xelys jobs xelys jobs

Security Engineer

DFND Security, Inc.

full-remoteseniorcontractsecuritybackend United States 3 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Application SecurityVulnerability ManagementThreat ModelingSecure Design ReviewsArmorCodeApplication Security Posture Management (ASPM)SSDLCOWASP Top 10CWECVSS

About the role

Security Engineer (Application/Product Security)

Role Overview

You will drive security improvements across the software development lifecycle by partnering with engineering, DevOps, product, and third-party vendors. The role focuses on application security, vulnerability management, threat modeling, and security risk assessments, with hands-on work and strong communication/project management responsibilities.

Responsibilities

  • Vulnerability & Security Findings Management
    • Manage application security findings across SAST, DAST, SCA, container, infrastructure, and cloud security tools.
    • Use ArmorCode (or similar ASPM) to aggregate, prioritize, and track vulnerabilities.
    • Coordinate remediation from identification through validation and closure with engineering teams.
    • Prioritize findings using business context, exploitability, and asset criticality.
    • Build dashboards/metrics for remediation effectiveness, SLA compliance, and security program maturity.
  • Threat Modeling & Secure Design
    • Lead threat modeling sessions during design/architecture reviews.
    • Use AI-assisted threat modeling tools/AI agents to accelerate attack path and abuse-case identification and mitigations.
    • Partner with development teams to integrate secure design principles into the SDLC.
    • Document security requirements and recommend technical controls.
  • Third-Party Security Assessments
    • Assess vendor/security posture for SaaS and strategic partners.
    • Review SOC reports, pen test results, certifications, compliance documentation, and security questionnaires.
    • Identify residual risks and communicate recommendations and risk acceptance decisions with stakeholders.
  • Security Risk Management
    • Perform risk assessments for new technologies, cloud services, APIs, and enterprise apps.
    • Support exception management and remediation planning.
    • Maintain risk registers and prepare evidence for audits/compliance initiatives.
  • Collaboration & Continuous Improvement
    • Create security guidance/standards/best practices.
    • Support secure development awareness.
    • Identify opportunities to automate security workflows using scripting, APIs, and AI.

Required Qualifications

  • 5–7+ years experience in Application Security, Security Engineering, or Security Operations.
  • Bachelor’s degree in Computer Science/Cybersecurity/Information Systems (or equivalent experience).
  • Experience with ArmorCode or similar Application Security Posture Management (ASPM) platforms.
  • Experience running vulnerability remediation programs across multiple engineering teams.
  • Strong knowledge of:
    • SSDLC (Secure Software Development Lifecycle)
    • OWASP Top 10
    • CWE (Common Weakness Enumeration)
    • CVSS scoring
    • Vulnerability management best practices

Nice-to-Haves / Additional Signals

  • Hands-on product security experience.
  • Deep background in threat modeling and secure design reviews.
  • Experience assessing third-party vendors and communicating risk decisions.

Contract & Location

  • Long-term contract, with potential to convert to permanent.
  • Remote, based out of California (but any time zone ok).
  • No 3rd parties and no sponsorship.

Scraped 8/2/2026