Security Engineer
Contract Remote RoleThe Security Engineer designs and implements controls that protect customer applications, cloud environments, and data.The Security Engineer owns security workstreams end-to-end: threat modeling on new services, hardening cloud infrastructure, integrating security tooling into CI/CD pipelines, tuning detection, and leading remediation work with developers and platform teams. They translate security requirements into engineering work and operate as a trusted technical contributor inside delivery teams.**Core Responsibilities**Conduct threat modeling and security design reviews on new and existing applications and services.Design and implement IAM, encryption, network, and logging controls in cloud environments (AWS, Azure, GCP).Integrate and tune security tooling (SAST, DAST, SCA, secret scanning, IaC scanning, CSPM) in CI/CD pipelines.Build and tune detection content in SIEM and cloud-native security tools; participate in incident response.Lead vulnerability management and remediation work across application, infrastructure, and container environments.Map controls to compliance frameworks (SOC 2, HIPAA, PCI, ISO 27001, NIST) and support audit evidence collection.Collaborate with developers, platform engineers, and architects to embed security into delivery practices.Use agentic AI tools (e.g., Claude, Cursor, GitHub Copilot, Coco, or similar) in real delivery work, following the client's agentic AI operating model and usage guidelines.**Experience**4-7 years owning security engineering work across cloud, application, and infrastructure domainsExperience designing and implementing IAM, encryption, network, and logging controls in AWS, Azure, or GCPExperience integrating security tooling (SAST, DAST, SCA, IaC scanning, CSPM) into CI/CD pipelinesExperience leading threat modeling and security design reviewsExperience contributing to incident response, detection engineering, and vulnerability managementHands-on experience using agentic AI tools in real delivery work, evaluated on demonstrated proficiency and judgment rather than tenure**Skills**Strong cloud security expertise in AWS, Azure, or GCP (IAM, KMS, VPC, Security Hub/Defender/SCC)Application security expertise (OWASP Top 10, secure coding, threat modeling, secure SDLC)Deep familiarity with vulnerability management (Wiz, Prisma Cloud, Tenable, Qualys) and SAST/DAST/SCA tools (Snyk, Checkmarx, Veracode, Semgrep)Infrastructure-as-code (Terraform, CloudFormation, Bicep) with IaC security scanning (Checkov, tfsec)Container and Kubernetes security (image scanning, admission controllers, network policies, RBAC)Detection engineering and SIEM content (Splunk, Sentinel, Chronicle) including KQL/SPL/YARA-LIdentity protocols (OAuth2, OIDC, SAML) and IdP configuration (Okta, Entra ID, Auth0)Scripting in Python, Bash, or PowerShell for automation and toolingUnderstanding of compliance frameworks (SOC 2, HIPAA, PCI, ISO 27001, NIST CSF, FedRAMP) and ability to map controlsIncident response participation including triage, investigation, and post-incident reviewsStrong communication skills for working with developers and platform teams**Delivery Methods**Agile or hybrid project delivery modelsLeads security workstreams within sprint cadence and partners with engineering teams on remediation**Certifications (Preferred)**AWS Certified Security — Specialty, Azure SC-200/SC-100, GCP Professional Cloud Security Engineer, CISSP (in progress acceptable), OSCP, CKS