- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 2 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
Role Overview
Join a dynamic security team focused on deeply integrating security within software engineering and product teams. This senior, hands-on position requires strong technical expertise and a collaborative approach to embed security seamlessly into modern software development processes. You will be part of a progressive technology organization in the midst of a comprehensive security transformation, influencing both routine engineering practices and the overarching security strategy.
Key Responsibilities
- Embed security best practices throughout the Software Development Lifecycle (SDLC) and DevOps processes.
- Collaborate closely with developers, architects, and platform teams to design and build secure systems.
- Implement security automation and controls within Continuous Integration/Continuous Deployment (CI/CD) pipelines.
- Conduct security-focused code reviews, testing, and offer guidance on secure coding techniques.
- Facilitate threat modeling and identify risks related to applications, APIs, and cloud infrastructure.
- Enhance security automation tools, vulnerability management, and security tooling capabilities.
- Deliver practical security advice that enables rapid and secure software delivery.
- Contribute to the organization’s broad security strategy and ongoing initiatives.
- Support security risk assessments, incident response efforts, and threat intelligence operations.
- Evaluate and integrate emerging security technologies and methodologies.
- Mentor peers and raise security expertise across the broader technology teams.
Candidate Profile
- Extensive hands-on experience in DevSecOps or application security roles.
- Proven ability to embed security within engineering, development, or product teams.
- In-depth understanding of software development concepts and credibility when working with seasoned developers and architects.
- Experience integrating security into CI/CD pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), Software Composition Analysis (SCA), and infrastructure-as-code security scanning.
- Robust knowledge of cloud security principles, preferably within Azure or other leading cloud environments.
- Familiarity with securing modern architectures such as APIs, containers, Kubernetes, and serverless platforms.
- Strong grasp of secure SDLC methodologies, threat modeling practices, and secure coding standards.
- Experience with security automation, vulnerability scanning, and security testing tools.
- Understanding of security risk management and frameworks like NIST and ISO 27001.
- Excellent communication skills, with the confidence to constructively challenge technical choices when necessary.
Additional Skills and Certifications
Experience with Microsoft security technologies such as Entra ID, Defender, Sentinel, or other Azure security services is advantageous. Certifications including CISSP, CISM, CCSP, or Azure Security Engineer Associate are preferred but not mandatory.
Why Join?
This role provides a unique opportunity to embed security at the forefront of software engineering rather than acting as a gatekeeper after decisions are made. You'll engage closely with engineering teams to influence architecture and development, supporting secure product and platform creation from the ground up. With significant transformation underway, you will address immediate technical challenges and shape the long-term security outlook. If you thrive on working near engineering, resolving complex security challenges, and enabling secure technology delivery without impeding speed, this position is ideal.