Job Closed
This listing is no longer active.
We save lives through cell therapy.
Senior Information Security Engineer – Application
Location
United States
Posted
68 days ago
Salary
$105K - $130K / year
Seniority
Senior
Job Description
Senior Information Security Engineer – Application
NMDP
• The Sr Information Security Engineer is responsible for designing, implementing, and continuously improving the technical security controls that protect internally developed applications, including cloud systems, containerized, and serverless workloads. • This role is a hands-on application security specialist who performs deep secure code reviews, leads threat modeling, and drives remediation of complex vulnerabilities across the SDLC. • Collaborating with other technical teams, this role ensures secure application development, deployment, and operation by assessing maturity, defining security requirements and guardrails, and delivering prioritized recommendations to improve pipeline controls, tooling, and integrations within the DevSecOps pipeline. • Conducting application security assessments, guiding secure software development practices, and advancing the maturity of application security capabilities. • The Information Security Engineer partners with development, operations, and security teams to embed security into development practices and responds as a subject matter expert during application-related security incidents.
Job Requirements
- Bachelor’s degree in computer science, management information systems, or related field. Four years work experience in the areas of information security, systems or network administration, programming, or systems analysis may be substituted for a degree.
- Seven (7) or more years of experience in information security, software engineering, DevSecOps, SRE/Platform Engineering, or a closely related field.
- At least four (4) years of direct application security experience, including hands-on secure code review and vulnerability remediation guidance.
- Knowledge of: Secure software development practices, secure software architecture principles, and common vulnerability classes with demonstrated ability to translate findings into practical engineering fixes.
- Cloud-native, containerized, and serverless security concepts; particularly AWS IAM and event-driven architectures.
- Demonstrated understanding of secure application development, DevSecOps practices, and application security technologies (e.g., SAST, DAST, SCA, container security).
- AI/ML security concepts relevant to internal AI development (data governance, model/inference service security, and common AI threat scenarios). Equivalent demonstrated experience securing complex systems with the ability to quickly build AI security depth is acceptable.
- Demonstrate experience with one or more of the following: Application Vulnerability Management, Identity and Access Management, and Data Loss Prevention process development, technical analysis and supporting technologies.
- Demonstrate understanding in forensic investigations, data recovery and the handling of digital evidence.
Benefits
- NMDP offers regular, full-time employees medical, dental, vision, life and disability, accident/critical illness/hospital, well-being, legal, identity theft and pet benefits.
- Retirement, paid time off/holidays, leave and incentive plans are also offered to eligible employees.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Staff Corporate Security Engineer
AirwallexAirwallex is a financial services company that has developed a “global financial platform for modern businesses.” As an employer, the company strives to cul
About Airwallex Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 200,000 businesses worldwide - including Brex, Rippling, Navan, Qantas, SHEIN and many more - with fully integrated solutions to manage everything from business accounts, payments, spend management and treasury, to embedded finance at a global scale. Proudly founded in Melbourne, we have a team of over 2,000 of the brightest and most innovative people in tech across 26 offices around the globe. Valued at US$8 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood Ventures, Sequoia, Salesforce Ventures, DST Global, and Lone Pine Capital, Airwallex is leading the charge in building the global payments and financial platform of the future. If you're ready to do the most ambitious work of your career, join us. Attributes We Value We hire successful builders with founder-like energy who want real impact, accelerated learning, and true ownership. You bring strong role-related expertise and sharp thinking, and you're motivated by our mission and operating principles. You move fast with good judgment, dig deep with curiosity, and make decisions from first principles, balancing speed and rigor. You're humble and collaborative; turn zero-to-one ideas into real products, and you "get stuff done" end-to-end. You use AI to work smarter and solve problems faster. Here, you'll tackle complex, high-visibility problems with exceptional teammates and grow your career as we build the future of global banking. If that sounds like you, let's build what's next. Your role As a Staff Corporate Security Engineer, you will be a critical part of defending Airwallex's enterprise systems and employees from threats such as malware, phishing and unauthorised access. This role is a highly technical opportunity to detect, investigate and prevent security issues across a modern corporate environment. You will work on digital forensics, incident response and tool development and deployment, protecting a range of corporate IT platforms from endpoints to identity providers. What you'll be doing - Contribute to incident response for malware, phishing, digital forensics. - Design, develop, test, and evaluate new corporate security controls for a rapidly growing business. - Perform incident response and hunt through log sources to identify new threats. - Design and implement security alerts and workflows to support the incident response lifecycle. - Secure corporate IT infrastructure and remediate issues across identity providers, endpoints, corporate networks and other platforms. - Deploy, configure and operate security tooling with a laser focus on impact. What you'll bring - A passion for solving the complex challenges of high-growth startups. - Self motivation and drive to learn new skills, or dive deeper into existing skills. - Bachelor's degree in Computer Science, Cybersecurity or similar. - 7+ years working in a security engineering or incident response role within a tech company. - Strong experience with Crowdstrike, Splunk or other common security monitoring tools. - In depth understanding of common attacker tools and techniques, how they can be detected and prevented, and ability to respond to incidents with high depth and quality of investigation. - Experience with GCP, Alibaba Cloud or other cloud platforms is preferred. - Experience with Okta, Google Workspace and cloud-based VPN services is preferred. - Experience securing endpoints, including with MDM tooling such as Kandji, Intune - Strong communication skills with the ability to explain technical security and software concepts to a non-technical audience. - Scripting experience such as with Python, Bash, Powershell. Applicant Safety Policy: Fraud and Third-Party Recruiters To protect you from recruitment scams, please be aware that Airwallex will not ask for bank details, sensitive ID numbers (i.e. passport), or any form of payment during the application or interview process. All official communication will come from an @airwallex.com email address. Please apply only through careers.airwallex.com or our official LinkedIn page. Airwallex does not accept unsolicited resumes from search firms/recruiters. Airwallex will not pay any fees to search firms/recruiters if a candidate is submitted by a search firm/recruiter unless an agreement has been entered into with respect to specific open position(s). Search firms/recruiters submitting resumes to Airwallex on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary. Equal opportunity Airwallex is proud to be an equal opportunity employer. We value diversity and anyone seeking employment at Airwallex is considered based on merit, qualifications, competence and talent. We don't regard color, religion, race, national origin, sexual orientation, ancestry, citizenship, sex, marital or family status, disability, gender, or any other legally protected status when making our hiring decisions. If you have a disability or special need that requires accommodation, please let us know. #BI-Hybrid
Senior Security Engineering Manager
AllstateNational General Insurance, a division of Allstate, describes itself as one of the largest insurers in the United States. The company provides personal and commercial auto, recreat
• Advise others on complex security engineering matters • Manage teams for strategic security architecture • Design and implement security controls • Collaborate with business and technical teams
J'aime trouver des solutions à des problèmes. Fort d'une précédente expérience d'une dizaine d'années dans le domaine du développement, de la sécurité informatique et de la gestion des opérations, je possède une vaste connaissance technologique. Seul, je peux travailler de trois façons : urgence (incidents), méthodique (conformité) ou attentionné (solution). En équipe, une façon m'interpelle : compréhension (collaboration). Je désire maintenant trouver un emploi me permettant de renforcer cet esprit d'équipe.
Information System Security Officer
Dragonfli GroupCyberSecurity as a Solution: Enabling Secure Business.
• Execute and maintain all RMF lifecycle activities for assigned federal information systems: categorization, control selection, implementation, assessment, authorization, and continuous monitoring • Develop, maintain, and update system security documentation including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and Authorization to Operate (ATO) packages • Coordinate with Information System Owners (ISOs), Authorizing Officials (AOs), and Security Control Assessors (SCAs) to drive ATO decisions on schedule • Monitor security controls on an ongoing basis; identify, document, and track deviations and vulnerabilities to closure • Conduct and support continuous monitoring activities including log review, vulnerability scan analysis, and configuration compliance validation • Support incident response activities including documentation, escalation, and remediation tracking • Maintain system inventory, hardware/software baselines, and interconnection agreements • Ensure compliance with applicable federal directives including FISMA, OMB A-130, and agency-specific security policies • Participate in security reviews, audits, and inspections as required




