JOBSEARCHER

Software Security Engineer

Software Security EngineerThis position is responsible for ensuring the security of software products throughout the development lifecycle. The engineer will partner with product, software development, architecture, DevOps, and cybersecurity teams to integrate security tools and practices into development processes while ensuring compliance with industry standards and regulations.Key ResponsibilitiesPerform security plan reviews and secure code reviews for flagship services, products, and partner applications.Guide development teams in triaging and remediating findings from SAST, DAST, SCA, bug bounty programs, and vulnerability assessments.Develop automation scripts and tools to help identify and remediate security vulnerabilities.Serve as a security advocate within development teams and promote secure software development practices.Collaborate with software architects, developers, and DevOps teams to integrate security throughout the SDLC and CI/CD pipelines.Provide guidance on secure architecture, API security, IAM, logging, encryption, data protection, and secure coding practices across Azure, GCP, and AWS environments.Define and maintain security best practices based on current threats and vulnerabilities.Ensure access controls, data encryption, and data anonymization requirements are followed.Partner with incident response teams during security incidents and incorporate lessons learned into product and system hardening.Work with engineering teams to ensure security vulnerabilities are addressed within established SLAs.Support software supply-chain security, SBOM requirements, technical debt, and upgrade planning.Maintain security requirements, test plans, and other cybersecurity documentation.Support cybersecurity compliance activities, risk assessments, and related security requirements.Communicate complex technical risks clearly to both technical and business stakeholders.Required SkillsCybersecurity / Application SecuritySoftware Development and Secure SDLCScripting and automationWeb applications and web technologiesTCP/IP and network fundamentalsSoftware development lifecycleTroubleshooting and problem solvingData integrity and data modelingSecurity vulnerability remediationExperience working with developers and DevOps teamsExperience with at least two programming languages, or advanced proficiency in oneStrong communication and analytical skillsPreferred SkillsExperience with Java, JavaScript, Python, Spring Security, Spring Boot, Linux, React, REST/API security, IAM, cloud computing, Azure, GCP, AWS, Burp Suite, Dynatrace, Salesforce, Pega, Apache Tomcat, penetration testing, network security, risk management, ISO 27001, configuration management, and security compliance.ExperienceEngineer 3 level6+ years of IT experience4+ years of software development experiencePractical experience in two coding languages or advanced practical experience in oneExperience with application security, cybersecurity, or secure software development preferredExperience supporting cybersecurity compliance activities is a plusCISSP, CISA, CISM, or similar certifications are highly valuedEducationBachelor's degree requiredMaster's degree preferredIdeal CandidateThe ideal candidate will have broad experience across software development, cybersecurity, cloud, DevOps, and IT. This role is well suited for a technical “jack of all trades” who can understand development and security while working closely with engineering teams. The candidate should be comfortable translating security risks into practical solutions, helping developers remediate vulnerabilities, automating security processes, and supporting cybersecurity compliance activities.