skills:

  • Excellent written and verbal communications skills; demonstrated ability to communicate highly technical security concepts to non-security audiences 
  • Ability to coordinate multiple teams in accomplishing process review and improvement

Disqualifiers/Red Flags:

  • Choppy tenure/ consistent job hoping.
  • If candidate is not local to one of the above office locations, we will not consider them for this role at this time.  
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10481525
  • Position Id: 9061317
  • Posted 1 day ago
Contact the job poster
AP

Alex Pesci

Seasoned Recruiting Manager with a Passion for Talent Acquisition @ Shiro Technologies
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Chicago, Illinois

Today

Full-time

Chicago, Illinois

Today

Full-time

USD 27.00 - 42.00 per hour

Chicago, Illinois

Today

Full-time

USD 168,000.00 per year

Hybrid in Bloomingdale, Illinois

Today

Easy Apply

Full-time

$150,000 - $195,000

Search all similar jobs