Cyber Security Engineer
About The Company
Delta Defense is a leading organization dedicated to empowering responsible American gun owners through its flagship platform, the USCCA®. As the nation's largest self-defense membership organization, Delta Defense is committed to protecting life, freedom, and financial security. The company operates at the intersection of security, technology, and community, providing its members with trusted resources, innovative products, and comprehensive support. With a focus on integrity, discipline, and excellence, Delta Defense fosters a dynamic environment where security professionals can thrive. The organization values innovation, collaboration, and a relentless pursuit of excellence to ensure the safety and confidence of its members and stakeholders.
About The Role
We are seeking a highly skilled Cybersecurity Engineer with a focus on Application Security to join our Information Security team. In this role, you will be instrumental in designing, implementing, and maintaining security controls across our software development lifecycle, cloud infrastructure, and enterprise applications. Your expertise will help safeguard our critical data, platforms, and member information by integrating security best practices into our engineering processes. You will work closely with product, engineering, and DevOps teams to embed security into the development process, perform proactive threat assessments, and lead offensive security initiatives. Your work will directly contribute to our mission of protecting life, freedom, and financial security, ensuring our systems are resilient against evolving threats. This position offers an exciting opportunity to influence security architecture, develop automation solutions, and serve as a trusted advisor across multiple technical domains, all while working in a fast-paced, innovative environment that values proactive security and continuous improvement.
Qualifications
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field (or equivalent work experience)
- Minimum of 3 years of cybersecurity engineering experience with a focus on application security, cloud security, and infrastructure security
- Hands-on experience with SAST, DAST, SCA, secure code review, and API security tools such as Semgrep, Snyk, Burp Suite, OWASP ZAP, and Cloudflare
- Proficiency in at least one programming or scripting language including Python, JavaScript, PHP, Golang, or Rust
- Knowledge of AI security risks, including prompt injection, model abuse, data leakage, and related controls, with familiarity with OWASP LLM Top 10 and MITRE ATLAS
- Experience with cloud platforms such as AWS, GCP, DigitalOcean, and container orchestration tools like Kubernetes
- Understanding of security frameworks including NIST CSF, CIS Controls, PCI DSS, ISO 27001, and MITRE ATT&CK
- Relevant certifications such as CCSP, CASP+, Security+, CEH, or GWAPT are preferred
- Excellent communication skills with the ability to translate technical risks into business language
- Strong analytical, problem-solving, and decision-making abilities
Responsibilities
- Lead application security initiatives throughout the software development lifecycle by collaborating with engineering and DevOps teams to embed security into design, development, testing, and deployment processes
- Perform threat modeling, secure design reviews, code reviews, and implement automated security testing (SAST, DAST, SCA, secrets detection) within CI/CD pipelines
- Design, implement, and refine web application and API security controls, including WAF policies and API security assessments, ensuring secure-by-design standards
- Plan and execute penetration testing activities on web applications, APIs, cloud environments, and supporting infrastructure to identify and remediate vulnerabilities
- Develop and enforce security controls for enterprise AI platforms, including data classification, access controls, audit logging, and secure integration practices
- Conduct security assessments of AI systems such as Retrieval-Augmented Generation (RAG), agentic AI, and large language models, identifying risks like prompt injection and model abuse
- Contribute to incident response activities, including threat analysis, digital forensics, containment, and root cause investigations
- Manage vulnerability programs by prioritizing remediation efforts based on exploitability, business impact, and threat intelligence, ensuring compliance with security standards
- Maintain and enhance cloud security architecture across AWS, GCP, and DigitalOcean, including IAM, container security, Infrastructure-as-Code security scanning, and Zero Trust models
- Design and develop security automation solutions using scripting, APIs, and AI-assisted workflows to improve operational efficiency and security outcomes
- Serve as a trusted security advisor to engineering, infrastructure, and product teams, providing guidance, mentorship, and strategic security recommendations
- Stay informed on emerging security threats, innovative defense techniques, and evolving industry standards to continuously enhance our security posture
Benefits
- Competitive salary within the range of $100,000 to $125,000, commensurate with experience
- Eligible for company incentive bonus
- Flexible work arrangements including remote or hybrid options
- Comprehensive health, dental, and vision insurance plans
- Paid time off and holidays
- Professional development opportunities and certification reimbursement
- Collaborative and innovative work environment
- Access to cutting-edge security tools and technologies
- Engagement in meaningful work that directly impacts member safety and security