Jobs · Information Technology · Michigan

Software Security Engineer

Stefanini Group · Dearborn, MI · 1 wk ago
On-siteInformation TechnologyFull-time

Stefanini Group is a global provider of IT digital consulting, systems integration, application, and strategic staffing services to Fortune 1000 enterprises. Our presence spans the Americas, Europe, Africa, and Asia, serving over four hundred clients across industries such as financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. We are a CMM Level 5 company.

About the role

The Software Security Engineer will translate security risks into practical solutions, support vulnerability remediation, automate security processes, and contribute to compliance initiatives across software development, cybersecurity, cloud, DevOps, and IT.

Responsibilities

  • Perform security plan reviews and secure code reviews for flagship services, products, and partner applications.
  • Guide development teams in triaging and remediating findings from SAST, DAST, SCA, bug bounty programs, and vulnerability assessments.
  • Develop automation scripts and tools to help identify and remediate security vulnerabilities.
  • Serve as a security advocate within development teams and promote secure software development practices.
  • Collaborate with software architects, developers, and DevOps teams to integrate security throughout the SDLC and CI/CD pipelines.
  • Provide guidance on secure architecture, API security, IAM, logging, encryption, data protection, and secure coding practices across Azure, GCP, and AWS environments.
  • Define and maintain security best practices based on current threats and vulnerabilities.
  • Ensure access controls, data encryption, and data anonymization requirements are followed.
  • Partner with incident response teams during security incidents and incorporate lessons learned into product and system hardening.
  • Work with engineering teams to ensure security vulnerabilities are addressed within established SLAs.
  • Support software supply-chain security, SBOM requirements, technical debt, and upgrade planning.
  • Maintain security requirements, test plans, and other cybersecurity documentation.
  • Support cybersecurity compliance activities, risk assessments, and related security requirements.
  • Communicate complex technical risks clearly to both technical and business stakeholders.

Requirements

  • 6+ years of IT experience.
  • 4+ years of software development experience.
  • Practical experience in two coding languages or advanced practical experience in one.
  • Experience with application security, cybersecurity, or secure software development (preferred).
  • Experience supporting cybersecurity compliance activities (a plus).
  • CISSP, CISA, CISM, or similar certifications (highly valued).
  • Bachelor’s degree (required).
  • Master’s degree (preferred).

Skills

  • Cybersecurity / Application Security
  • Software Development and Secure SDLC
  • Scripting and automation
  • Web applications and web technologies
  • TCP/IP and network fundamentals
  • Software development lifecycle
  • Troubleshooting and problem solving
  • Data integrity and data modeling
  • Security vulnerability remediation
  • Experience working with developers and DevOps teams
  • Experience with at least two programming languages, or advanced proficiency in one
  • Strong communication and analytical skills

Preferred Skills

  • Java, JavaScript, Python
  • Spring Security, Spring Boot, Linux, React
  • REST/API security, IAM
  • Cloud computing (Azure, GCP, AWS)
  • Burp Suite, Dynatrace, Salesforce, Pega
  • Apache Tomcat
  • Penetration testing, network security
  • Risk management, ISO 27001
  • Configuration management, security compliance

Similar jobs