Security Engineer
DFND Security, Inc.
full-remoteseniorcontractsecuritybackend United States 3 days ago via LinkedIn
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
Application SecurityVulnerability ManagementThreat ModelingSecure Design ReviewsArmorCodeApplication Security Posture Management (ASPM)SSDLCOWASP Top 10CWECVSS
About the role
Security Engineer (Application/Product Security)
Role Overview
You will drive security improvements across the software development lifecycle by partnering with engineering, DevOps, product, and third-party vendors. The role focuses on application security, vulnerability management, threat modeling, and security risk assessments, with hands-on work and strong communication/project management responsibilities.
Responsibilities
- Vulnerability & Security Findings Management
- Manage application security findings across SAST, DAST, SCA, container, infrastructure, and cloud security tools.
- Use ArmorCode (or similar ASPM) to aggregate, prioritize, and track vulnerabilities.
- Coordinate remediation from identification through validation and closure with engineering teams.
- Prioritize findings using business context, exploitability, and asset criticality.
- Build dashboards/metrics for remediation effectiveness, SLA compliance, and security program maturity.
- Threat Modeling & Secure Design
- Lead threat modeling sessions during design/architecture reviews.
- Use AI-assisted threat modeling tools/AI agents to accelerate attack path and abuse-case identification and mitigations.
- Partner with development teams to integrate secure design principles into the SDLC.
- Document security requirements and recommend technical controls.
- Third-Party Security Assessments
- Assess vendor/security posture for SaaS and strategic partners.
- Review SOC reports, pen test results, certifications, compliance documentation, and security questionnaires.
- Identify residual risks and communicate recommendations and risk acceptance decisions with stakeholders.
- Security Risk Management
- Perform risk assessments for new technologies, cloud services, APIs, and enterprise apps.
- Support exception management and remediation planning.
- Maintain risk registers and prepare evidence for audits/compliance initiatives.
- Collaboration & Continuous Improvement
- Create security guidance/standards/best practices.
- Support secure development awareness.
- Identify opportunities to automate security workflows using scripting, APIs, and AI.
Required Qualifications
- 5–7+ years experience in Application Security, Security Engineering, or Security Operations.
- Bachelor’s degree in Computer Science/Cybersecurity/Information Systems (or equivalent experience).
- Experience with ArmorCode or similar Application Security Posture Management (ASPM) platforms.
- Experience running vulnerability remediation programs across multiple engineering teams.
- Strong knowledge of:
- SSDLC (Secure Software Development Lifecycle)
- OWASP Top 10
- CWE (Common Weakness Enumeration)
- CVSS scoring
- Vulnerability management best practices
Nice-to-Haves / Additional Signals
- Hands-on product security experience.
- Deep background in threat modeling and secure design reviews.
- Experience assessing third-party vendors and communicating risk decisions.
Contract & Location
- Long-term contract, with potential to convert to permanent.
- Remote, based out of California (but any time zone ok).
- No 3rd parties and no sponsorship.
Scraped 8/2/2026