Security Engineer

Brightspot

Reston (VA)

Hybrid

USD 113,000 - 138,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance
Dental insurance
Vision insurance
PTO

Job summary

Brightspot is seeking a hands-on Security Engineer to protect our AI-powered CMS platform and strengthen security across infrastructure and applications. You will own security initiatives, investigate incidents, and collaborate with Engineering, Platform, QA, and IT to embed security into daily workflows.

The role emphasizes cloud security, IaC integration, and proactive risk mitigation, with a strong ownership mindset and the chance to impact a SaaS-scale environment.

Qualifications

  • 7+ years of hands-on security engineering experience in software development.
  • Experience securing cloud environments (AWS/Azure/GCP) and modern DevOps.
  • Strong knowledge of networking, secure configuration, and IaC security workflows.
  • Proven ability to scope, own, and deliver security initiatives with minimal oversight.
  • Experience with AI tools applied to security tasks and automation.

Responsibilities

  • Lead security projects from scoping to completion with cross-team collaboration.
  • Investigate incidents, respond to alerts, and contribute code for remediation.
  • Identify risks, plan resolutions, and drive them to closure.
  • Work with CSPM, vulnerability mgmt, and GRC tools to improve security posture.
  • Enhance alerting, monitoring, and production observability for security events.
  • Integrate IaC tooling (Terraform/Pulumi) into development lifecycle.
  • Communicate risks clearly to technical and non-technical stakeholders.

Skills

Security engineering
Cloud security
IaC (Terraform/Pulumi)
Coding/scripting
Vulnerability management
SOC 2 Type 2 experience
AI tools in security
Cross-functional collaboration

Education

SOC 2 Type 2 certification

Tools

SIEM
GRC tooling
SAST/DAST

Job description

About The Company

At Brightspot, we help content-driven organizations turn content chaos into momentum. Our flexible, AI-powered content management platform (CMS) enables teams to move faster, collaborate more effectively, and scale with confidence. Since 2008, leading enterprises have partnered with Brightspot to transform fragmented ecosystems into streamlined, high-performing operations that drive growth, strengthen governance, and deliver real business impact.

About The Company

At Brightspot, we help content-driven organizations turn content chaos into momentum. Our flexible, AI-powered content management platform (CMS) enables teams to move faster, collaborate more effectively, and scale with confidence. Since 2008, leading enterprises have partnered with Brightspot to transform fragmented ecosystems into streamlined, high-performing operations that drive growth, strengthen governance, and deliver real business impact.

About The Role

We're looking for a hands-on Security Engineer to help protect our platform and strengthen our overall security posture. This is a highly technical, self-directed role for someone who enjoys getting into the details of infrastructure and application security, can drive projects from idea to completion with minimal oversight, and knows how to use AI tools as a force multiplier to move faster and dig deeper.

You'll split your time between hardening cloud infrastructure, investigating and resolving security issues, and partnering closely with Engineering, Platform, QA, and IT to make security a shared responsibility across the company. If you're someone who values ownership and autonomy and enjoys solving complex security challenges end-to-end, this role will give you room to make a real impact.

Responsibilities
  • Drive security projects independently from scoping through completion, working across teams to see initiatives through rather than handing them off after the design phase.
  • Contribute directly to the investigation of security issues, incidents, and alerts as a hands-on member of the response effort.
  • Identify security issues, develop plans for resolution, and, where appropriate, contribute code through pull requests.
  • Work hands-on with Cloud Security Posture Management, vulnerability management, and GRC tooling to identify risks and drive them to closure.
  • Continuously evaluate and strengthen existing security tools and processes to improve our overall security maturity.
  • Conduct external security assessments and operationalize the findings.
  • Partner with engineering teams to securely integrate Infrastructure as Code tools, such as Terraform and Pulumi, into the development lifecycle.
  • Improve alerting, monitoring, and production observability for security-relevant events.
  • Collaborate closely with Engineering, Platform, QA, and IT to embed security into everyday workflows and help build a culture in which security is everyone's responsibility.
  • Clearly communicate risks and proposed solutions to both technical and non-technical audiences.
Qualifications
  • 7+ years of hands-on security engineering experience within a software development environment.
  • Proven experience as a hands-on security engineer, ideally in a SaaS or cloud-natives environment.
  • Experience securing cloud environments, such as AWS, Azure, or GCP, and working within modern DevOps pipelines.
  • Strong self-direction, with the ability to identify problems, prioritize them, and drive them to resolution with minimal oversight.
  • Deep understanding of networking and network security fundamentals, including segmentation, routing, firewalls, VPNs, TLS, and secure configuration management.
  • Experience with Infrastructure as Code, particularly Terraform or Pulumi, and securing IaC workflows.
  • Solid coding and scripting skills sufficient to investigate issues, build tooling, and contribute pull requests that directly address infrastructure vulnerabilities.
  • Proven track record of identifying vulnerabilities and driving remediation through completion in fast-paced environments.
  • Working knowledge of Cloud Security Posture Management platforms, vulnerability management tools, GRC and compliance tools, and Static Application Security Testing tools.
  • Familiarity with application security practices, including secure SDLC, code review, SAST, and DAST.
  • Experience working at a company undergoing or maintaining SOC 2 Type 2 certification.
  • Practical experience applying AI tools to security work, including investigation, code analysis, automation, and detection logic.
  • Excellent cross-functional collaboration skills, with a track record of working effectively alongside Engineering, Platform, QA, and IT teams.
  • Ability to clearly communicate technical risks and remediation plans to both engineering teams and non-technical stakeholders.
Preferred Qualifications
  • Experience operationalizing compliance frameworks, such as SOC 2 Type 2, in real production environments—not just passing an audit, but making the controls meaningful and sustainable.
  • Experience coordinating with third-party vendors for penetration testing and managing findings through remediation.
  • Experience building or tuning security monitoring and alerting pipelines, such as SIEM or cloud-native detection tooling.
  • Relevant certifications, such as AWS or GCP security certifications, OSCP, or CISSP.
Compensation & Benefits
  • The starting salary for this role is $125,000 with bonus potential.
  • Benefits include health, dental, and vision insurance, 3 weeks paid vacation, paid sick leave, paid company holidays, Safe Harbor 401(k) with employer matching, continuing education stipend, and a 3-week paid sabbatical after your 5th anniversary.
Hybrid Expectations
  • This is a hybrid position. Candidates are expected to work on-site at our Reston office 2-3 days per week.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

ADP, Inc. • Reston (VA)

Hybrid
USD 125,000 - 130,000
Health insurance
Dental insurance
Vision insurance
+6
Security Engineer
Security Engineer

Perfect Sense, Inc • Reston (VA)

Hybrid
USD 125,000 - 130,000
Health insurance
Dental insurance
Vision insurance
+4
Senior Security Engineer – Hybrid (4649)
Senior Security Engineer – Hybrid (4649)

Hireclout • Los Angeles (CA)

On-site
USD 180,000 - 200,000
Competitive compensation package
Equity participation
100% covered medical, dental, and vision coverage
+5
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Senior Director, Security Engineering
Senior Director, Security Engineering

iterable • United States

Remote
USD 220,000 - 300,000
Equity
401(k) plan
Medical insurance
+8
Staff Software Engineer, Security
Staff Software Engineer, Security

XOXO AI Inc. • San Francisco (CA)

On-site
USD 250,000 - 500,000
Health benefits
Dental benefits
Vision benefits
Cloud Engineer
Cloud Engineer

Advisor Group Inc. • Scottsdale (AZ)

Hybrid
USD 140,000 - 160,000
Health insurance
Dental insurance
401(k)
+2
Security Engineer - Infrastructure Security
Security Engineer - Infrastructure Security

Figure • San Jose (CA)

On-site
USD 150,000 - 250,000
Cloud Application Security Engineer
Cloud Application Security Engineer

Tactical Edge • Washington

Hybrid
USD 140,000 - 180,000
Senior Security Engineer
Senior Security Engineer

muonspace • United States

Hybrid
USD 193,000 - 218,000
Competitive equity grant
Comprehensive benefits
Hybrid/remote work options
+3