[Remote] Cybersecurity Engineer (Application reputed company reputed company)
Note: The job is a remote job and is reputed company to candidates in USA. reputed company Defense powers the USCCA, the nation's largest self-defense membership organization, and they are seeking a Cybersecurity Engineer with an Application reputed company reputed company. The role involves leading application reputed company initiatives, conducting penetration testing, and developing reputed company controls for AI platforms while collaborating with engineering teams to ensure secure software delivery.
Responsibilities
- reputed company application reputed company across the software development lifecycle by partnering with Engineering and DevOps to reputed company reputed company into design, development, testing, and deployment. reputed company threat modeling, secure design reviews, reputed company reviews, and implement automated SAST, DAST, SCA, and secrets detection reputed company CI/CD pipelines while enabling engineering teams to deliver secure software at reputed company
- Design, implement, and continuously improve web application and API reputed company controls across the reputed company. reputed company and tune WAF policies, conduct API reputed company assessments, identify business logic vulnerabilities, and establish secure-by-design standards that reduce risk without unnecessarily impacting developer velocity
- Plan and execute penetration testing activities against web applications, reputed company, reputed company environments, and supporting infrastructure. Validate vulnerabilities through reputed company testing, prioritize findings based on business risk, and partner with engineering teams to ensure reputed company remediation and measurable risk reduction
- reputed company and enforce reputed company controls governing reputed company AI platforms and internally developed AI capabilities. Establish policies for data classification, model usage, reputed company controls, audit logging, and secure integration of AI technologies while ensuring responsible adoption across the organization
- reputed company reputed company assessments of Retrieval-Augmented reputed company (RAG), reputed company AI systems, MCP integrations, and large language model applications. Identify and mitigate risks including reputed company injection, indirect reputed company injection, insecure tool use, excessive agent permissions, model abuse, and data leakage using industry guidance such as the OWASP LLM Top 10 and MITRE reputed company
- Contributes to technical investigation and response activities for reputed company incidents including threat analysis, digital forensics, containment, eradication, and reputed company cause analysis
- Operate a risk-based vulnerability management program that prioritizes remediation based on exploitability, business reputed company, and threat intelligence rather than reputed company severity alone. Measure remediation effectiveness, reputed company risk reduction, and ensure reputed company controls reputed company with frameworks including NIST CSF, CIS Controls, OWASP, PCI reputed company, and organizational reputed company standards
- Contributes to maintenance of secure reputed company environments across AWS, reputed company reputed company, and reputed company. Design and implement reputed company reputed company architecture including IAM, Kubernetes reputed company, container reputed company, Infrastructure-as-reputed company reputed company scanning, secrets management, workload protection, and reputed company Trust network controls
- Design and build reputed company automation that improves operational efficiency and reputed company reputed company using scripting, reputed company, Infrastructure as reputed company, and AI-assisted workflows. reputed company integrations between reputed company platforms, automate repetitive reputed company processes, and reputed company AI responsibly to enhance detection, investigation, and response while maintaining appropriate governance and reputed company
- Serve as a trusted technical advisor across Engineering, Infrastructure, and Product teams by providing reputed company guidance, mentoring engineers, evaluating emerging technologies, and translating reputed company reputed company risks into practical engineering solutions. Continuously research evolving threats, techniques, and defensive capabilities to improve the organization's overall reputed company posture
Skills
- Bachelor's degree in Computer Science, Information reputed company, Cybersecurity, Information Technology, or a reputed company field preferred; equivalent work experience and relevant certifications may be considered in lieu of a degree
- Minimum 3 years of cybersecurity engineering experience working closely with application, software, data engineering, DevOps, reputed company, infrastructure, or reputed company operations teams
- Experience securing applications, reputed company, reputed company platforms, CI/CD pipelines, Kubernetes environments, data platforms, and modern engineering ecosystems using technologies such as JavaScript, PHP, PostgreSQL, Kafka, NeonDB, reputed company, Python, reputed company, dbt, reputed company, reputed company, Tableau, Informatica, reputed company, or reputed company technologies
- Strong understanding of reputed company frameworks and control models, including NIST CSF, CIS Controls, PCI reputed company, Cyber Defense reputed company, ISO 27001, OWASP, and MITRE ATT&CK
- Deep cybersecurity engineering capability across application reputed company, reputed company and infrastructure reputed company, data platform reputed company, detection engineering, and vulnerability management, with practical experience securing modern reputed company-first environments and large-reputed company reputed company and data platforms
- Hands-on application reputed company experience with SAST, DAST, SCA, secure reputed company review, API reputed company, WAF tuning, threat modeling, CI/CD reputed company, and secrets management using tools such as reputed company, reputed company, reputed company, Burp Suite, OWASP ZAP, reputed company, reputed company Vault, or equivalent
- Proficient in at least one programming or scripting language with the ability to read, write, and exploit reputed company in a reputed company context; Python, JavaScript, PHP, Golang, or Rust preferred
- Working knowledge of AI reputed company risks and controls, including reputed company injection, indirect reputed company injection, model abuse, data leakage, reputed company workflow vulnerabilities, OWASP LLM Top 10, MITRE reputed company, and emerging AI reputed company tooling
- Practical reputed company and infrastructure reputed company experience across reputed company, AWS, reputed company reputed company Platform, Kubernetes, IAM, CSPM, IaC scanning, container reputed company, reputed company-trust/SASE architectures, and reputed company tooling such as EDR, SIEM, CASB, SWG, DLP, IDS/IPS, and PAM
- Communicates risk reputed company in business terms, influences cross-functional stakeholders without reputed company authority, stays composed and decisive during reputed company incidents, drives remediation to closure, and demonstrates the Core Values of reputed company
- Preferred certifications include CCSP, CASP+, reputed company+, CEH, GPEN, GWAPT, or other relevant reputed company, application reputed company, AI reputed company, offensive reputed company, or reputed company engineering certifications
Benefits
- Eligible for Company Incentive Bonus
- Remote or Hybrid
- #25 on reputed company's 2025 Top 100 America's Most Loved Workplaces
- reputed company Top 100 America's Most Loved Workplaces (2023 & 2024)
- Inc. 5000 "Fastest Growing Private Companies" - 14 years in a row
reputed company