Hypori logo
Hypori

Never Trust, Always Verify - Hypori Halo Zero Trust BYOD

Senior Software Engineer – Application & Cloud Security

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 51-200H1B No SponsorCompany SiteLinkedIn

Location

Texas

Posted

3 days ago

Salary

$180K - $195K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishAWSCloudVault

Job Description

Senior Software Engineer – Application & Cloud Security

Hypori

• Maintain a deep understanding of the security aspects of Hypori's product/system architecture and implementation patterns; collaborate with engineering teams on threat models; participate in design and architecture reviews; and engage across scrum teams to surface and address application security, privacy, and compliance concerns. • Be the go-to AppSec expert for software engineering, security, and compliance teams. Mentor engineers on application security principles, secure design patterns, and secure coding practices; grow security capability and awareness through thought leadership and active engagement. • Develop and maintain software security patterns to enable security/compliance/privacy-by-default engineering, such as: secure coding and configuration standards, code snippets/templates for Infrastructure as Code, hardening of containerized applications, etc. • Lead automation and integration of vulnerability management tooling – including SAST, DAST, and SCA tools – across artifact repositories, container registries, and other components of development and build pipelines. • Perform security-focused code reviews on request, providing targeted guidance on security-sensitive components and implementation decisions. • Triage vulnerability and compliance testing results for technical implications, validate their applicability, determine exposure in a system/component context, and generate user stories for remediation efforts. • Contribute to technical compliance strategies and hardening across cloud infrastructure, development/QA environments, and system components (such as FIPS-validated crypto configurations and network segmentation); implement quality gates and security test suites across development and build pipelines. • Actively contribute to the success of Hypori’s Security Champions program. • Participate in Engineering on-call rotations to provide application security expertise during incident triage and response. • Protect intellectual property, user data, and system integrity by (a) adhering to Hypori's policies and procedures for secure software development and (b) following best practices for secure product design, implementation, and deployment of development, build, test, production, and other environments.

Job Requirements

  • Must be a US Citizen or US Permanent Resident
  • 5+ years of hands-on software engineering experience, with a demonstrated focus on building and securing production systems.
  • Proficient in at least one programming language.
  • Proficient in understanding and explaining the ins and outs of software vulnerabilities across stacks, their potential impact when exploited, and how to mitigate them.
  • Proficient in the security management of cloud infrastructure services and container-based deployments.
  • Proficient in the management of software supply chain security aspects, including the management of software security vulnerabilities in dependencies.
  • Proficient in secrets management practices and tooling (e.g., HashiCorp Vault, AWS Secrets Manager), including automated secrets scanning in development workflows and CI/CD pipelines.
  • Proficient in expressing the concepts, practical application, and typical implementation of identity & access management, applied cryptography, network security, and related security domains.
  • Proficient in API security concepts and their application, authentication and authorization patterns (OAuth 2.0, OIDC), and secure API design principles.
  • Proficient in concisely articulating both technical risk and the trade-offs of proposed solutions to decision makers and peers.
  • Experience with modern CI/CD pipelines, scrum-based engineering practices, and the automation, integration, and centralized management of security and compliance tooling across development lifecycles.
  • Experience in interpreting security and compliance frameworks and standards.
  • Experience with application security testing tools and techniques, and with demonstrating/validating the exploitability of vulnerabilities.
  • Experience with AI/LLM-assisted tooling to automate application security tasks, and ability to advise software engineers on the security, compliance, and privacy implications of their use.

Benefits

  • Medical, dental, and vision insurance
  • Parental leave
  • Life and disability packages
  • 401(k) plan with employer-matching contributions
  • Performance bonus

Related Categories

Related Job Pages

More Security Engineer Jobs

GuidePoint Security logo

Strategic Security Advisor – Northeast Region

GuidePoint Security

Founded in 2011 and headquartered in Herndon, Virginia, GuidePoint Security furnishes commercial and federal organizations with customized information security

• Establish and maintain deep, consultative relationships with customer executives and security leaders, serving as their primary trusted advisor on cybersecurity matters • Identify and uncover opportunities where GuidePoint Security solutions can address customer cybersecurity needs and business objectives • Provide expert guidance on cybersecurity strategy, risk management, and security program development tailored to each customer's unique environment • Represent GuidePoint Security as a subject matter expert in the cybersecurity community through speaking engagements, publications, and industry events • Partner closely with sales, delivery, and product teams to ensure seamless customer experiences and drive solution alignment • Stay current on emerging threats, industry trends, and regulatory requirements affecting customers in the region, and proactively communicate relevant insights to customers • Serve as a senior resource and mentor to colleagues, contributing to the development of best practices, methodologies, and advisory frameworks across the organization

New York

Role Description This position is in the Department of the Chief Information Office, Information Technology Security Office (ITSO), Security Operations Division. ITSO manages the Judiciary's IT security program, oversees the security operations of Judiciary IT assets and environments, proposes national IT security policies and develops guidelines for their implementation, and establishes and maintains collaborative relationships within the Judiciary and with third-party partners. The Supervisory Information Technology Specialist (Security) serves as the Security Operations Support Branch Chief within the Security Operations Support Branch (SOSB). The incumbent is responsible for leading detection engineering, threat hunting, and threat intelligence teams to identify cybersecurity threats that impact the confidentiality, integrity, and availability of judicial data. The position reports to the SOD Division Chief and is critical to protecting the confidentiality, integrity, and availability of Judiciary information systems. - Providing leadership, direction, and oversight for the Security Operations Support Branch, which delivers enterprise detection engineering, threat hunting, and threat intelligence capabilities in support of continuous cybersecurity operations. - Overseeing the development, testing, deployment, and lifecycle management of detection logic used to identify malicious activity across the Judiciary's information technology environment. - Leading the production and operational integration of threat intelligence to inform detection engineering priorities, threat hunting activities, and risk-based decision-making. - Directing proactive threat hunting efforts to identify emerging, novel, or evasive adversary behaviors not addressed by existing detection mechanisms. - Establishing and maintaining detection engineering standards, methodologies, and quality assurance processes to ensure accuracy, consistency, and operational effectiveness. - Overseeing the validation, tuning, and refinement of detections based on operational feedback, adversary emulation results, and observed threat activity. - Ensuring the development of metrics and reporting to measure detection coverage, effectiveness, and operational maturity. - Leading the development and maintenance of a common operational picture that identifies baseline activity and highlights meaningful deviations to support situational awareness, prioritization, and leadership decision-making. - Providing executive summaries and briefings to senior leadership and cybersecurity stakeholders to support enterprise risk awareness, prioritization, and resource allocation. - Coordinating with the Security Operations Center to improve alert fidelity, investigative workflows, and analytic outcomes. - Managing branch personnel, contractor support, and resource planning to sustain required capabilities. - Performing duties consistent with the skills, knowledge, and abilities defined in NIST Special Publication 800-181 (NICE Cybersecurity Workforce Framework) for Program Management (OG-WRL-010), Threat Analysis (PD-WRL-006), and Defensive Cybersecurity (PD-WRL-001) roles. Qualifications - Demonstrated experience leading enterprise detection engineering, threat hunting, and cyber threat intelligence programs in support of continuous cybersecurity operations and organizational cyber defense objectives. - Experience directing the development, implementation, and execution of proactive threat hunting strategies to identify sophisticated, emerging, or previously undetected adversary activity across enterprise environments. - Established and maintained governance, standards, methodologies, and quality assurance processes for detection engineering programs to ensure operational effectiveness, consistency, and alignment with organizational cybersecurity objectives. - Experience leading the production, analysis, and operational integration of cyber threat intelligence to inform detection engineering priorities, guide threat hunting activities, and support risk-based cybersecurity and organizational decision-making. Requirements - At least one full year (52 weeks) of specialized experience in or directly related to the line of work of this position. Benefits - Desired (but not required) certifications: - Offensive Security Professional (OSCP) - GIAC Reverse Engineering Malware (GREM) - GIAC Certified Forensic Analyst (GCFA) - GIAC Exploit Researcher and Advanced Penetration Tester (GXPN) - Offensive Security certifications relevant to malware or exploit analysis

United States
$106.4K / year
Packetlabs logo

Ethical Hacker – OT Security Consultant

Packetlabs

Ready to strengthen your security posture?

Full TimeRemoteTeam 51-200Since 2011H1B No Sponsor

• Security Architecture Reviews • Perform holistic tabletop reviews covering both technical and non-technical risk across OT environments, without engaging in high-risk manual or automated activity • Analyze for areas of negative impact, high risk, and single points of failure (SPOF) within sensitive, legacy networks • Apply structured judgment to identify where risk is concentrated and where controls are missing • Adapt review depth and approach to the operational realities of each client environment • OT Risk Identification & Assessment • Identify vulnerabilities and weaknesses across Operational Technology environments, including Industrial Control Systems (ICS), SCADA, and field devices • Assess legacy and sensitive networks where conventional testing methods carry unacceptable operational risk • Distinguish between theoretical and operationally relevant risk to keep findings actionable • Prove impact where appropriate, exercising restraint where the environment demands it • Client Advisory & Program Improvement • Support OT clients with security program improvements, identifying which critical controls are needed • Refine testing scope collaboratively as engagements proceed and the environment becomes clearer • Translate technical findings into guidance that clients can act on across both technical and leadership audiences • Build client confidence through credibility, clear communication, and operational awareness • Methodology & Continuous Improvement • Contribute to the maturity of Packetlabs' OT testing methodology and practice • Stay current on OT threats, attack techniques, and defensive controls • Share knowledge with the broader team to minimize blind spots and strengthen collective capability • Help raise the standard of OT security work across the firm

Texas
Full TimeRemoteTeam 11-50Since 2012H1B No Sponsor

• Design and refine security profiles for NATO communication standards • Analyze compliance with NATO Data Centric Security (DCS) requirements • Develop proof-of-concept implementations and concept demonstrators • Support interoperability and validation exercises • Design and execute security validation testing • Produce technical specifications and standards documentation • Develop and maintain software components supporting secure information exchange • Contribute to SCRUM-based development teams • Support knowledge transfer and technical handover activities

Poland