xelys jobs xelys jobs

Senior Security Engineer

Jobgether

seniorsecurity United States 69 days ago via LinkedIn

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Application SecurityThreat ModelingSecure Code ReviewSecure SDLCSASTDASTSCAVulnerability ManagementCloud SecurityCI/CD Security

About the role

Role Overview

Senior Security Engineer (US-based) — a hands-on security role focused on embedding security throughout the development lifecycle. You’ll act as a technical security subject-matter expert, partnering with engineering, product, IT, and legal to define security strategy and improve defenses across applications, APIs, and infrastructure.

Responsibilities

  • Own and advance security initiatives while staying deeply involved in engineering execution
  • Define and execute security strategy, roadmap, and programs to improve overall security posture
  • Lead application security: threat modeling, secure architecture reviews, secure code reviews, and SDLC improvements
  • Establish and improve secure coding standards, vulnerability management processes, and security engineering practices
  • Implement and maintain security tooling and automation (e.g., SAST, DAST, SCA, vulnerability scanning)
  • Build security tools/automation workflows and infrastructure-as-code solutions to improve operational security
  • Implement security controls across apps, APIs, and infrastructure environments
  • Partner with engineers to improve authentication, authorization, encryption, and data protection
  • Strengthen cloud security practices (IAM, networking, secrets management, logging/monitoring)
  • Integrate security controls into CI/CD pipelines and add automated security checks
  • Support compliance initiatives (security frameworks, audits, policies, regulatory requirements)
  • Help build a security-focused culture through knowledge sharing and process enablement

Requirements

  • 7+ years of hands-on software engineering experience
  • Proven application security experience (threat modeling, secure code reviews, integrating security into SDLC)
  • Experience securing cloud environments (AWS, GCP, or Azure), including identity, networking, and infrastructure security
  • Ability to operate at both strategic and tactical levels (security direction plus implementation)
  • Strong understanding of secure software development, vulnerability management, and security architecture
  • Experience implementing security tooling (SAST, DAST, SCA, SIEM, vulnerability management platforms)
  • Strong communication skills and ability to translate security concepts into recommendations

Nice-to-haves

  • Experience with security automation and CI/CD security integration
  • Familiarity with infrastructure-as-code and scalable security tooling workflows

Scraped 7/22/2026