EngineerJobs.io
← Back to all jobs

Job Description

Own application security across physical datacenter and cloud environments, driving vulnerability management, threat modeling, and security tooling automation.

Responsibilities

  • Manage and support application vulnerability scanning technologies, AST platforms, and cloud security tooling
  • Partner with business stakeholders to design secure applications and test for security weaknesses
  • Collaborate on remediation of identified issues and respond to information security concerns
  • Coordinate orchestration, automation, and day-to-day management of security technologies and platforms
  • Support life cycle management activities including threat assessment, threat modeling, and risk avoidance
  • Produce actionable reporting that shows direct impact to the organization’s security posture
  • Define and implement security effectiveness measures using Key Risk Indicators (KRIs) and security scorecards
  • Serve as a subject-matter-expert for Application Security and a key contact for critical issues and security risk assessments
  • Triage and support CI/CD security issues with internal partners and stakeholders
  • Evaluate business and technical needs to select tools, processes, and technologies that improve security across environments
  • Continuously improve compliance processes

Requirements

  • 5+ years of experience
  • Computer Science or a similar degree
  • Experience using vulnerability scanning technologies, AST platforms, and cloud security tooling
  • Formal experience with threat modeling
  • Ability to assess and prioritize risk with an attacker mindset to inform threat models
  • Cloud experience: AWS, Azure, or GCP
  • Understanding of Infrastructure as Code (IaaC) and Policy as Code (PaC) concepts
  • Experience implementing secure Software Development Lifecycle programs
  • Familiarity with technical security controls, guidelines, and frameworks including SOC2, ISO 27001, and NIST 800-53
  • Experience with project delivery through direct and indirect leadership
  • Ability to automate repetitive tasks and build code solutions
  • Scripting or programming experience: Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, Bash
  • Penetration testing and web application assessment experience
  • Experience assessing software compliance with HIPAA, PHI, PII, and PCI regulations

Technologies

  • AWS, Azure, GCP
  • Infrastructure as Code (IaaC), Policy as Code (PaC)
  • Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript
  • PowerShell, Bash
  • SOC2, ISO 27001, NIST 800-53
  • HIPAA, PCI
  • CI/CD

Compensation

  • USD 96,700 - 145,000 per year (national range)
  • Eligible for a bonus incentive plan

Benefits

  • Competitive Compensation & Total Rewards Incentives
  • Comprehensive Healthcare Coverage
  • Multiple 401(k) Savings Plan Options
  • Auto Enrollment in Employer-Directed Retirement Account Feature (100% employer-funded)
  • Generous Paid Time Off, including 12 paid holidays, Volunteer Time Off, and Paid Family Leave
  • Disability, Life, and Long Term Care Insurance
  • Tuition Reimbursement, Student Loan Repayment, and Training & Certification Support
  • Wellness support including gym membership reimbursement and Employee Assistance Program resources
  • Caregiver and Mental Health Support Services

Location & Schedule

  • Richmond, VA (Hybrid)
  • Hybrid schedule requires Remote and In-Office days
  • In-office days: Tuesday, Wednesday, and Thursday
  • Working hours target: 9am-5pm EST

Additional Location Information

  • In-office applicants: Richmond or Lynchburg, Virginia

Disclaimer

  • Role aligned to a national market-based pay range; actual compensation varies by geography, experience, skills, and other job-related factors
  • Bonus incentive plan eligibility depends on individual and company performance and is not guaranteed

Similar Jobs