Job Closed

This listing is no longer active.

Mechanical Orchard logo
Mechanical Orchard

Mechanical Orchard combines software development and managed cloud operations in one offering.

Information Security Engineer – Application Security Focus

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

Canada

Posted

133 days ago

Salary

0

Seniority

Senior

Job Description

Information Security Engineer – Application Security Focus

Mechanical Orchard

• Build Security into Development: Work alongside engineering teams to integrate security throughout the SDLC; from design reviews and threat modeling to secure coding practices. Conduct security assessments of applications, APIs, and cloud infrastructure. Guide developers on secure authentication, authorization, cryptography, and data protection. Champion security best practices while maintaining developer velocity and trust. • Implement Security Tooling & Automation: Deploy and manage application security tools including SAST, DAST, SCA, and container scanning. Build automation for security testing in CI/CD pipelines. Implement and improve secrets management solutions. Create dashboards and metrics to track security posture. • Drive Security Initiatives: Lead application vulnerability management programs including triage, prioritization, and driving remediation. Support security compliance efforts (SOC 2, ISO 27001, or similar frameworks). Contribute to incident response and security event investigation. Develop security training and documentation for engineering teams. • Collaborate Across Teams: Partner with infrastructure and DevOps teams on cloud security controls. Perform risk assessments for new features, technologies, and third-party integrations. Participate in architecture reviews and provide security guidance.

Job Requirements

  • Bachelor’s degree in Computer Science, Software Engineering, Information Security, or a related technical field, or equivalent practical experience.
  • Strong written and verbal communication skills in English.
  • 5+ years of professional experience in information security, with a significant focus on application and cloud security.
  • Professional software development experience, with hands-on responsibility for designing, building, and maintaining production systems in a language like Python, Go, Java, JavaScript, or similar.
  • Strong understanding of application security principles: OWASP Top 10, secure authentication/authorization, encryption, API security.
  • Experience with cloud platforms (AWS, GCP, or Azure) and cloud-native security.
  • Hands-on experience with CI/CD systems and DevOps practices.
  • Knowledge of container security and orchestration platforms (Docker, Kubernetes).
  • Experience implementing security tools like SAST/DAST scanners, dependency checkers, or secrets detection.
  • Experience with security tools such as Aikido, Snyk, Semgrep, Trivy, Wiz, HashiCorp Vault, or similar.
  • Collaborative mindset—you build security solutions with engineers, not against them.

Benefits

  • Employee accommodations for disabilities.
  • Equal employment opportunities for all applicants.

Related Categories

Related Job Pages

More Security Engineer Jobs

CrowdStrike logo

Senior Technical Marketing Manager – Cloud Security

CrowdStrike

CrowdStrike has redefined security with the world’s most advanced cloud-native platform that protects and enables the people, processes and technologies that drive modern enterprise. Tested and proven, the world's largest organizations trust CrowdStrike to stop breaches with unparalleled protection against the most sophisticated cyberattacks. The CrowdStrike culture has been built upon our Core Values since the day we began. We are Fanatical About the Customer, Relentlessly Focused on Innovation and believe that our Limitless Passion drives Unlimited Potential for every CrowdStriker. As a purpose-built remote-first company, we believe cultivating a connected culture for every employee, no matter where they are in the world, is a key ingredient in building a high-performing, diverse team. We don’t have a mission statement. We’re on a mission—to stop breaches. Ready to join a mission that matters?

Security Engineer133 days ago
OtherRemoteTeam 5,001-10,000Since 2011H1B Sponsor

• Develop and deliver compelling demonstrations of CrowdStrike Cloud Security capabilities aligned to GTM motions, use cases, and product lines • Build labs, workshops, demo videos, whitepapers, best practice deployment guides, and enablement assets that accelerate adoption and highlight CrowdStrike's differentiation in multi-cloud and hybrid environments • Serve as a bridge between technical marketing and product marketing, aligning product capabilities with market narratives and competitive positioning • Shape positioning, messaging frameworks, and launch strategies as a core member of the Product Marketing team, ensuring they resonate with cloud architects, security engineers, DevOps teams, and C-level buyers • Lead the creation of technical and thought leadership content, including demo assets, launch materials, blogs, webinars, and technical articles that highlight CrowdStrike's innovation in cloud-native security, container protection, and runtime security • Influence messaging and competitive positioning strategies for cloud security in close partnership with Product Marketing • Play a key role in launch planning, campaign development, and field enablement, ensuring that technical depth and product positioning are tightly aligned • Support Analyst Relations with technical expertise, live demos, and detailed product briefings focused on cloud security trends and capabilities • Collaborate with Sales Engineering and Enablement to develop sales plays and training that sharpen differentiation in cloud security conversations • Create practitioner-level guides and technical content that accelerate buyer decision-making for cloud transformation and security initiatives • Represent CrowdStrike at conferences, tradeshows, analyst briefings, and customer events as both a technical SME and product marketing spokesperson

United States
$125K - $180K / year
Job Closed
LocalStack logo

Head of Security

LocalStack

LocalStack - tools and services that revolutionize the development flow for modern cloud&AI applications.

Security Engineer133 days ago
Full TimeRemoteTeam 11-50Since 2017H1B No Sponsor

• Ensure robust security posture of our product across various components • Lead initiatives for incident monitoring, intrusion detection, and vulnerability management • Define and implement regular security auditing procedures across systems and access controls • Deliver a sustainable process for vendor risk assessments and other security-related initiatives • Ensure secure configurations and permission models while collaborating with engineering teams • Identify gaps between claimed and actual compliance and propose/lead corrective actions • Own documentation of security controls, configurations, and policies • Engage with internal stakeholders to evaluate different security threats and attack vectors • Generate and distribute internal audit and compliance reports at regular intervals

Spain
Job Closed
Slingshot Aerospace logo

Account Executive, National Security

Slingshot Aerospace

We build space simulation and analytics solutions to bring clarity to complex environments and create a safer world.

Security Engineer133 days ago
OtherRemoteTeam 51-200Since 2020H1B No Sponsor

• Own the full sales lifecycle for assigned National Security accounts, from opportunity identification through contract execution and expansion • Develop deep relationships with senior government stakeholders, program offices, and mission users across the Intelligence Community and related national security organizations • Build and maintain a qualified pipeline of enterprise opportunities aligned to territory and revenue targets • Shape customer requirements and acquisition strategies through early engagement and solution positioning • Partner cross-functionally with Product, Engineering, Science, Capture, and Program teams to deliver customer-aligned proposals, briefings, RFIs, and demonstrations • Forecast accurately and maintain disciplined pipeline hygiene using established sales processes and tools • Represent Slingshot at customer meetings, industry events, and mission-focused forums • Communicate customer feedback and market insights to internal stakeholders to inform roadmap and go-to-market strategy • Perform other duties as assigned (less than 10%)

Arizona + 28 moreAll locations: Arizona | California | Colorado | District of Columbia | Florida | Hawaii | Illinois | Kansas | Montana | Nevada | New Jersey | New Mexico | New York | North Carolina | Oregon | Maryland | Massachusetts | Michigan | Minnesota | Missouri | Rhode Island | Tennessee | Texas | Utah | Vermont | Virginia | Washington | West Virginia | Wisconsin
$140K - $160K / year
Acronis logo

Cybersecurity Researcher, Threat Analysis, Detection Engineering

Acronis

Natively integrated, highly efficient cyber protection.

Security Engineer133 days ago
Full TimeRemoteTeam 1,001-5,000Since 2003H1B Sponsor

• Participate in design and implementation of detection capabilities of Acronis Security and EDR products. • Analyze clean and malicious content: executables, scripts, various document formats, websites, memory dumps, vulnerabilities. • Develop, support, and fine-tune threat detection logic and signatures. • Conduct online research of the latest cyber threats and ensure those can be detected by existing in-house technologies. • Contribute to sharing research results in blog posts and articles. • Monitor automated detection pipelines to ensure high detection accuracy. • Support scan engine and product development by participating in joint research projects.

Bulgaria