Назад
Company hidden
6 часов назад

Security Engineer, Application

77 800 - 117 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer, Application (Application Security/DevSecOps): Supporting secure application development across physical datacenters and cloud environments with an accent on vulnerability scanning, application security testing, threat modeling, and risk reduction. Focus on operating security tools, partnering with development teams on remediation, reviewing CI/CD security, and improving security metrics and compliance.

Location: Hybrid role based in Richmond or Lynchburg, Virginia, with in-office days on Tuesday, Wednesday, and Thursday. Core working hours target 9am–5pm EST.

Salary: $77,800–$117,000 annually, plus eligibility for a performance-based bonus incentive.

Company

hirify.global/CareScout provides guidance, products, and services that help families navigate aging and long-term care.

What you will do

  • Operate and maintain application vulnerability scanning tools, Application Security Testing platforms, and cloud security technologies.
  • Partner with development teams and business stakeholders to identify vulnerabilities and support remediation.
  • Support security investigations, vulnerability triage, CI/CD security reviews, and remediation tracking.
  • Participate in security assessments, threat modeling, risk reduction initiatives, and security tool evaluations.
  • Generate application security reports, dashboards, metrics, Key Risk Indicators, and security scorecards.
  • Support security governance, compliance reviews, documentation, and secure software development lifecycle improvements.

Requirements

  • 3+ years of experience in a security engineering role, including application security, DevSecOps, and cloud security.
  • Experience with vulnerability scanning technologies, AST platforms, cloud security tooling, threat modeling, penetration testing, and web application assessment.
  • Cloud experience with AWS, Azure, or GCP, plus Infrastructure as Code and Policy as Code concepts.
  • Experience implementing secure software development lifecycle programs and automating repetitive tasks.
  • Knowledge of risk assessment, technical security controls, and frameworks including SOC 2, ISO 27001, and NIST 800-53.
  • Experience assessing compliance involving HIPAA, PHI, PII, and PCI regulations, with scripting or programming experience in languages such as Python, JavaScript, PowerShell, Bash, Java, .NET, Ruby, PHP, Perl, C#, or HTML.

Culture & Benefits

  • Healthcare coverage, disability, life, and long-term care insurance.
  • 401(k) savings options and an employer-funded retirement account feature.
  • Paid time off, 12 paid holidays, volunteer time off, and paid family leave.
  • Tuition reimbursement, student loan repayment, and training and certification support.
  • Wellness, caregiver, mental health, financial, and legal support resources.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →