Cybersecurity Engineer
Payrate
Payrate: $83.00 - $84.00/hr.
Position’s Contributions to Work Group
As a Lead Cybersecurity Engineer, you will be responsible for understanding and contributing to Security by Design practices, secure application software development lifecycle practices, security testing and assessment, and the integration of Security with DevOps. This role is responsible for security engineering of the cloud (AWS, Azure) environments and vulnerability management of both Infrastructure as Code (IaC) and application development (SAST/DAST). Engineers will spend their time helping development teams identify and track security risks to remediation while embracing concepts of agile delivery and DevOps.
Typical Task Breakdown
- Security Defect Management - Analyzing, validating, communicating, and consulting on security defects identified by both automated and manual sources such as CodeQL, Rapid7 Web Application Security, penetration testing, bug bounty, etc.
- Engineering Consulting - Serving as a “best friend” to software engineers, architects, product owners, and leaders, providing contextually-aware guidance to help these groups make good decisions, document those decisions and resulting architectures, and navigate relevant review & approval processes (where necessary) when implementing new features and remediating existing issues.
- Tool Enablement - Enabling and monitoring automated defect detection tooling (CodeQL, Rapid7, etc.) at the repository or application level according to established process.
- Security Test Onboarding & Management - Collecting and communicating required scope and access information for penetration testing and security assurance assessments, as well as handling the output of these assessments via our Defect Management Process.
Education & Experience Required
- Bachelor’s degree in computer science or a related field with 8+ or more years in information security
- Master’s Degree must have 6+ years’ experience
Technical Skills
- Application security expertise understanding vulnerabilities and remediation solutions (OWASP, CWE/CVE, SANS 25)
- Experience with a wide variety of information security processes and principles, such as: Enterprise security architecture, Threat modeling, Vulnerability assessment, Risk analysis, Defense in depth, SDLC and product development processes, Identity and access management, API security, SCA/SAST/DAST, Cloud security experience with MS Azure and/or AWS
- Professional certification (CISSP, CCSP, GWAPT, GWEB, AWS SA / Certified Security, etc.)
- Development experience (Java, Python, .Net, JS, or equivalent)
- Implementation of automation and scripting
- AI Fluency is preferred
- Web services security
Desired
- Professional information security certification (CISSP, CCSP, CSSLP, GISCP, GWAPT, GWEB etc)
- Strong understanding and experience with information security technologies
Soft Skills
- Excellent written and verbal communications skills
- Demonstrated ability to communicate highly technical security concepts to non-security audiences
- Ability to coordinate multiple teams in accomplishing process review and improvement
Pay Transparency
Pay Transparency: The typical base pay for this role across the U.S. is: $83.00 - $84.00 /hr. Non-exempt positions are eligible for overtime at a rate of 1.5 times the base hourly rate for all hours worked in excess of 40 in a work week, or as required by state or local law. Final offer amounts, within the base pay set forth above, are determined by factors including your relevant skills, education and experience. Full-time employees are eligible to select from different benefits packages. Packages may include medical, dental, and vision benefits, health savings accounts with qualified medical plan enrollment, 10 paid days off, 3 days paid bereavement leave, 401(k) plan participation with employer match, life and disability insurance, commuter benefits, dependent care flexible spending account, accident insurance, critical illness insurance, hospital indemnity insurance, accommodations and reimbursement for work travel, and discretionary performance or recognition bonus. Sick leave and mobile phone reimbursement provided based on state or local law.
Consent to Communication and Use of AI Technology
By submitting your application for this position and providing your email address(es) and/or phone number(s), you consent to receive text (SMS), email, and/or voice communication whether automated (including auto telephone dialing systems or automatic text messaging systems), pre-recorded, AI-assisted, or individually initiated from Aditi Consulting, our agents, representatives, or affiliates at the phone number and/or email address you have provided. These communications may include information about potential opportunities and information. Message and data rates may apply. Message frequency may vary. You represent and warrant that the email address(es) and/or telephone number(s) you provided to us belong to you and that you are permitted to receive calls, text (SMS) messages, and/or emails at these contacts. You also acknowledge and agree to Aditi Consulting LLC’s use of AI technology during the sourcing process, including calls from an AI Voice Recruiter. AI is used solely to gather data and does not replace human-based decision-making in employment decisions. Calls may be recorded. Consent is not a condition of purchasing any property, goods, or services. You may revoke your consent at any time by replying “STOP” to :messages or by contacting privacy@aditiconsulting.com. For information about our collection, use, and disclosure of applicant's personal information as well as applicants' rights over their personal information, please see our Privacy Policy #AditiConsulting #26-04519