Get more replies from employers
Send a job-specific resume in minutes.
Topcon Positioning Group, headquartered in Livermore, CA, seeks a Senior Security Engineer focused on Application Security within a broader Security Engineering team. You will lead secure design reviews, triage vulnerabilities across SAST/DAST/SCA, and guide remediation across the SDLC while collaborating with engineering and offshore partners.
Responsibilities include managing offshore vendor relationships, supporting Security Operations, incident response, and contributing to AI/ML security
Topcon Positioning Group is headquartered in Livermore, California, USA (topconpositioning.com). We design, manufacture and distribute productivity tools for developing a brighter future. Whether cultivating the earth or building upon it, Topcon brings innovation in workflow automation and seamless connectivity of data to construction, geopositioning and agriculture industries focused on developing a sustainable tomorrow.
Topcon is an equal opportunity employer and does not discriminate against any employee or applicant on the basis of race, color, religion, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, genetic information, or other legally protected status.
To learn more about Topcon career opportunities go to www.topconcareers.com.
Serve as a senior individual contributor on the Security Engineering team with a primary focus on Application Security, while contributing to Security Operations and AI Security. Maintain the day-to-day technical relationship with the offshore security vendor — setting expectations, reviewing deliverables, and ensuring quality — and reduce application and operational security risk across the SDLC while helping mature the organization’s security practices.
Lead application security reviews across the SDLC — threat modeling, secure design review, and secure code review for web, API, and cloud services. Triage and drive remediation of vulnerabilities from SAST, DAST, SCA, and penetration testing in partnership with engineering.
Serve as the primary day-to-day technical contact for the offshore security vendor — scoping work, reviewing deliverables for quality, coordinating across time zones, unblocking the team, and tracking commitments and risks.
Support detection, monitoring, alert investigation, and incident response. Help tune detections, reduce false positives, improve runbooks, and contribute to vulnerability management and infrastructure/endpoint hardening.
Help assess and secure AI/ML and LLM-based systems (prompt injection, data leakage, model abuse, supply-chain risk) and contribute to emerging AI security standards, review processes, and guardrails.
Standard office/remote work environment. Prolonged periods working at a computer. Occasional travel may be required.
Hybrid work arrangement during standard business hours, with periodic coordination across time zones to support the offshore vendor and occasional after-hours work during security incidents.
We are Topcon. We collaborate, create and distribute disruptive technologies that help businesses flourish through improved processes, machine automation and data services. We design and manufacture productivity tools for building a better future. Whether cultivating the earth or building upon it, Topcon brings innovation in workflow automation and seamless connectivity of data to infrastructure and agriculture industries with a focus on developing a sustainable tomorrow. Learn more here.