SC Security Engineer

Hubnest Inc

United States

Hybrid

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health coverage
Flexible working arrangements
Learning budget
Paid time off

Job summary

Hubnest Inc. is seeking a seasoned security professional to defend our proprietary systems and client data. You will lead vulnerability assessments across Hubnest’s four products, implement SAST/DAST in CI/CD, and monitor SIEM for anomalies.

You’ll harden AWS IAM configurations and map security controls to SOC 2, HIPAA, and GDPR, while training engineers on secure coding practices. Join a team that values discretion, ethical standards, and robust incident response.

Qualifications

  • 5+ years of professional experience in Application Security, Cloud Security, or Offensive Security roles.
  • 4+ years securing AWS cloud environments and auditing IAM policies.
  • 3+ years using penetration testing tools such as Burp Suite Pro, Metasploit, Nmap, Nessus.
  • 3+ years implementing and tuning SAST/DAST tools in CI/CD pipelines.
  • 2+ years incident response leadership during cybersecurity incidents or data breaches.
  • 2+ years mapping engineering controls to SOC 2 Type II or HIPAA requirements.
  • 2+ years using SIEM platforms to write custom detection rules.
  • Bachelor’s degree in relevant field or equivalent experience.

Responsibilities

  • Conduct vulnerability assessments and internal penetration tests across Hubnest’s products.
  • Manage automated SAST/DAST in CI/CD pipelines.
  • Monitor SIEM dashboards to detect anomalous activity and unauthorized access.
  • Perform manual code reviews targeting OWASP Top 10 vulnerabilities.
  • Lead during active security incidents with containment, eradication, and forensics.
  • Harden AWS configurations and IAM roles; reduce misconfigurations.
  • Collaborate with Compliance to map controls to SOC 2/HIPAA/GDPR.
  • Document incident response playbooks and disaster recovery procedures.
  • Maintain endpoint detection across distributed hardware.
  • Run third-party vendor risk assessments prior to new tool procurement.
  • Train engineering teams on secure coding practices.

Skills

Security engineering
AWS security
Vulnerability management
Incident response
SOC 2/HIPAA/GDPR mapping
SIEM technologies

Education

Bachelor's degree in Cybersecurity, Computer Science, Information Security

Tools

Burp Suite Pro
Metasploit
Nmap
Nessus
SonarQube
Checkmarx
Veracode
SIEM platforms (Splunk, Datadog Security, ELK)

Job description

Hubnest builds vertical specific product engines for industries that require high operational precision. Founded in 2014, the company has spent twelve years embedded in the operational realities of the industries it serves, developing four purpose built products used by organizations across field services, political and civic operations, continuing care, and enterprise security.

You will defend Hubnest's proprietary systems and sensitive client data against external and internal threats. You proactively identify vulnerabilities, engineer defensive mechanisms, and enforce security protocols across all engineering teams.

What You Will Be Doing
  • Conduct ongoing vulnerability assessments and internal penetration tests against Hubnest's four distinct products.
  • Implement and manage automated Static Application Security Testing and Dynamic Application Security Testing in the CI/CD pipeline.
  • Monitor centralized SIEM dashboards to detect, analyze, and hunt anomalous network behavior and unauthorized access attempts.
  • Perform manual code reviews of complex pull requests, targeting OWASP Top 10 vulnerabilities including XSS, SQLi, and CSRF.
  • Respond as the technical lead during active security incidents, executing containment, eradication, and forensic analysis protocols.
  • Review and harden AWS cloud infrastructure configurations, eliminating misconfigurations and overly permissive IAM roles.
  • Collaborate with the Compliance Analyst to map technical security controls to SOC 2, HIPAA, and GDPR frameworks.
  • Document incident response playbooks, disaster recovery strategies, and internal security standard operating procedures.
  • Maintain endpoint detection and response solutions across all distributed company hardware.
  • Execute third-party vendor risk assessments prior to the procurement of any new software tooling.
  • Train the software engineering department semi-annually on secure coding practices and emerging threat vectors.
What We Are Looking For
  • 5+ years of professional experience in Application Security, Cloud Security, or Offensive Security roles.
  • 4+ years of hands-on experience securing AWS cloud environments and auditing complex IAM policies.
  • 3+ years of verifiable experience utilizing industry-standard penetration testing tools such as Burp Suite Pro, Metasploit, Nmap, and Nessus.
  • 3+ years of experience implementing and tuning SAST/DAST tools such as SonarQube, Checkmarx, or Veracode within CI/CD pipelines.
  • 2+ years of experience serving as a primary technical responder during active cybersecurity incidents or data breaches.
  • 2+ years of direct, hands-on experience mapping technical engineering controls to SOC 2 Type II or HIPAA compliance requirements.
  • 2+ years of experience utilizing SIEM platforms such as Splunk, Datadog Security, or ELK Suite to write custom detection rules.
  • Current certification required: CISSP, OSCP, AWS Certified Security Specialty, or equivalent.
  • Commitment to maintaining discretion and ethical standards regarding sensitive client data.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Security, or equivalent practical experience.
What We Offer
  • Competitive compensation commensurate with experience
  • Comprehensive health, dental, and vision coverage
  • Flexible working arrangements
  • Learning and development budget
  • Paid time off and statutory holidays
Equal Opportunity Employment

Hubnest is an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, national origin, age, disability, genetic information, or any other characteristic protected by applicable federal, state, or local law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer — Cloud & App Defenses (Flexible)
Senior Security Engineer — Cloud & App Defenses (Flexible)

Hubnest Inc • United States

Hybrid
USD 140,000 - 190,000
Health coverage
Flexible working arrangements
Learning budget
+1
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Seattle (WA)

On-site
USD 100,000 - 130,000
Health Care Plan (Medical, Dental & Vision)
Retirement Plan (401k, IRA)
Life Insurance (Basic, Voluntary & AD&D)
+5
Staff Security Engineer I, Security Operations
Staff Security Engineer I, Security Operations

Etsy, Inc. • New York (NY)

On-site
USD 204,000 - 240,000
Equity package
Annual performance bonus
Competitive benefits supporting employees and families
Cloud Security Architect - St. Louis, MO
Cloud Security Architect - St. Louis, MO

Hubbell Incorporated • Maryland Heights (MO)

On-site
USD 150,000 - 190,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Security Engineer, Correlation and Response, AWS Security Hub
Security Engineer, Correlation and Response, AWS Security Hub

Socket.dev • Boston (MA)

On-site
USD 159,000 - 203,000
Health insurance
401(k) matching
Paid time off
+1
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Senior Staff Engineer - DevSecOps
Senior Staff Engineer - DevSecOps

Exelixis Inc • Alameda (CA)

On-site
USD 154,500 - 220,500
401(k) plan with company contributions
Group medical, dental, and vision coverage
Flexible spending accounts
+1
Security Engineer, Correlation and Response, AWS Security Hub
Security Engineer, Correlation and Response, AWS Security Hub

Amazon Web Services (AWS) • Seattle (WA)

On-site
USD 159,000 - 202,000