JOBSEARCHER

Security Software Engineer

ItelDenver, COL6 LeadAugust 14th, 2026
JOB SUMMARYitel is growing and expanding our customer base and mission portfolio, we face an ever-evolving threat landscape. This position will have a direct hand and focus in making sure our applications, data, and platform are secure and always provide reliable service. As part of the InfoSec Team at itel, the Software Security Engineer will take lead on all security aspects regarding software. This includes responsibilities like:KEY RESPONSIBILITIESCollaboration with Development and Product Teams:Security Integration: Work closely with development and product teams to integrate security into the software development lifecycle (SDLC), including software designs, security tests, and code reviews. Ensure security is considered at every stage of the development process, from design to deployment. Guidance: Provide guidance and best practices for application integration into cloud environment such as AWS / Azure.The Secure Software Development Framework (SSDF): Assist in developing and enforcing a set of fundamental, sound, and secure software development processes based on established practices from NIST, OWASP, and others. (Review and Publish Release Notes)Product Security Enhancements: Collaborate with product managers to incorporate security features and enhancements into product roadmaps. Ensuring security is a key consideration in product planning and development.Design, implement, and operate the following information security programs:Secure Software Development ProgramData Protection ProgramCross-functional Coordination: Facilitate cross-functional collaboration between InfoSec, development, and product teams to address security challenges and align security goals with business objectives.Reviewing Designs and Code:Security Code Reviews: Conduct thorough security reviews, both internal and external where necessary, of application code developed by the product and development teams. Identify potential security defects and recommend necessary changes to mitigate risks.Assess current and newly developed code for security vulnerabilities using dynamic and static analysis techniques. Work with software engineering teams to fix vulnerable code by providing guidance on secure coding practices and industry best practices.Provide expertise on authentication, entitlements, identity management (SSO), data leak prevention, data protection, encryption, etc. to developers.Design and implement technology and processes to reduce the potential risk of data compromise and leakage.Design Assessments: Evaluate system designs from a security perspective, ensuring they adhere to best practices and compliance requirements. Provide feedback to development teams to enhance security measures.Collaboration with Development Teams: Work closely with developers to educate and assist them in implementing secure coding practices. Foster a culture of security awareness and continuous improvement.Other Responsibilities: Participate with Incident Response events, assist in responding, minimize the impact, conducting a technical and forensic investigation, gather and preserve evidence for potential use in the prosecution of computer crimes.Monitor, analyze, respond to and resolve security alerts, incidents, attacks or platform issues and assist in workstation, server systems and networking triage. Source, review, gain approval and implement new security solutions to better protect the organization.Understand and identify advanced cyber threats, where they can materialize within the overall enterprise given the organizations security posture and then providing strategies to defend against these threats. Provide support to Information Security team members, IT Operations and business staff as assigned and required with regards to information security activities.Assist with implementing and enforcing IT security policies and procedures across the organization.Identify, select, propose, and implement security solutions for protecting the organizations most sensitive data. Solutions may include Data Loss Prevention (DLP) systems and database monitoring and anomaly detection systems (e.g., Guardian, Imperva)Drive the evaluation of solutions, selection of technologies and enact strategic decisions based on established standards and existing architecture.Work in partnership with MSSP, MSP and other technology vendors to implement security solutions and for those solutions maintain the software, hardware, systems making up the enterprise security stack. Assist with the deployment, maintenance and support of IT security systems and applications across the enterprise. ROLE QUALIFICATIONSEDUCATION & EXPERIENCERequired Skills and ExperienceBachelor’s degree in a computer-related engineering fieldTwo to five years of progressing industry experienceAt least one language from the set {.NET, Python, C/C++, TypeScript} and one other languageMicrosoft Certified Azure Security Engineer (AZ-500) certification.Experience with AWS and Google Cloud Environments.Proficiency in Azure Sentinel for threat detection, investigation, and response.Previous security familiarity of some sort: security development, network security, cloud security, etc.Improved DevSecOps maturity levels of the overall development process.Implemented credential scanning tools like Git Guardian in the CI/CD pipeline.Integrated SAST tools such as SonarQube, SonarCloud, Fortify, Veracode, and Checkmarx into the CI/CD pipeline.Integrated SCA tools like OWASP Dependency Check, Snyk, and Black Duck into the CI/CD pipeline.Integrated container scanning tools such as Trivy and AQUA into the CI/CD pipeline.Integrated infrastructure-as-code scanning tools like Snyk and Bridgecrew into the CI/CD pipeline.Implemented security best practices for Azure cloud solutions to comply with requirements.Managed user access and identity using Azure AD, Azure AD B2C, and OAuth.Conducted risk assessments and developed mitigation strategies within the Azure environment.Integrated various security scanning tools (SAST, SCA, DAST) into the CI/CD pipeline for early vulnerability detection.Performed security testing methodologies (SAST, SCA, DAST) and analyzed false positives.Reviewed source code security before migration to cloud platformsDesired Skills and ExperienceKubernetes and container technologiesIoT or robotics technologies, including firmware, CAN architectures, and real-time operating systemsKEY COMPETENCIESResults-Oriented: ability to plan, schedule and organize professional schedule to achieve strategic goals within or ahead of established time framesAdaptability to Change: ability to be flexible and supportive, react swiftly to and able to positively and proactively assimilate change in rapid growth environmentInterpersonal Communication: ability to choose a communication behavior that is both appropriate and effective for a given situation; the ability to understand and manage your own emotions, as well as recognize and influence the emotions of othersTeam Orientation and Collaboration: ability to successfully build and maintain collaborative relationships to work effectively together as a team through shared responsibility, respect, and empathy to complete a shared goal for a common goodAccountability: ability to act with a clear sense of ownership; takes personal responsibility for decisions, actions, deliverables, and failures; establishes clear responsibilities and processes for monitoring work and measuring results; embraces experimentation, creativity, and positive changeCultural Competence: ability to understand and respect values, attitudes, beliefs, and mores of the member that differ across cultures, and to consider and respond appropriately to these differences in planning, implementing, and evaluating health programs and interventionsWORKING CONDITIONS/EQUIPMENT USEWork is performed indoors in a typical office environment - not substantially exposed to adverse environmental conditions.Must be able to lift up to fifteen (15) poundsFrequent use of office machines to include telephone, computer, and printer