As an employer, Abbott is interested in candidates who are passionate about creating healthy solutions and making a difference in the world. Abbott offers compe
Senior Cybersecurity Engineer
Location
United States
Posted
15 days ago
Salary
$86.7K - $173.3K / year
Seniority
Senior
Job Description
Senior Cybersecurity Engineer
Abbott
• Develop and deliver cybersecurity artifacts for product software releases, including SBOMs, vulnerability remediation evidence, and release security documentation. • Lead technical reviews with development teams to discuss vulnerabilities, security controls, remediation progress, and residual risk. • Prioritize vulnerability remediation and patching efforts based on business impact, proof of exploit, and policy requirements, partnering with engineering, PMs, and product owners to drive timely risk reduction. • Design and recommend systematic remediation strategies and preventive controls to reduce recurring vulnerabilities, including secure coding practices, dependency management, and configuration hardening across product and supporting applications. • Triage and analyze findings from application, network‑based, and agent‑based security scanning tools (SAST, DAST, SCA, infrastructure scanners) to determine true security impact, validate exploitability, and distinguish false positives. • Validate security fixes through hands‑on testing, including web application testing using tools such as Burp Suite and Postman, and verification of remediation for iOS and Android mobile application vulnerabilities. • Clearly communicate complex technical security concepts to executive leadership and cross‑functional stakeholders, translating vulnerability findings, security controls, and security metrics into business‑relevant risk insights and decision support. • Lead remediation efforts after security assessment findings outline weaknesses requiring attention. • Support the advancement of cyber threat and vulnerability management program to ensure consistent identification, analysis, response, and monitoring of cyber security threats, events, and vulnerabilities. • Leverage JIRA for security project and vulnerability management, building dashboards, reports, and automation workflows to track remediation progress, improve visibility of security metrics, and streamline coordination across cross‑functional teams. • Participate in cross-functional team coordination to achieve defined security goals as well as meet technical requirements in support of detailed implementation plans for security projects. • Provide technical advice and training about potential security risks and prevention strategies.
Job Requirements
- Bachelor's degree in computer and information sciences or engineering, Security Systems, or related fields.
- Minimum 3 years of IT management system, cybersecurity, or other relevant experience with a strong preference for product security (i.e. – consumer facing applications and services).
- Minimum 5 years of Business experience.
- Demonstrated hands‑on experience conducting web, mobile, and cloud infrastructure security testing using DAST, SAST, SCA, SBOM generation tooling, and network‑ and agent‑based vulnerability scanning tools.
- Ability to prioritize multiple projects with strong organization skills.
- Demonstrated critical thinking, analytical skills, judgment, and logic for problem-solving and decision-making in an environment with changing priorities.
- Ability to work effectively in a team environment, adapting to rapidly changing business and technological needs.
- Excellent documentation, communication and interpersonal skills.
- Preferred: Holds or working toward one or more relevant certifications such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Ethical Hacker (CEH), or equivalent.
Benefits
- Career development with an international company where you can grow the career you dream of.
- Employees can qualify for free medical coverage in our Health Investment Plan (HIP) PPO medical plan in the next calendar year.
- An excellent retirement savings plan with high employer contribution.
- Tuition reimbursement, the Freedom 2 Save student debt program and FreeU education benefit - an affordable and convenient path to getting a bachelor’s degree.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Plan, coordinate and implement security solutions • Provide strategic and operational advice to clients on information security, ISMS and regulatory requirements (especially NIS2) • Manage measures for the sustainable implementation of security concepts • Establish, further develop and document ISMS according to ISO 27001 / ISO 2700x • Conduct gap analyses, risk assessments and maturity assessments • Prepare and support ISO 27001 certifications and internal/external audits • Implement and assess NIS2 requirements, including governance, risk management and reporting processes • Prepare and support regulatory assessments and examinations (e.g., NIS2) • Design and deliver training and awareness measures • Develop and improve incident management and contingency/emergency plans • Create business continuity plans and security policies
Role Description We are seeking a mid-level Cloud Security Engineer to join our Security Engineering team. This role is the first dedicated hire for cloud security within the organisation and will be critical in defining, implementing, and managing security controls across our Azure, AWS and SaaS environments. The successful candidate will work independently, reporting to the Head of Security Engineering, while collaborating with SOC, GRC, IT, Modern Workplace and Systems Engineering teams to build and mature our cloud security posture. Key Responsibilities - Cloud Security Framework: Define and implement the cloud security Framework in collaboration with IT Systems, SOC leadership, and GRC. - Implementation: - Recommending security best practices and implementing controls for Cloud Security and governance. - Implementation of automated security tooling to validate security requirements and identify potential issues. - Threat Detection & Incident Response: - Define threat detection and incident response processes and playbooks for cloud environments. - Collaborate with the SOC to operationalise detection rules and incident handling. - Compliance & Audit: - Support GRC in meeting evidence and compliance requirements for ISO27001, NCSC Cloud Security Principles, and SOC2. - Reviewing the outputs from security tools and security practices, filtering and prioritising these into security stories that can be understood and actioned by the delivery teams. - Collaboration & Enablement: - Influence and guide junior engineers and developers to adopt secure practices. - Upskill and train the wider security team in cloud security topics and tooling. - Identity & Access Management: - Provide input into IAM strategy and policy (RBAC, Conditional Access, MFA, least privilege), working closely with the IT and Systems teams. - Optional / Beneficial Areas: - Support automation of cloud security (IaC scanning, CI/CD integration). - Document standards, runbooks, and training material where appropriate. Qualifications - Previous experience in cloud security engineering or related roles. - Working knowledge of industry cloud security frameworks and best practice (CSA STAR, NCSC Cloud Security Principles). - Experience with automation and scripting (Python, PowerShell, Bash). - Proficiency with: - Azure security services: Defender for Cloud, Entra ID, Sentinel etc. - AWS security services: Security Hub, GuardDuty, IAM, Config, CloudTrail, CloudWatch. - Working knowledge of cloud incident response processes and procedures. - Strong understanding of security best practices in multi-cloud environments. Desirable Skills & Experience - Familiarity with Infrastructure as Code (Terraform). - Knowledge of cloud network security concepts (firewalls, NSGs, VPCs, private endpoints). - Exposure to compliance frameworks (ISO27001, SOC2, NCSC Cloud Security Principles). - Security certifications such as AZ-500, SC-100, AWS Security Specialty, CISSP, or CCSK. Embracing our differences At Kainos, we believe in the power of diversity, equity and inclusion. We are committed to building a team that is as diverse as the world we live in, where everyone is valued, respected, and given an equal chance to thrive. We actively seek out talented people from all backgrounds, regardless of age, race, ethnicity, gender, sexual orientation, religion, disability, or any other characteristic that makes them who they are. We also believe every candidate deserves a level playing field. Our friendly talent acquisition team is here to support you every step of the way, so if you require any accommodations or adjustments, we encourage you to reach out. We understand that everyone's journey is different, and by having a private conversation we can ensure that our recruitment process is tailored to your needs.
Security Specialist – Mid
LeidosLeidos is an innovation company rapidly addressing the world’s most vexing challenges in national security and health.
• Supports the SEC ISS contract by helping maintain a secure and compliant IT infrastructure through disciplined POAM and vulnerability management • Identifies, tracks, and assists with remediation of security vulnerabilities across infrastructure systems • Supports risk management activities, including documentation, reporting, and audit remediation support required to sustain operational authorization and security posture • Coordinates with technical teams to plan mitigation actions, drive POAM closure, and reduce recurring security risk • Supports development, implementation, and management of POAMs for IT infrastructure security findings • Tracks POAM milestones, ownership, due dates, and dependencies; escalates risks to closure timelines • Validates remediation evidence and updates POAM records to reflect status and completion • Maintains accurate POAM reporting to support contract deliverables and SEC oversight • Reviews vulnerability findings and assists with severity/impact assessment and prioritization • Coordinates with infrastructure and operations teams to implement timely remediation actions • Assists in resolving vulnerabilities through patching, configuration correction, and compensating controls • Helps monitor open vulnerabilities and promotes proactive measures to reduce reintroduction of findings • Supports security risk and compliance activities for ISS-supported systems • Assists with security documentation aligned to SOPs, change control, and system baselines • Provides support for audit remediation activities, including internal reviews and external oversight audits • Prepares recurring status updates on vulnerability trends, POAM health, and mitigation progress • Records remediation actions and supporting evidence in approved workflows • Coordinates with cross-functional teams to resolve blockers affecting remediation timelines • Supports surge and incident follow-up activities only as directed by contract tasking
• Define and design secure software architectures, establishing security patterns and guidelines for Java and Go applications. • Ensure that applications and platforms are protected by deploying and integrating security solutions across multiple technologies and geographies. • Design, implement, and standardize cryptography mechanisms, SSL/TLS certificate lifecycle management, and secret protection. • Lead and coordinate local and global security initiatives, aligning projects with international teams.




