Back to jobs

Security Software Engineer

We’re hiring an Information Technology Security Engineer III!

About the position

Responsible for penetration testing a variety of environments based on methodical adherence to attack-scoring frameworks. Builds, deploys, and maintains new security automation and orchestration tooling to integrate scanning and monitoring for compliance within existing pipelines. Reviews and guides internal teams in developing more secure codebases, while educating them on best practices to build a strong “security-first” culture.

Who will love this job?

  • A team steward, you are motivated to do your best work and strive to elevate the entire team
  • A creative problem solver, you are energized by roadblocks and have a knack for troubleshooting problems in stride and solving them in a calm, cool, and collected manner.
  • An efficient worker, you enjoy having multiples priorities at one time and multitask and without breaking a sweat.

What you'll do

In Depth Penetration Testing & Threat Modeling:

  • Conducts ongoing internal and 3rd party vendor penetration testing and auditing aligned with compliance and legal objectives.
  • Performs threat modeling in accordance with OWASP Top 10, MITRE ATT&CK, and similar attack-scoring frameworks.
  • Monitors, tests, and proactively reports on current threats and vulnerabilities to respective teams.
  • Researches and educates on emerging threats within similar environments and landscapes, along with offering remediation solutions for such.

Security Tooling, Automation, & Orchestration:

  • Builds, ships, and maintains various security packages to internal application codebases for automation.
  •  Identifies vulnerable dependencies across the organization and works with individual teams to resolve them.
  • Installs preventative programmatic measures to mitigate repeat vulnerability occurrences.
  • Integrates security monitoring within existing CI/CD pipelines. Works with Ansible and Jenkins a plus.
  • Builds complex regex pattern identification scripts and parsing to identify potential injection attempts.
  • Builds and integrates APIs from disparate systems for orchestrated audits and scans.

Secure-SDLC (SSDLC) Guidance, Codebase Review & Support:

  • Develops detailed security design and procedures across the enterprise to drive a standardized set of requirements and align with internal policies.
  • Leads secure-SDLC and product security maturity efforts to adopt a shift-left approach to security.
  • Conducts platform/service workload design and architecture reviews, as well as audit source code for compliance.
    Monitoring, Logging, & Reporting:
  • Parses a variety of debug logs for determining behavioral baselines to formulate granular internal policies and standards.
  • Orchestrates log ingestion into tools and tuning rulesets for advanced metrics reporting on enterprise-wide security posture.
  • Builds leaderboards and reporting interfaces on current and forecasted KPIs and risk indicators.

Other General Duties:

  • Provides product security related coaching and mentoring to elevate security expertise of development teams.
  • Takes ownership of security decisions made in the engineering organization by helping organization members make clear decisions in alignment with organizational goals, backing decisions made, and taking responsibility for their success.
  • Fosters a company-wide positive culture across by having conversations based on organizational strategy and principles to create alignment.
  • Ensures security goals are understood and continuously worked towards across the organization.
  • Takes ownership and responsibility for organizational security practices and processes and their continuous improvement.
  • Effectively handles risk, change, and uncertainty across the organization.
  • Facilitates organization-wide discussions, ensuring that everyone has an opportunity to share their opinion and be heard, and that discussion outcomes are tied to stated goals.
  • Actively advances a culture of documentation and knowledge sharing across the organization.
  • Ability to work off-hours with occasional evenings, weekends, and/or holidays.

What you need to know

  • Bachelor’s Degree in computer science or a related field or equivalent work experience.
  • 8 years experience as a Software/Security Engineer or Architect.
  • 8-10 Years of Development Experience in the following languages: Python, JS (Node, AJAX), Java, SQL, Linux Bash (or similar terminal languages), XML, YAML/JSON.
  • 3-4 years of Docker and/or k8s, Ansible, Jenkins, Terraform, and AWS/Azure preferred. Deep and current experience with AWS/Azure architectural design patterns and application.
  • Preferred Certification/ License: Any credentials from the following certification bodies: ISC2, ISACA, CompTIA, GIAC, AWS, Azure, TOGAF, SABSA.
  • Expert knowledge and experience with Kali Linux tooling (Burp, ZAP, Metasploit, sqlmap, etc).
  • Experience designing and implementing webhooks, SOAP, REST, and GraphQL APIs.
  • Expert knowledge of web application and database design, development, and integration techniques.
  • Participation in bug hunting / bug bounty communities is a plus.
  • Experience with PCI / GDPR / or CCPA a plus.
  • Knowledge and experiences with data protection concepts such as: (a) data obfuscation, anonymization, & de-identification; (b) secrets management; and (c) vault services.
  • Experience building application parameterized/prepared-statement query interfaces a plus.

About Plexus

Plexus Worldwide is a leading direct-sales company founded in Scottsdale, Arizona, where it remains a top employer and economic driver. For the past 16 years, Plexus has been focused on igniting hope, health, and happiness through its science-backed nutritional products, skincare, and an exciting home-based entrepreneurial opportunity.

As a 6-time Best Places to Work winner, the company enjoys a solid organizational culture and deeply commits to giving back to communities in need.

Our Core Values

We contribute to the overall growth and success of Plexus by embracing the Plexus core values:

  • We are One Plexus.
  • We are accountable.
  • We get the job done right.
  • We empower others.

Benefits

  • 401k program with a company match and immediate vesting.
  • Quarterly bonuses based on company profitability.
  • Weekly drawings for gift cards and cash.

Thank you for taking the time to apply for an opportunity with our One Plexus team! If you have any issues during the application process, please get in touch with us directly at careers@plexusworldwide.com.

We are committed to protecting the privacy and security of your information. Visit our Candidate Privacy Notice for additional information.

 

 

 

Apply for this job

*

indicates a required field

Resume/CV

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf

You can copy your LinkedIn URL to the answer field below.

Select...

Have you ever previously worked at Plexus?

Select...

What is your primary address?
Example:
1111 E. Phoenix Rd. Apt 11, Phoenix, AZ 85205

Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Plexus Worldwide’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.