EngineerJobs.io
← Back to all jobs

Job Description

RainFocus is seeking a mid-level, autonomous Security Engineer to protect its digital assets, infrastructure, and application ecosystem. The role connects IT operations, software development, and risk management through vulnerability management, secure development support, incident handling, and oversight of endpoint and security tools.

Responsibilities

  • Own the vulnerability management program end-to-end, including continuous vulnerability scanning using Tenable and software composition analysis and code dependencies using Sonarqube.
  • Drive remediation across teams and replicate or validate findings using tools such as Burp Suite and Kali Linux.
  • Manage and triage the crowdsourced BugCrowd bug bounty program and monitor external security posture using Bitsight.
  • Serve as the security voice in developer architecture meetings by partnering with engineering teams on dependency review, threat modeling for new features, and secure coding practices.
  • Perform system impact analyses for proposed changes and represent security on the Change Control Board (CCB).
  • Lead threat modeling sessions for new systems, features, and infrastructure changes.
  • Triage and document security incidents in OneTrust and Jira, collaborating with DevOps to ensure security tools are deployed correctly across AWS environments and endpoint configurations.
  • Maintain read-only and audit oversight for endpoint detection and response, MDM, and email security tooling including Sophos, JAMF, and BetterCloud to support compliance and active alerting.
  • Administer security awareness learning modules using RF Academy and support internal initiatives that keep security top-of-mind for all employees.

Requirements

  • All candidates must be a US citizen.
  • 3 to 5 years of dedicated experience in a technical cybersecurity role (for example, Security Engineer, AppSec Engineer, or Senior Security Analyst).
  • Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure code dependencies (SCA).
  • Proven experience running enterprise vulnerability scanners, interpreting results, and driving remediation across cross-functional teams.
  • Foundational knowledge of cloud environments, specifically AWS, and securing cloud-native applications.
  • Excellent collaboration skills, including the ability to align with software developers on sprint goals and support secure fixes without disrupting delivery.

Technology Stack

Tenable, Sonarqube, Burp Suite, Kali Linux, BugCrowd, Bitsight, OneTrust, Jira, AWS, Sophos, JAMF, BetterCloud, RF Academy, OWASP Top 10, SCA, PCI-DSS, ISO 27001, SOC 2, CompTIA Security+, CEH, GIAC, CISSP, Python, PowerShell, Bash.

Preferred Experience

  • Direct familiarity with the role’s specific tool stack, including Burp Suite, Kali Linux, BugCrowd, and Sonarqube; Tenable, Bitsight, and OneTrust; and Jira, AWS, Sophos, JAMF, PDQ, and BetterCloud.
  • CompTIA Security+, CEH, GIAC, or progress toward a CISSP (or other relevant certifications).
  • Basic scripting ability with Python, PowerShell, or Bash to automate repetitive security tasks or support log analysis.
  • Experience supporting compliance with PCI-DSS, ISO 27001, and SOC 2 frameworks.
  • Experience using AI to improve productivity and efficiency, including reviewing AI tools, integrations, and features.

Success Measures

  • Decrease time-to-remediation for vulnerabilities identified by Tenable and BugCrowd.
  • Contribute actively to developer sprint and architecture cycles, helping reduce security defects reaching production.
  • Track, document, and resolve incidents efficiently within OneTrust.
  • Reduce the number of security incidents and vulnerabilities.
  • Deliver timely and effective incident response and resolution.
  • Ensure security policies and procedures are implemented and followed.
  • Receive positive feedback from internal teams on security awareness and training programs.
  • Complete security audits and compliance assessments successfully.

Benefits

  • Competitive salaries
  • Competitive benefits
  • 401k
  • Generous PTO
  • Countless other team building activities

Role Location

Lehi, UT (remote)

Why Work at RainFocus

RainFocus supports large-scale events by delivering better insights, experiences, and marketing. The company pivoted its product and services offering in 2020 to continue growing and serving new clients and events. Team members can experience first-hand the impact of the platform at events around the world.

Similar Jobs