Lead Engineer, Information Security (Application Security)

RXO

Charlotte (NC)

Hybrid

USD 140,000 - 190,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health plans
401(k)
Pre-tax accounts
Insurance
EAP
Development programs
Paid time off

Job summary

RXO is seeking a Lead Engineer, Application Security to fortify and scale our security program across a multi-cloud environment. You’ll drive secure architecture, integrate security into the SDLC, and partner with engineering teams to remediate risks in modern cloud-native apps.

Based at RXO’s Charlotte headquarters with a four-day onsite schedule and remote Fridays, you’ll mentor developers, lead security reviews, and advance our security posture across Azure, GCP, and OCI.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
  • 3+ years in Application Security, Security Engineering, DevSecOps, or a related discipline.
  • Experience identifying and remediating security vulnerabilities within application code and software environments.
  • Experience with Akamai App & API Protector, F5 Advanced WAF, or similar WAF platforms.
  • Experience securing cloud-native workloads in Azure, GCP, and OCI.
  • Experience with CI/CD security integrations.

Responsibilities

  • Lead the development and governance of application security standards, secure architecture principles, and threat modeling.
  • Conduct security assessments and threat modeling for emerging technologies including AI/LLMs.
  • Analyze and tune WAF configurations and review logs; implement approved rule exceptions.
  • Integrate and optimize SAST, DAST, and SCA within CI/CD pipelines and DevSecOps.
  • Partner with engineering teams to remediate vulnerabilities and guide secure coding.
  • Lead security awareness initiatives and mentor developers.
  • Perform application security reviews, risk identification, and remediation tracking.
  • Evaluate cloud-native apps across Azure, GCP, and OCI to ensure security standards.
  • Support security controls within development pipelines to prevent risky deployments.
  • Drive continuous improvements to security processes and tooling.

Skills

Application Security
Security Engineering
DevSecOps
Threat Modeling
WAF Configuration
CI/CD Security
Cloud Security
Azure
GCP
OCI
Docker
Kubernetes
OWASP Top 10
Secure Coding

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering

Tools

Akamai App & API Protector
F5 Advanced WAF
SAST
DAST
SCA
Terraform
Ansible
Bicep

Job description

Accelerate your career at RXO

RXO is a leading provider of transportation solutions. With cutting-edge technology at the center, we're revolutionizing the industry with our massive network and commitment to finding solutions for every challenge. We create more efficient ways for shippers and carriers to transport goods across North America.

At RXO, we're looking for a Lead Engineer, Application Security to help strengthen and scale our application security program across a multi-cloud environment. In this role, you'll serve as a senior individual contributor responsible for driving secure application architecture, integrating security into the software development lifecycle, and partnering closely with engineering teams to identify and remediate security risks. You'll play a key role in securing modern cloud-native applications, supporting AI initiatives, and advancing our overall security posture.

This position is based out of RXO headquarters located at 11215 N Community House Road, Charlotte, NC 28277 and follows a four-day onsite work schedule Monday through Thursday, with remote work on Fridays.

What your day-to-day will look like:
  • Lead the development and governance of application security standards, secure architecture principles, and threat modeling practices across the enterprise.

  • Conduct security assessments and threat modeling for emerging technologies, including Agentic AI solutions, Large Language Models (LLMs), and autonomous AI workflows.

  • Analyze and tune Web Application Firewall (WAF) configurations, including reviewing F5 and Akamai logs, investigating anomalies, and implementing approved rule exceptions.

  • Integrate and optimize automated security tools, including SAST, DAST, and Software Composition Analysis (SCA), within CI/CD pipelines and DevSecOps processes.

  • Partner with software engineering teams to identify vulnerabilities and provide code-level remediation guidance aligned with secure coding best practices.

  • Lead and support security awareness initiatives, including mentoring developers and facilitating Security Champion programs across engineering teams.

  • Perform application security reviews and contribute to risk identification, vulnerability management, remediation tracking, and reporting efforts.

  • Evaluate cloud-native applications and services across Azure, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI) environments to ensure adherence to security standards.

  • Support the implementation of security controls within development pipelines, including mechanisms to prevent deployments with unresolved critical or high-risk vulnerabilities.

  • Drive continuous improvement initiatives to enhance application security processes, tooling, and developer enablement.

At a minimum, you'll need:
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent combination of education and experience.

  • 3+ years of experience in Application Security, Security Engineering, DevSecOps, or a related cybersecurity discipline.

  • Experience identifying and remediating security vulnerabilities within application code and software development environments.

  • Experience working with enterprise WAF platforms such as Akamai App & API Protector, F5 Advanced WAF, or similar technologies.

  • Experience securing cloud-native workloads and applications within Azure, GCP, and/or OCI environments.

  • Experience with container technologies, including Docker and Kubernetes.

  • Experience integrating security tools into CI/CD pipelines and development workflows.

  • Knowledge of OWASP Top 10, Common Weakness Enumeration (CWE), secure API design principles, and application security best practices.

  • Strong analytical, problem-solving, and communication skills with the ability to collaborate across technical teams.

It'd be great if you also have:
  • Experience securing AI-enabled applications, LLM-based solutions, or autonomous agent workflows.

  • Experience reviewing and securing Infrastructure as Code (IaC) technologies such as Terraform, Ansible, or Bicep.

  • Microsoft Certified: Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, CISSP, CSSLP, CASE, GWEB, or related security certifications.

  • Experience with Akamai and/or F5 security platforms in large-scale enterprise environments.

  • Experience leading Security Champion programs or mentoring engineering teams on secure development practices.

  • Ability to influence cross-functional teams and drive security improvements through collaboration and technical expertise.

  • Experience developing scalable security frameworks that support innovation while managing enterprise risk.

Why Join Us:
Our Benefits
  • Comprehensive medical, dental, and vision plans

  • 401(k) retirement plan with up to 5% company match

  • Pre-tax accounts to help streamline eligible expenses

  • Company-paid disability and life insurance

  • Employee Assistance Program (EAP)

  • Career and Leadership Development Programs

  • Paid time off, company holidays, and volunteer days

Our Culture

Our values are the key to our unique culture and our ability to deliver for everyone we serve.

We do great things when we are inclusive and work together. To perform with excellence, we learn from one another, value diverse perspectives, operate safely and build strong relationships.

The Next Step

Ready to join our team? We'd love to hear from you. We are proud to be an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. All applicants who receive a conditional offer of employment may be required to take and pass a pre-employment drug test. The above statements are not an exhaustive list of all required responsibilities, duties, and skills for this job classification. Review RXO's candidate privacy statement here and RXO's Privacy Notice to California Job Applicants here.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Lead Engineer, Information Security (Application Security)
Lead Engineer, Information Security (Application Security)

Web: • Charlotte (NC)

Hybrid
USD 150,000 - 200,000
Medical benefits
Dental & Vision
401(k) match
+4
Lead Analyst, Information Security (Risk and Governance)
Lead Analyst, Information Security (Risk and Governance)

RXO Inc. • Charlotte (NC)

On-site
USD 110,000 - 140,000
Medical, dental, and vision plans
401(k) retirement plan with company 5%
Employee Assistance Program (EAP)
+2
Application Security & Red Team - Lead Engineer, Information Security
Application Security & Red Team - Lead Engineer, Information Security

RXO, Inc. • Charlotte (NC)

On-site
USD 90,000 - 150,000
Lead Analyst, Information Security (Risk and Governance)
Lead Analyst, Information Security (Risk and Governance)

RXO • Charlotte (NC)

Hybrid
USD 120,000 - 170,000
Medical, dental, and vision plans
401(k) with company match
Lead Analyst, Information Security (Risk and Governance)
Lead Analyst, Information Security (Risk and Governance)

RXO Inc. • United States

Hybrid
USD 120,000 - 180,000
Comprehensive medical, dental, and vis
401(k) retirement plan with company
Pre-tax accounts
+4
Senior Analyst, External Reporting
Senior Analyst, External Reporting

RXO, Inc. • Town of Charlotte (NY)

On-site
USD 90,000 - 115,000
Comprehensive medical, dental, and vis
401(k) retirement plan with up to 5%公司
Pre-tax accounts
+4
Lead Application Security Engineer - Cloud-Native & AI
Lead Application Security Engineer - Cloud-Native & AI

Web: • Charlotte (NC)

On-site
USD 150,000 - 200,000
Medical benefits
Dental & Vision
401(k) match
+4
Lead Application Security Engineer - AI & Cloud
Lead Application Security Engineer - AI & Cloud

RXO • Charlotte (NC)

Hybrid
USD 140,000 - 190,000
Health plans
401(k)
Pre-tax accounts
+4
Senior Director, Operations
Senior Director, Operations

RXO, Inc. • Phoenix (AZ)

On-site
USD 170,000 - 230,000
Medical, dental, and vision plans
401(k) with company match
Pre-tax accounts
+5
Senior Auditor
Senior Auditor

RXO, Inc. • Charlotte (NC)

Hybrid
USD 75,000 - 105,000
Comprehensive medical, dental, and eye
401(k) with company match
Pre-tax accounts
+4