Job Closed
This listing is no longer active.
Fragomen is a law firm specializing in immigration law. The global company was founded in 1951 and is based in New York, New York. The firm has over 40 offices
Security Engineer - Application Security
Location
United States
Posted
100 days ago
Salary
0
Seniority
Mid Level
Job Description
Security Engineer - Application Security
Fragomen
Role Description Fragomen is seeking a Security Engineer – Application Security to join our talented Cyber Security team in our Technology Innovation Lab in Pittsburgh. Our industry-leading, immigration specific software and supporting infrastructure is undergoing tremendous transformation and security is on the critical path to success in that endeavor. A professional, who is passionate about security, capable of effecting change, and ready to build a strong AppSec program, is what we seek. You will be joining a small team of Security Engineers who make security a distinguishing factor in our technological offerings. A successful candidate will help engineer solutions to secure software development, identify threats and mitigate vulnerabilities throughout our environment. - Build, deploy and maintain tooling to validate and track security controls in and around our code - Work closely with application development and infrastructure architectural teams to create code which is secure by design and default - Triage programmatic source code findings and automate penetration testing to decrease potential introduction of vulnerabilities - Lead and collaborate with developers on secure coding techniques and threat modeling - Contribute to vulnerability detection and remediation of technological offerings - Deploy developed or OTS security applications to support our efforts - Participate in a cross-functional response to cyber security incidents - Work closely with the security team to establish prevention, detection and mitigation techniques - Support the scoping and rules of engagement of our penetration testing regime Qualifications - A passionate team player who builds knowledge and solves complex problems - 5+ years of web application development (.net, python, java, etc.) - Secure SDLC (Software Development Life Cycle), DAST (Dynamic Application Security Testing), and SAST (Static Application Security Testing) experience - Demonstrated understanding of web application penetration testing, secure coding and source code analysis - Strong, professional communication skills that maintain under pressure Requirements - Experience in developing highly automated detection and triage tools - Deep understanding of cyber security techniques - Technical certification demonstrating technical prowess in secure software development e.g. Certified Secure Software Lifecycle Professional (CSSLP), or Certified Application Security Engineer (CASE) or similar - BA degree in a related field or a combination of related experience is a must Benefits All offers and/or employment contracts are contingent upon the successful completion of the Firm’s pre-employment screening process. This process may include verifying the candidate’s identity, confirming legal authorization to work in the offered position’s location, and conducting a comprehensive background check, where permitted by local regulations. We use limited AI‑assisted tools for administrative screening purposes only - never for decision‑making. All hiring decisions are made by people. Applicants may have rights to information and explanations regarding the use of such tools, or request human review, as required by applicable regional laws.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Solutions Architect – Pre-Sales
EVOTEKToday’s Emerging Technology will be Tomorrow’s Competitive Advantage
• Communicate directly with customers providing recommendations and presenting security solutions. Will follow security projects from pre-sales through to the delivery of products and services. • Drive business opportunities from opportunity identification, scoping process through booking. Identify, qualify, and close new opportunities through the application of technical expertise, account management skills, sales ability, and exceptional client focus. • Work closely with clients to fully understand security concerns, and how company offerings and solutions can help remediate those concerns. Build and maintain relationships with clients and prospects while designing, communicating, and evangelizing cyber security solutions. • Communicate clearly, and concisely the capabilities of security offerings, advisory services, and build reference architectures. Serve as a trusted advisor and consultant to optimize their cyber security strategy. • Assists the sales team with design, sales engineering, proposal assimilation, while delivering high quality results that differentiates us from competitors. • Quickly grasp new technologies and develop solutions integrating new technologies with existing cyber security tools and services. Responsible for technology evaluation and testing. • Develop go-to-market strategy, operationalize plans, collect learnings, and establish the foundation for innovative ideas to scale. A record of accomplishment of developing services. • Deliver technical presentations and/or cyber security solution demos to clients and partners. • Cross collaboration and solution design with adjacent practices (Network, Data Center, Cloud). • Responsible for hands-on work or may be responsible for working with other Engineers. • Leverage and maximize partner alliance relationships to increase opportunity identification. • Identify opportunities where existing client products/tools can be leveraged to develop solutions that provide additional features and capabilities. • Develop white papers and knowledge base articles as needed. • Provide thought leadership in the areas of security requirements, methodologies, techniques, and tools used to reduce the client’s cyber security risk posture.
Databricks Tech Lead (Remote anywhere in México)
CapgeminiFounded in 1967, Capgemini is revered as one of the world's leading consulting, technology, and outsourcing agencies. In 2016 alone, the company reported global
At Capgemini Engineering, the world leader in engineering services, we bring together a global team of engineers, scientists, and architects to help the world’s most innovative companies unleash their potential. From autonomous cars to life-saving robots, our digital and software technology experts think outside the box as they provide unique R&D and engineering services across all industries. Join us for a career full of opportunities. Where you can make a difference. Where no two days are the same. Your role - Plan, manage, and execute releases across all environments - from development to production. - Identify technical and functional interdependencies between various tracks. - Coordinate with all development pods and stakeholders across programs. - Review application code, documentation, and perform pre/post deployment tasks. - Define release process for new data engineering applications. - Change management communication to all required stakeholders. - Execute release packages, step-by-step deployment guides, and command line instructions on production environment. - Support project timelines, clearly setting expectations, and realigning expectations internally as priorities change. - Develop a sound understanding of client’s needs: data conversion and migration requirements, environment management and build processes, deployment planning and execution, solution designs, systems - integrations, technical architectures, and infrastructure architectures. Your profile - Execute deployment scripts and step-by-step instructions in test and production environments. - Comfortable with Command Line Interfaces. - Understanding of CI/CD, Git branching, packaging and DevOps pipelines. - Working knowledge of data warehousing and reporting technologies: Azure, Databricks, Unity Catalog, Python, Spark, PySpark, Airflow, MicroStrategy, Tableau. What you will love about working here - Empowered Careers with Purpose: Work on meaningful projects that use technology to solve real-world challenges. Be part of a company that values sustainability, inclusion, and digital equity. Contribute to building a better future for people, planet, and society. - Growth and Learning at Every Step: Access continuous learning through internal academies, certifications, and mentorship. Explore career mobility across roles, industries, and geographies. Be part of a “school of excellence” where your skills resonate beyond the company - Own your growth: Open access to digital learning platforms. Digital campuses on AI, Cloud, Data or Sustainability. Award winning career acceleration programs Need to know - Work modality: remote - Flexible Schedules: We support flexible working hours to accommodate different lifestyles, time zones, and family responsibilities. - Benefits: Training, certifications, and mentorship programs - Community Engagement: Participate in local volunteering initiatives, tech meetups, and cultural events that connect you with the Capgemini community. About Capgemini Capgemini is a global business and technology transformation partner, helping organizations to accelerate their dual transition to a digital and sustainable world, while creating tangible impact for enterprises and society. It is a responsible and diverse group of 340,000 team members in more than 50 countries. With its strong over 55-year heritage, Capgemini is trusted by its clients to unlock the value of technology to address the entire breadth of their business needs. It delivers end-to-end services and solutions leveraging strengths from strategy and design to engineering, all fueled by its market leading capabilities in AI, generative AI, cloud and data, combined with its deep industry expertise and partner ecosystem. At Capgemini Mexico, we aim to attract the best talent and are committed to creating a diverse and inclusive work environment, so there is no discrimination based on race, sex, sexual orientation, gender identity or expression, or any other characteristic of a person. All applications welcome and will be considered based on merit against the job and/or experience for the position.
Purpose This role is responsible for establishing and maintaining the enterprise-wide IT security infrastructure to ensure the security, integrity, and availability of the company’s information assets. This includes the rigorous application of information security and information assurance policies, principles, and practices, with a strong emphasis on Incident Response readiness and operational execution. The position will lead efforts to detect, analyze, contain, eradicate, and recover from security incidents while continuously improving response processes, tooling, playbooks, and defensive capabilities. Responsibilities - Provide efficient and effective Infrastructure Security Operations Support of all supported infrastructure security components - Investigate and analyze common security incidents, including malware infections, phishing attempts, unauthorized access, and suspicious network activity. - Develop, maintain, and optimize Incident Response playbooks and SOPs to ensure consistent, efficient detection, containment, eradication, and recovery processes. - Collaborate closely with the MSSP to refine detection use cases, validate alerts, coordinate response actions, and improve overall SOC effectiveness. - Drive containment and remediation efforts during active security events, working with cross‑functional teams to minimize impact and ensure rapid recovery. - Support and enhance email security controls, including phishing analysis, message tracing, and mail flow/security policy tuning. - Participate in an on‑call rotation to provide timely response during off‑hours incidents. - Conduct root‑cause analysis and produce post‑incident reports, identifying gaps and recommending improvements to tooling, processes, and security posture. - Assist in threat hunting activities to proactively identify emerging threats or abnormal behaviors in the environment. - Contribute to continuous improvement of logging, monitoring, and alerting across security platforms. - Provide timely and effective maintenance and repair support on all supported infrastructure security components - Conduct efficient security monitoring of all supported infrastructure security components to include but not limited to firewalls and intrusion detection/prevention systems - Ensure effective change control and configuration management of all supported infrastructure security-related components to establish and maintain consistency of their performance and functional and physical attributes - Develop and execute advanced automation and orchestration activities as applicable across several information security domains - Some familiarity administering the following technology stack: Splunk, Microsoft Azure and Defender, CheckPoint Firewall/Email, and Imperva WAF. - Manage risk identification within the technical architecture in partnership with infrastructure teams - Keep abreast of and gain expertise in the evolving technology and understand how new technologies could be applied to our security environment - Research, test and understand the relevant products and product capability - Participate in the vendor community on relevant products and product capability - Work under the guidance from more senior information security engineers - Mentors’ junior information security engineers About You - Bachelor's degree in information systems, or related field, OR 5-7 years of experience in the information security field - Relevant Industry certifications such as CISSP, CISM, and AZ-500 - Demonstrate good judgment in solving problems, identifying problems in advance, and proposing solutions - Strong analytical and organizational skills, with attention to detail - Demonstrate strong verbal and written communication skills - Ability to multi-task, prioritizing multiple objectives and initiatives - Able to work in a team environment and with a diverse group Physical Requirements - Ability to travel up to ~10% of the time, which may include weekends and evenings, as needed - Most work is performed in a temperature-controlled environment - Incumbent may sit for long periods of time at a desk or computer terminal - Incumbent may use calculators, keyboards, telephone and other office equipment in the course of a normal workday - Stooping, bending, twisting and reaching may be required in completion of job duties Our Values Ability to demonstrate, understand and apply our workplace values. Simplicity (operate) – the drive to identify root cause and innovate to remove complexity to deliver the best outcome Heart (emotion) – the passion that drives you to get up every day and work hard to strive for excellence Performance Excellence (mindset) – clearly defining high expectations, driving ownership of key roles and responsibilities, executing with integrity and emphasis while creating a culture of accountability Respect (philosophy) – taking pride in being inclusive and treating everyone who comes through the doors with respect Benefits - 401K company match up to 4% - Paid Time Off - Medical Insurance options including FSA & HSA - Vision Insurance - Dental insurance - Employee Assistance Programs - Team Member Referral Program - Tuition Reimbursement - Wellbeing Program - Career development opportunities The above statements are intended to describe the general nature of the work performed by the employees assigned to this job. All employees must comply with Company policy and applicable laws. The responsibilities, duties and skills required of personnel so classified may vary within each department and /or location.
CNAPP Security Engineer – Mid-Atlantic region
GuidePoint SecurityWe help organizations make smarter cybersecurity decisions that minimize risk.
• Perform implementation of CNAPP and CSPM tools in multi-account AWS and Azure environments. • Implement IaC scanning tools within the CI/CD Pipelines. • Develop Infrastructure as code in Cloud Formation or Terraform. • Develop custom control checks within CNAPP Platforms using JSON, REGO, or Terraform. • Analysis – identifies and evaluates potential threats and vulnerabilities to the public cloud environments network, applications, infrastructure, and systems. • Issue Resolution – leads the resolution of identified issues in public cloud environments. • Deep understanding of Kubernetes and microservices security best practices. • Performs container registry scanning. • Reviewing and creating metrics, KPIs, and KRIs to track overall cloud security posture. • Create, maintain, and update runbooks for cloud configuration checks. • Assess the overall security posture of cloud security infrastructure and workloads. • Advise customers on Cloud security best practices.


