We are seeking a Security Engineer with strong experience in application security, vulnerability management, and security risk assessments.
We need someone with strong hands-on product security experience with a deeper background in threat modeling, secure design reviews, and working directly with engineering teams on remediation
.
This role will partner closely with engineering, DevOps, product teams, and third-party vendors to identify, prioritize, and remediate security risks across the software development lifecycl
e.
The position is expected to be a long term contract and could also turn into a permanent job down the ro
ad.
Sorry No 3rd parties and No sponsorship availa
ble.
The job is expected to be remote and based out of California but any time zone i
s ok.
The ideal candidate has hands-on experience with security posture management platforms such as ArmorCode, understands modern application security practices, and is comfortable leveraging AI-assisted threat modeling to improve security design and risk analysis. This role combines technical security expertise with excellent communication and project management skills to drive security improvements across the organiz
ation.
Vulnerability & Security Findings Man
- agementManage application security findings across SAST, DAST, SCA, container, infrastructure, and cloud security
- tools.Utilize ArmorCode (or similar Application Security Posture Management platforms) to aggregate, prioritize, and track security vulnerabi
- lities.Coordinate remediation efforts with software engineering teams from identification through validation and c
- losure.Perform risk-based prioritization of security findings using business context, exploitability, and asset criti
- cality.Develop dashboards and metrics to measure remediation effectiveness, SLA compliance, and security program ma
turity.Threat Modeling & Secure
- DesignLead application threat modeling sessions during software design and architecture r
- eviews.Utilize AI-assisted threat modeling tools and AI agents to accelerate identification of attack paths, abuse cases, and mitigation stra
- tegies.Partner with development teams to integrate secure design principles into th
- e SDLC.Document security requirements and recommend technical controls to reduce applicatio
n risk.Third-Party Security Asse
- ssmentsConduct security assessments of third-party vendors, SaaS providers, and strategic pa
- rtners.Review security questionnaires, SOC reports, penetration testing results, certifications, and compliance documen
- tation.Evaluate vendor security controls and identify residual
- risks.Work with procurement, legal, and business stakeholders to communicate security recommendations and risk acceptance dec
isions.Security Risk Man
- agementPerform security risk assessments for new technologies, cloud services, APIs, and enterprise applic
- ations.Assist with exception management and remediation pl
- anning.Maintain risk registers and provide recommendations for reducing organizationa
- l risk.Support audit activities and evidence collection for compliance initi
atives.Collaboration & Continuous Impr
- ovementWork closely with development, DevOps, infrastructure, cloud, and architecture
- teams.Develop security guidance, standards, and best pra
- ctices.Support security awareness initiatives related to secure devel
- opment.Identify opportunities to automate security workflows using scripting, APIs, and AI techno
logies.
Required Qualif
- icationsBachelor's degree in Computer Science, Cybersecurity, Information Systems, or equivalent exp
- erience.5-7+ years of experience in Application Security, Security Engineering, or Security Ope
- rations.Experience with ArmorCode, or similar Application Security Posture Management (ASPM) pl
- atforms.Experience managing vulnerability remediation programs across multiple engineerin
- g teams.Strong understan
- ding of:Secure Software Development Lifecycle
- (SSDLC)OWAS
- P Top 10Common Weakness Enumerati
- on (CWE)CVSS
- scoringVulnerability management best p
- racticesExperience conducting threat modeling using methodologies such as STRIDE, PASTA, or ATT
- &CK.Familiarity with AI-assisted security analysis and threat modelin
- g tools.Experience performing third-party/vendor security asse
- ssments.Excellent written and verbal communication
- skills.Ability to translate technical risks into business-focused recommen
dations.