EngineerJobs.io
← Back to all jobs

Job Description

Delta Defense, LLC is building a modern security engineering program that spans product engineering, cloud infrastructure, and analytics teams. In this role, you will help design and evolve security controls across application and web/API security, offensive security, AI security and governance, incident response and detection, vulnerability management, and security automation.

This onsite position is based in West Bend, WI, and the target salary range is USD 100,000 - 125,000 per year. Delta Defense is seeking a cybersecurity engineer with 3+ years of experience to partner across Engineering, DevOps, Infrastructure, and Product.

Responsibilities

  • Lead application security throughout the software development lifecycle by partnering with Engineering and DevOps to integrate security into design, development, testing, and deployment.
  • Conduct threat modeling, secure design reviews, and code reviews, and implement automated SAST, DAST, SCA, and secrets detection in CI/CD pipelines.
  • Design, implement, and continuously improve web application and API security controls across the enterprise.
  • Develop and tune WAF policies, perform API security assessments, identify business logic vulnerabilities, and define secure-by-design standards that reduce risk without unnecessarily slowing developer velocity.
  • Plan and execute penetration testing against web applications, APIs, cloud environments, and supporting infrastructure.
  • Validate vulnerabilities through manual testing, prioritize findings by business risk, and work with engineering teams to ensure timely remediation and measurable risk reduction.
  • Develop and enforce security controls governing enterprise AI platforms and internally developed AI capabilities.
  • Establish policies for data classification, model usage, access controls, audit logging, and secure AI integrations to support responsible adoption.
  • Perform security assessments of Retrieval-Augmented Generation (RAG), agentic AI systems, MCP integrations, and large language model applications.
  • Identify and mitigate AI and application risks including prompt injection, indirect prompt injection, insecure tool use, excessive agent permissions, model abuse, and data leakage using guidance such as OWASP LLM Top 10 and MITRE ATLAS.
  • Support security incident investigation and response, including threat analysis, digital forensics, containment, eradication, and root cause analysis.
  • Operate a risk-based vulnerability management program that prioritizes remediation based on exploitability, business impact, and threat intelligence rather than scanner severity alone.
  • Measure remediation effectiveness, track risk reduction, and ensure alignment to frameworks including NIST CSF, CIS Controls, OWASP, PCI DSS, and organizational security standards.
  • Help maintain secure cloud environments across AWS, Google Cloud, and DigitalOcean.
  • Design and implement cloud security architecture covering IAM, Kubernetes security, container security, Infrastructure-as-Code security scanning, secrets management, workload protection, and Zero Trust network controls.
  • Build security automation to improve operational efficiency and security outcomes using scripting, APIs, Infrastructure as Code, and AI-assisted workflows.
  • Develop integrations between security platforms, automate repetitive security processes, and use AI responsibly to enhance detection, investigation, and response while maintaining governance and oversight.
  • Serve as a trusted technical advisor across Engineering, Infrastructure, and Product teams by providing security guidance, mentoring engineers, evaluating emerging technologies, and translating security risks into practical engineering solutions.
  • Continuously research evolving threats, techniques, and defensive capabilities to improve the organization’s security posture.

Requirements

  • Deep cybersecurity engineering capability across application security, cloud and infrastructure security, data platform security, detection engineering, and vulnerability management, with practical experience securing modern cloud-first environments and large-scale SaaS and data platforms.
  • Hands-on application security experience with SAST, DAST, SCA, secure code review, API security, WAF tuning, threat modeling, CI/CD security, and secrets management using tools such as Doppler, Semgrep, Snyk, Burp Suite, OWASP ZAP, Cloudflare, HashiCorp Vault, or equivalents.
  • Proficiency in at least one programming or scripting language and the ability to read, write, and exploit code in a security context; Python, JavaScript, PHP, Golang, or Rust preferred.
  • Working knowledge of AI security risks and controls including prompt injection, indirect prompt injection, model abuse, data leakage, agentic workflow vulnerabilities, OWASP LLM Top 10, MITRE ATLAS, and emerging AI security tooling.
  • Practical cloud and infrastructure security experience across DigitalOcean, AWS, GCP, Kubernetes, IAM, CSPM, IaC scanning, container security, zero-trust/SASE architectures, and security tooling such as EDR, SIEM, CASB, SWG, DLP, IDS/IPS, and PAM.
  • Ability to communicate risk clearly in business terms, influence cross-functional stakeholders without direct authority, and stay decisive during active incidents while driving remediation to closure and demonstrating Delta Defense’s core values.
  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Information Technology, or a related field preferred; equivalent work experience and relevant certifications may be considered in lieu of a degree.
  • Minimum 3 years of cybersecurity engineering experience working closely with application, software, data engineering, DevOps, cloud, infrastructure, or security operations teams.
  • Experience securing applications, APIs, cloud platforms, CI/CD pipelines, Kubernetes environments, data platforms, and modern engineering ecosystems using technologies such as JavaScript, PHP, PostgreSQL, Kafka, NeonDB, GitLab, Python, Snowflake, dbt, Fivetran, Databricks, Tableau, Informatica, Kestra, or related technologies.
  • Strong understanding of security frameworks and control models including NIST CSF, CIS Controls, PCI DSS, Cyber Defense Matrix, ISO 27001, OWASP, and MITRE ATT&CK.
  • Preferred certifications include CCSP, CASP+, Security+, CEH, GPEN, GWAPT, or other relevant cloud, application security, AI security, offensive security, or security engineering certifications.
  • Must be authorized to work in the United States without current or future sponsorship.

Benefits

  • Target Salary Range: $100,000 - $125,000
  • Eligible for Company Incentive Bonus

Working Conditions

  • Remote or Hybrid

Learn more & apply: https://www.deltadefense.com/careers

Similar Jobs