Overview
Skills
Job Details
Job Title: Application & Cloud Security Engineer Full Stack
Location: Alameda, CA (Fully Onsite)
Duration: 6 months contract (Potential to extend)
NOTE: Biggest focus is on Cloud Security.
Focus on candidates who can bridge the gap between cloud infrastructure, application security, and development teams true full-stack security engineers who understand both how apps are built and how to secure them in the cloud. Should have a greater impact on both security posture and developer adoption of secure practices.
Key Responsibilities:
Collaboration & Communication: Collaboration with development teams and the ability to communicate complex security concepts to non-technical stakeholders
Cloud security: Design, implement, and maintain security measures across applications, cloud environments, and full stack systems.
Security testing and vulnerability management: Conduct security assessments, threat modeling, and vulnerability management for applications and cloud infrastructure. Exposure to Pen Testing, Fuzz Testing
DevSecOps: Collaborate with development teams to integrate security best practices throughout the software development lifecycle (SDLC). Exposure and/or experience with Automated Security Testing, Integrating Security into CI/CD Pipelines, or implementing IaC security best practices.
Monitor, detect, and respond to security incidents in cloud and application environments.
Compliance and regulatory requirements: Ensure compliance with industry standards and regulatory requirements, including HIPAA, GDPR, and biotech-specific guidelines. Exposure to various Security Frameworks NIST, OWASP Top 10 etc.
Develop and maintain security documentation, policies, and procedures.
Provide guidance and mentorship to engineering teams on secure coding practices and cloud architecture security.
Support DevSecOps initiatives to automate security into CI/CD pipelines.
Qualifications:
Bachelor s degree in Computer Science, Information Security, or related field (or equivalent experience).
5+ years of experience in application and cloud security with hands-on full stack expertise. Deep understanding of cloud platforms (AWS, Azure, or Google Cloud Platform) and associated security practices. Experience with secure software development, including web and API security, containers, and microservices.
Knowledge of security frameworks, tools, and protocols (OWASP, SAST/DAST, IAM, encryption, SIEM).
Strong scripting/coding skills (Python, Java, JavaScript, or similar).
Excellent problem-solving skills and ability to work collaboratively in a fast-paced biotech environment.
Familiarity with regulatory compliance in biotech or healthcare a plus.