Remote Junior Cloud & Application Security Engineer
About the jobStopAHack.com® is seeking a Junior Cloud & Application Security Engineer with hands-on experience using Wiz, Socket Security, and Vanta. This role is designed for an early-career security professional who can monitor findings, perform initial investigations, support remediation, maintain security tooling, and work with engineering and compliance teams.Who we areStopAHack.com® is a veteran-founded cybersecurity and technology services company and a Great Place To Work® certified employer. We deliver hands-on expertise to client programs and partner-led engagements.The roleYou will support day-to-day cloud, application, and compliance security operations using Wiz, Socket Security, and Vanta. You will triage security findings, investigate cloud and dependency risks, monitor compliance tests, maintain integrations, document issues, and coordinate remediation with cloud, development, IT, and security teams. This is a hands-on junior engineering role with guidance from senior security professionals.What you will doMonitor and triage cloud security findings in Wiz.Investigate misconfigurations, vulnerabilities, exposed resources, identity risks, secrets, and attack paths.Help validate findings and prioritize remediation based on severity, exposure, and business impact.Support Wiz policies, controls, dashboards, reports, integrations, and exceptions.Review Socket Security alerts involving open-source dependencies, package behavior, malware, typosquatting, install scripts, and other software supply-chain risks.Work with developers to investigate dependency alerts and determine whether packages should be approved, updated, replaced, or removed.Monitor Socket findings in GitHub pull requests and assist with repository onboarding and configuration.Monitor Vanta compliance tests, integrations, controls, evidence, access reviews, and remediation tasks.Investigate failed Vanta tests and work with system owners to collect evidence or correct security control deficiencies.Support frameworks such as SOC 2, ISO 27001, HIPAA, PCI DSS, or comparable security and compliance standards.Create and track remediation tickets in Jira, ServiceNow, or another ticketing platform.Maintain clear investigation notes, operating procedures, and audit-ready documentation.Work with security, cloud, DevOps, engineering, IT, and compliance stakeholders.Escalate high-risk, complex, or potentially exploitable findings to senior engineers.What you bring (must-have)Approximately 1 to 3 years of professional experience in cybersecurity, cloud security, application security, DevSecOps, vulnerability management, compliance operations, or a related area.Hands-on professional experience using Wiz, Socket Security, and Vanta.Ability to navigate each platform, review alerts or failed checks, gather supporting evidence, and track remediation.Foundational knowledge of at least one major cloud platform: AWS, Microsoft Azure, or Google Cloud Platform.Understanding of cloud security risks involving identity, permissions, networking, storage, logging, encryption, vulnerabilities, and exposed resources.Familiarity with GitHub, pull requests, package manifests, open-source dependencies, and software supply-chain risks.Familiarity with compliance controls, automated tests, evidence collection, and audit preparation.Experience documenting findings and communicating remediation requirements to technical teams.Ability to distinguish legitimate risks from false positives and escalate issues when necessary.Strong attention to detail, troubleshooting ability, and willingness to learn.Nice to haveExperience with more than one of AWS, Azure, and GCP.Familiarity with Wiz Security Graph, attack paths, policies, and cloud integrations.Experience with Socket’s GitHub application, CLI, alerts, or repository configuration.Experience maintaining Vanta integrations or supporting SOC 2 or ISO 27001 readiness.Familiarity with Jira, ServiceNow, GitHub Issues, Slack, or Microsoft Teams.Basic experience with Python, PowerShell, Bash, APIs, JSON, or YAML.Familiarity with Terraform or other infrastructure-as-code technologies.CompTIA Security+, AWS, Microsoft Azure, Google Cloud, or similar certifications.Associate’s or bachelor’s degree in cybersecurity, information technology, computer science, or a related field. Equivalent professional experience may be considered.Reporting and supervisionWork under the direction of senior security engineers, architects, or security program leadership.Coordinate daily activities with assigned security, cloud, development, and compliance teams.Escalate complex technical decisions and high-risk findings to senior personnel.Receive performance management and HR support from StopAHack.Work model and hoursRemote within the United States.Standard business hours aligned with the assigned team.Occasional schedule flexibility may be required for meetings, remediation activities, or urgent security findings.Work authorizationApplicants must be authorized to work in the United States without current or future sponsorship.Hiring processStopAHack recruiter screening.Technical interview covering Wiz, Socket Security, and Vanta.Practical or scenario-based security discussion.Customer or program alignment interview, if applicable.Background and onboarding requirements applicable to the assignment.EEO and accessibilityStopAHack.com® is an Equal Opportunity Employer. We consider all applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other legally protected status. If you require a reasonable accommodation during the application or interview process, contact info@stopahack.com