We are seeking a highly skilled Senior Cybersecurity Engineer to join our dynamic cybersecurity team. This is a hands-on role focused on building, automating, and securing our cloud-based SaaS infrastructure and products. The ideal candidate will have a strong background in both application and cloud security, with a passion for designing and implementing robust security solutions to protect our systems, data, and services from evolving threats.
Responsibilities
- Secure Software Development: Champion security throughout the entire software development lifecycle (SDLC). Conduct threat modeling, perform code analysis (SAST), and integrate security tools into CI/CD pipelines to identify and remediate vulnerabilities early.
- Cloud Security Architecture: Collaborate with DevOps to enhance and maintain the security of our existing cloud environment (AWS, Azure, GCP). Continuously identify opportunities to strengthen security controls across infrastructure, platforms, and services—covering network, container, and serverless technologies. Provide input and guidance to shape future cloud security designs and best practices.
- Security Automation & Orchestration: Develop and deploy automation scripts, tools, and workflows to streamline security operations. Automate incident response, threat hunting, compliance checks, and remediation processes.
- Vulnerability Management & Penetration Testing: Proactively identify and mitigate security weaknesses by conducting dynamic application security testing (DAST), infrastructure vulnerability scanning, and coordinating penetration tests.
- Data Protection & Encryption: Implement and manage data protection controls, including data loss prevention (DLP) and encryption. Manage key management services (KMS) to secure data at rest and in transit.
- Security Monitoring & Incident Response Engineering: Implement and fine-tune security monitoring tools (SIEM, CSPM) to detect and alert on security incidents. Develop and maintain automated incident response playbooks to enable rapid mitigation of threats.
Requirements
- Education: Bachelor's or Master's degree in Information Security, Computer Science, or a related field, or equivalent professional experience.
- Experience: 5+ years of hands-on experience in cybersecurity, with a deep focus on application security, cloud security, and secure software development.
- Technical Skills:
- Expert knowledge of web application vulnerabilities (OWASP Top 10) and secure coding practices.
- Hands-on experience with security tools such as SAST, DAST, IAST, and CSPM.
- Proven experience securing cloud platforms (AWS, Azure, or GCP) and their native security services.
- Proficiency in one or more programming/scripting languages (e.g., Python, Go, Java, JavaScript).
- Frameworks & Compliance: Experience implementing and auditing technical controls for security frameworks such as SOC 2, NIST, and ISO 27001.
- Certifications (Preferred): Relevant security certifications are a strong plus (e.g., CCSK, CCSP, CSSLP, GWAPT, or cloud-specific security certs).
- Soft Skills: Strong analytical and problem-solving skills, with the ability to communicate complex technical concepts to a variety of audiences.