Senior Security Engineer


Tixy Services LLC
Dice Job Match Score™
🔢 Crunching numbers...
Job Details
Skills
- Agentic AI
- OWASP
- ISO/IEC 27001:2005
- Vulnerability Management
- SIEM
- Security Engineering
- Amazon Web Services
- HIPAA
- OIDC
- OAuth
- OSCP
Summary
Job Title: Security Engineer
- JD: The Security Engineer designs and implements controls that protect customer applications, cloud environments, and data.
- The Mid Security Engineer owns security workstreams end-to-end: threat modeling on new services, hardening cloud infrastructure, integrating security tooling into CI/CD pipelines, tuning detection, and leading remediation work with developers and platform teams. They translate security requirements into engineering work and operate as a trusted technical contributor inside delivery teams.
- **Core Responsibilities**
- - Conduct threat modeling and security design reviews on new and existing applications and services.
- - Mid: Owns threat models for assigned services and translates findings into actionable engineering tickets.
- - Design and implement IAM, encryption, network, and logging controls in cloud environments (AWS, Azure, Google Cloud Platform).
- - Mid: Builds reusable IAM, KMS, and network security patterns in infrastructure-as-code.
- - Integrate and tune security tooling (SAST, DAST, SCA, secret scanning, IaC scanning, CSPM) in CI/CD pipelines.
- - Mid: Owns tool configuration, false-positive tuning, and policy-as-code rule development.
- - Build and tune detection content in SIEM and cloud-native security tools; participate in incident response.
- - Mid: Authors detection rules, writes runbooks, and leads triage on routine security incidents.
- - Lead vulnerability management and remediation work across application, infrastructure, and container environments.
- - Mid: Owns the remediation backlog and partners with engineering teams on prioritization and fixes.
- - Map controls compliance frameworks (SOC 2, HIPAA, PCI, ISO 27001, NIST) and support audit evidence collection.
- - Mid: Maintains control mappings and produces audit-ready evidence for assigned scope.
- - Collaborate with developers, platform engineers, and architects to embed security into delivery practices.
- - Mid: Pairs with engineering teams, runs secure-coding sessions, and influences design decisions early.
- - Use agentic AI tools (e.g., Claude, Cursor, GitHub Copilot, Coco, or similar) in real delivery work, following and the client's agentic AI operating model and usage guidelines.
- - Mid: Independently incorporates agentic AI tools into day-to-day delivery work, follows and client's operating model for responsible use (review, validation, disclosure where required), and can speak to where they've caught or corrected AI-introduced errors.
- **Experience**
- - Mid: 4-7 years owning security engineering work across cloud, application, and infrastructure domains
- - Experience designing and implementing IAM, encryption, network, and logging controls in AWS, Azure, or Google Cloud Platform
- - Experience integrating security tooling (SAST, DAST, SCA, IaC scanning, CSPM) into CI/CD pipelines
- - Experience leading threat modeling and security design reviews
- - Experience contributing to incident response, detection engineering, and vulnerability management
- - Hands-on experience using agentic AI tools in real delivery work, evaluated on demonstrated proficiency and judgment rather than tenure
- **Skills**
- - Strong cloud security expertise in AWS, Azure, or Google Cloud Platform (IAM, KMS, VPC, Security Hub/Defender/SCC)
- - Application security expertise (OWASP Top 10, secure coding, threat modeling, secure SDLC)
- - Deep familiarity with vulnerability management (Wiz, Prisma Cloud, Tenable, Qualys) and SAST/DAST/SCA tools (Snyk, Checkmarx, Veracode, Semgrep)
- - Infrastructure-as-code (Terraform, CloudFormation, Bicep) with IaC security scanning (Checkov, tfsec)
- - Container and Kubernetes security (image scanning, admission controllers, network policies, RBAC)
- - Detection engineering and SIEM content (Splunk, Sentinel, Chronicle) including KQL/SPL/YARA-L
- - Identity protocols (OAuth2, OIDC, SAML) and IdP configuration (Okta, Entra ID, Auth0)
- - Scripting in Python, Bash, or PowerShell for automation and tooling
- - Understanding of compliance frameworks (SOC 2, HIPAA, PCI, ISO 27001, NIST CSF, FedRAMP) and ability to map controls
- - Incident response participation including triage, investigation, and post-incident reviews
- - Strong communication skills for working with developers and platform teams
- **Delivery Methods**
- - Agile or hybrid project delivery models
- - Leads security workstreams within sprint cadence and partners with engineering teams on remediation
- **Tools**
- AWS, Azure, Google Cloud Platform, Wiz or Prisma Cloud, Snyk or Checkmarx, Splunk or Sentinel, Terraform, Checkov or tfsec, Burp Suite, Nessus or Qualys, Okta or Entra ID, GitHub or GitLab, JIRA or ADO, AI Tools (Claude, Cursor, GitHub Copilot)
- **Certifications (Preferred)**
- AWS Certified Security — Specialty, Azure SC-200/SC-100, Google Cloud Platform Professional Cloud Security Engineer, CISSP (in progress acceptable), OSCP, CKS
- Dice Id: 91173297
- Position Id: 9086165
- Posted 2 hours ago
Company Info
About Tixy Services LLC
Tixy Tech is a reputable consulting and staffing firm that operates across the nation, committed to delivering exceptional resources to cater to our clients' diverse hiring needs in technology, assessment, management, logistics, and accounting/finance.
We specialize in offering comprehensive solutions to address various corporate challenges such as organizational transformations, headcount limitations, budgetary constraints, fundamental shifts in core business operations, staff augmentation requirements, and mergers/acquisitions.
Our primary objective is to provide top-notch consultants who excel at completing your projects within the designated timelines and budgetary limits. With our experienced sales and recruitment team, we make it a priority to thoroughly comprehend your business direction, technical prerequisites, and unique organizational culture. This deep understanding allows us to allocate the best available resources to fulfill your organization's staff augmentation needs effectively.


Similar Jobs
It looks like there aren't any Similar Jobs for this job yet.
Search all similar jobs