{"schemaVersion":"jobsearcher.job.v1","id":"418afe1069aa9c837f7f2cf5","url":"https://jobsearcher.com/jobs/418afe1069aa9c837f7f2cf5","canonicalUrl":"https://jobsearcher.com/jobs/418afe1069aa9c837f7f2cf5","title":"Software Security Engineer","description":"JOB SUMMARY\nThis is an exempt position that reports to the VP, Chief Information Security Officer. The person in this position will assist in supporting WCF's business units with product security initiatives. They will assist in developing security standards, resiliency, security assessments, and ensuring that software development practices meet security best practices. They will help create high-quality security-focused products by providing product development teams with the necessary support, requirements validation, tools, and training. They will partner with development teams to conduct manual and automated security testing and code audits to discover vulnerabilities for internally and externally developed systems.\nQUALIFICATIONS\nBachelor's degree in computer science, or equivalent education.\n5 years of experience including 2-3 years of development experience and at least 1 year of experience in information/cyber security with an emphasis on software security (or nine years of related work experience without a degree); insurance experience preferred.\nStrong knowledge of the OWASP top 10 for Web and OWASP Top 10 for APIs.\nUnderstanding of computer networking, routing, and associated hardware.\nFamiliarity with security tooling used to support an SSDLC (SCA/SAST/DAST/container scanning).\nBackground and experience with Java and JavaScript/TypeScript frameworks. Additional skills with C#, .NET, Python are preferred.\nCertifications for Security+, Network+, GSEC, CEH, CSSLP, or willingness to obtain certifications.\nESSENTIAL JOB FUNCTIONS\nServe as an authority on application security with development and operations teams by learning and assessing new and existing WCF Insurance technologies/products from a security perspective.\nCollaborate with development teams to integrate security throughout the software development lifecycle. Ensure security testing and compliance requirements are integrated into all phases of development and providing product development teams with the necessary support, requirements validation, tools, and training.\nOversee and recommend web security technology implementations (SRI, CSP), API security and automation functions.\nAssist in penetration testing activities to identify and address security vulnerabilities including management of external/internal bug bounty and other related web vulnerability initiatives.\nDefine and implement a comprehensive application security program to protect the confidentiality, integrity, and availability of company assets available through applications.\nCreate architecture and application security documentation.\nDesign and provide system encryption, cryptography, and other security protection mechanisms and standards to be adhered to by all other programmers.\nPerform complex problem analysis and decision making to mitigate security threats.\nResearch, develop, and recommend product security requirements for applications, infrastructure, cloud, and other products.\nDesign, establish and prepare relevant, actionable security metrics.\nACCOUNTABILITY & REQUIREMENTS\nActively participate in building the information security program by evaluating and suggesting innovative solutions and ideas and championing the information security program.\nActively research, learn, and keep up with software security best practices and emerging technologies.\nSupport collaboration and knowledge sharing across the organization and build relationships between business units and key stakeholders.\nWork independently and assume IT security management with general supervision.\nDeliver excellent customer service to internal and external customers and department peers.\nDemonstrate effective organization and time-management skills.\nVALUES\nThe person in this position must demonstrate the WCF values of doing the right thing, being great at your job, and helping others succeed to fulfill the company's mission of excellence.\nWORKING CONDITIONS\nThis position is based in an office environment with adequate temperature and lighting control. There are no known hazardous or unpleasant conditions caused by noise, dust, or other environmental factors. There are potentially high-stress situations that require meeting deadlines. The employee must meet the job attendance requirements for this position.","company":"Wcfinsurance","rawCompany":"wcfinsurance","city":"Sandy","state":"UT","isRemote":false,"isActive":false,"createdAt":"2026-04-12T21:02:11.853Z","occupations":[{"code":"15-1252.00","title":"Software Developers","slug":"software-developers"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Software Security Engineer","description":"JOB SUMMARY\nThis is an exempt position that reports to the VP, Chief Information Security Officer. The person in this position will assist in supporting WCF's business units with product security initiatives. They will assist in developing security standards, resiliency, security assessments, and ensuring that software development practices meet security best practices. They will help create high-quality security-focused products by providing product development teams with the necessary support, requirements validation, tools, and training. They will partner with development teams to conduct manual and automated security testing and code audits to discover vulnerabilities for internally and externally developed systems.\nQUALIFICATIONS\nBachelor's degree in computer science, or equivalent education.\n5 years of experience including 2-3 years of development experience and at least 1 year of experience in information/cyber security with an emphasis on software security (or nine years of related work experience without a degree); insurance experience preferred.\nStrong knowledge of the OWASP top 10 for Web and OWASP Top 10 for APIs.\nUnderstanding of computer networking, routing, and associated hardware.\nFamiliarity with security tooling used to support an SSDLC (SCA/SAST/DAST/container scanning).\nBackground and experience with Java and JavaScript/TypeScript frameworks. Additional skills with C#, .NET, Python are preferred.\nCertifications for Security+, Network+, GSEC, CEH, CSSLP, or willingness to obtain certifications.\nESSENTIAL JOB FUNCTIONS\nServe as an authority on application security with development and operations teams by learning and assessing new and existing WCF Insurance technologies/products from a security perspective.\nCollaborate with development teams to integrate security throughout the software development lifecycle. Ensure security testing and compliance requirements are integrated into all phases of development and providing product development teams with the necessary support, requirements validation, tools, and training.\nOversee and recommend web security technology implementations (SRI, CSP), API security and automation functions.\nAssist in penetration testing activities to identify and address security vulnerabilities including management of external/internal bug bounty and other related web vulnerability initiatives.\nDefine and implement a comprehensive application security program to protect the confidentiality, integrity, and availability of company assets available through applications.\nCreate architecture and application security documentation.\nDesign and provide system encryption, cryptography, and other security protection mechanisms and standards to be adhered to by all other programmers.\nPerform complex problem analysis and decision making to mitigate security threats.\nResearch, develop, and recommend product security requirements for applications, infrastructure, cloud, and other products.\nDesign, establish and prepare relevant, actionable security metrics.\nACCOUNTABILITY & REQUIREMENTS\nActively participate in building the information security program by evaluating and suggesting innovative solutions and ideas and championing the information security program.\nActively research, learn, and keep up with software security best practices and emerging technologies.\nSupport collaboration and knowledge sharing across the organization and build relationships between business units and key stakeholders.\nWork independently and assume IT security management with general supervision.\nDeliver excellent customer service to internal and external customers and department peers.\nDemonstrate effective organization and time-management skills.\nVALUES\nThe person in this position must demonstrate the WCF values of doing the right thing, being great at your job, and helping others succeed to fulfill the company's mission of excellence.\nWORKING CONDITIONS\nThis position is based in an office environment with adequate temperature and lighting control. There are no known hazardous or unpleasant conditions caused by noise, dust, or other environmental factors. There are potentially high-stress situations that require meeting deadlines. The employee must meet the job attendance requirements for this position.","datePosted":"2026-04-12T21:02:11.853Z","dateModified":"2026-04-12T21:02:11.853Z","hiringOrganization":{"@type":"Organization","name":"Wcfinsurance","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Sandy","addressRegion":"UT","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"418afe1069aa9c837f7f2cf5"},"url":"https://jobsearcher.com/jobs/418afe1069aa9c837f7f2cf5"}}