We're looking for a Security Engineer focused on designing and building scalable technical solutions. This mid level role requires 5+ years of relevant experience.
About the role
Vulnerability & Threat Management: Proven ability to perform vulnerability assessments and run penetration tests, interpret the results, and prioritize remediation efforts. Experience with threat modeling and threat intelligence is also key.
Cloud Security: Working knowledge of securing Google Cloud (and AWS, Azure). This includes identity and access management (IAM), GKE, and Cloud Armor, logging, and data protection in the cloud.
Scripting and Automation: Proficiency in scripting language (e.g., Python, GoLang, or Bash) to automate security tasks, analyze logs, and develop custom tools.
Kubernetes and Container Hardenin g: Expertise in securing GKE cluster components, including leveraging native features like Pod Security Standards (PSS) enforcement, and Network Policies to control Pod-to-Pod traffic and runtime security observability.
AppSec Security: Integrating security checks (SAST/DAST, dependency scanning, SCA) into CI/CD pipelines, and hardening build infrastructure and workflows.
Strong oral and written communication skills, ideally experience writing technical documentation and specifications.
Some experience with cryptographic keys, KMS, HSMs
3-7 years of experience in IT and application security.
Bachelor’s Degree Cyber Security, Computer Science or related field.
Based in the NY/NJ/CT tri-state area
As a Security Engineer, you will have the opportunity to shape our security posture in many domains including; application security, vulnerability management, IAM, cloud and network security, incident response, digital forensics, DevSecOps, etc.
Participate in and, in some cases, lead security incident response efforts, including initial containment, investigation, forensic analysis, and post-incident reporting.
Contribute to the secure design and architecture of new and existing systems, ensuring security is integrated from the start (Security by Design).
Participate in fostering a DevSecOps culture in the company
Collaborate with other teams to facilitate adoption of security processes and tooling