Position Overview
We are seeking an experienced Security Assurance Engineer to support application modernization and digital transformation initiatives. This role will be responsible for ensuring security is embedded throughout the project lifecycle, from design and development through testing and production deployment.
The ideal candidate will partner with project teams, developers, architects, vendors, and business stakeholders to identify security requirements, assess risks, coordinate security testing, prioritize and remediate vulnerabilities, implement security controls, and validate production readiness.
Key Responsibilities
- Define and document security requirements, controls, and acceptance criteria for applications and technology solutions.
- Review application architectures, integrations, data flows, cloud environments, identity solutions, and infrastructure designs to identify security risks.
- Perform risk assessments and recommend mitigation strategies.
- Coordinate security testing activities, including vulnerability scanning, static and dynamic code analysis, and penetration testing.
- Analyze security findings, prioritize risks, validate vulnerabilities, and work with technical teams to implement remediation plans.
- Support secure deployment of cloud, web, mobile, SaaS, and AI-enabled solutions.
- Assess security risks related to AI technologies, including large language models (LLMs), retrieval-augmented generation (RAG) solutions, and automated workflows.
- Collaborate with engineering teams to implement and validate security controls and vulnerability remediation efforts.
- Maintain security documentation, testing evidence, risk assessments, remediation tracking, and release-readiness records.
- Support incident investigation and assist teams with security-related issues and escalations.
- Coordinate with internal security teams, vendors, and service providers to ensure security requirements are met.
- Monitor project security posture and communicate risks, findings, and recommendations to both technical and non-technical stakeholders.
- Provide regular project status updates, including security testing results, open risks, remediation efforts, and deployment readiness.
Required Qualifications
- 5+ years of experience in application security, cloud security, security engineering, or a related field.
- Strong understanding of vulnerability management, risk assessment, and security testing methodologies.
- Experience with SAST, DAST, penetration testing, and vulnerability scanning tools.
- Knowledge of IAM, RBAC, cloud security, data protection, logging, encryption, and infrastructure security.
- Experience reviewing application architectures, integrations, and technical solutions from a security perspective.
- Familiarity with tools such as Jira, GitHub, security testing platforms, and cloud technologies.
- Strong experience documenting risks, remediation plans, security controls, and production readiness recommendations.
- Excellent communication skills with the ability to work across technical and business teams.
Preferred Qualifications
- Experience securing AWS, Salesforce, SaaS, or cloud-native applications.
- Experience supporting application modernization or cloud migration initiatives.
- Familiarity with AI security, including LLMs, RAG solutions, and AI-enabled applications.
- Knowledge of security frameworks such as NIST, ISO 27001, or CIS Controls.
- Relevant certifications such as CISSP, CCSP, CSSLP, or equivalent.