Remote job
Security engineer
Job details
About this role
Role overview
A security engineering role partnering with client teams and internal engineering groups to design, review, and harden modern applications. The focus is on producing findings that engineers can actually act on, rather than reports that gather dust. The work spans architecture review, threat modeling, and concrete remediation guidance across a range of application stacks.
Responsibilities
- Review application designs and architectures to identify security weaknesses before and during build. - Conduct threat modeling sessions with engineering teams to surface realistic risk scenarios. - Perform code and configuration review focused on exploitable defects and hardening opportunities. - Produce actionable findings with clear remediation guidance that engineers can ship. - Partner with engineering teams across multiple client engagements to track remediation through to closure.
Requirements
- Solid experience in application security, including secure design review and code review. - Familiarity with common vulnerability classes affecting modern web and API-driven applications. - Ability to translate technical findings into prioritized, engineer-friendly remediation steps. - Comfort working alongside development teams in a collaborative, advisory capacity. - Working knowledge of authentication, authorization, data protection, and supply chain risk patterns.
Nice to have
- Background in penetration testing, red teaming, or offensive security work. - Experience with cloud security, infrastructure-as-code review, or container hardening.