> Markdown version of [/jobs/ext/1320389-security-engineer](https://www.wearedevelopers.com/jobs/ext/1320389-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Cinc Systems - **Location:** United States (Remote available) - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), JavaScript (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Amazon Cloudfront, Amazon Elastic Compute Cloud, Amazon S3, Business Logic, Software System Penetration Testing, Application Testing, User Authentication, Bash Shell, Burp Suite, C Sharp (Programming Language), Apache Lucene, Code Review, Computer Networks, Continuous Integration, Information Leak Prevention, DevOps, Distributed Systems, Federated Identity Management, Identity and Access Management, Python (Programming Language), Key Management, Network Segmentation, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Windows PowerShell, Systems Development Life Cycle, Role-Based Access Control, Cloud Services, Fortify (Software), Red Team (Cyber Security), Kusto Query Language, JSON Web Token, Security Assertion Markup Language (SAML), Secure Coding, Session Management, Security Information and Event Management, SQL Databases, Data Streaming, Tripwire, TypeScript, Software Vulnerability Management, Web Applications, YAML, Policy as Code, AWS Cdk, Data Logging, S3 Bucket, Scripting, Delivery Pipeline, Large Language Models, Multi-Agent Systems, Sonatype, Software Security, Mitre Att&ck, Kubernetes Helm Charts, Veracode, Amazon Virtual Private Cloud (VPC), Cloudformation, Kotlin, Amazon Relational Database Service, GWAPT, Kubernetes, Cybercrime, Microsoft Sentinel, Bitbucket, Machine Learning Operations, Route53, Checkmarx, Opsworks, Functional Programming, CIS Benchmarks, Api Design, Cloudwatch, Api Gateway, Terraform, Prisma Cloud Platform, Splunk, Automation Anywhere, Api Management, Security Orchestration, Automation & Response, Jenkins, Static Application Security Testing, Golang, Microservices, Dynamic Application Security Testing - **Published:** July 17, 2026 - **Apply:** https://www.dice.com/job-detail/31c59e66-376e-4551-bcd9-c82bd7a8639b ## About the Role We are looking for a highly technical Security Engineer with deep experience across application security, AWS cloud security, offensive security, secure SDLC, threat modeling and AI security. This role is suited for someone who can operate at both the engineering and adversarial levels by reviewing architecture, testing applications, identifying exploitable weaknesses, automating security workflows, securing AWS infrastructure and helping product teams build resilient systems. The ideal candidate has hands-on experience with SAST, DAST, SCA, manual application security testing, AWS security reviews, red teaming, SIEM-driven detection workflows, infrastructure-as-code security and security automation. They should be comfortable working directly with engineering teams while also thinking like an attacker to uncover realistic abuse paths across applications, APIs, AWS services, CI/CD pipelines and AI-enabled systems., * Strong hands-on experience in application security, product security, AWS cloud security, offensive security or security engineering. * Deep understanding of secure SDLC practices and experience embedding security into engineering workflows. * Practical experience with SAST, DAST, SCA, manual penetration testing, code review and vulnerability validation. * Strong knowledge of OWASP Top 10, OWASP API Security Top 10, OWASP ASVS, common CWE classes and real-world application attack techniques. * Experience testing web applications, APIs, microservices, cloud services, containers and distributed systems. * Strong understanding of authentication, authorization, identity federation, OAuth, OIDC, SAML, JWT, session security and access control design. * Hands-on experience securing AWS environments in production. * Strong knowledge of AWS IAM, VPC networking, encryption, KMS, Secrets Manager, S3 security, CloudTrail, GuardDuty, Security Hub, AWS Config and workload hardening. * Experience reviewing infrastructure-as-code and identifying security issues in Terraform, CloudFormation, AWS CDK, Kubernetes YAML, Helm, Dockerfiles or similar technologies. * Experience with CI/CD security across tools such as bitbucket pipelines, Jenkins, AWS CodePipeline, or similar platforms. * Experience with red teaming, adversary emulation, penetration testing, exploit development, attack path mapping or offensive security assessments. * Familiarity with SIEM platforms and the ability to write detection or hunting queries using SPL, KQL, SQL, Lucene, YARA, Sigma or similar languages. * Strong scripting ability in Python, Bash, PowerShell, JavaScript or similar languages. * Ability to automate repetitive security tasks and build internal tools that improve security testing, visibility and response. * Familiarity with container and Kubernetes security, including ECS,EKS, RBAC, admission controls, image scanning, runtime controls, network policies and secrets handling. * Ability to review code in languages such as Python, JavaScript, TypeScript, Java, Go, Kotlin, C# or similar. * Strong written and verbal communication skills, with the ability to explain complex technical risks to engineering and leadership teams. Preferred Qualifications * Experience securing AI-enabled applications, LLM products, autonomous agents, RAG pipelines, AI plugins or ML infrastructure. * Experience performing AI red teaming, prompt injection testing, jailbreak testing, model abuse testing or evaluation of agentic workflows. * Experience with AWS Organizations, Control Tower, service control policies, multi-account security patterns and centralized logging. * Experience with threat modeling methodologies such as STRIDE, PASTA, attack trees, abuse cases, data flow diagrams or architecture risk reviews. * Experience with security automation, SOAR workflows, detection-as-code, policy-as-code or cloud security posture automation. * Experience with tools such as Burp Suite Pro, OWASP ZAP, Semgrep, CodeQL, Checkmarx, Fortify, Veracode, Snyk, Dependabot, Trivy, Grype, Syft, Gitleaks, Checkov, tfsec, Prowler, ScoutSuite, Wiz, Prisma Cloud or similar. * Experience building custom security tooling, scanners, exploit harnesses, detection rules, cloud guardrails or CI/CD security integrations. * Experience with MITRE ATT&CK, MITRE ATLAS, CIS Benchmarks, AWS Well-Architected Security Pillar, NIST, ISO 27001, SOC 2, PCI DSS or similar frameworks. * Experience with bug bounty programs, coordinated vulnerability disclosure, internal red team programs or external penetration testing engagements. * Relevant certifications such as OSCP, OSWE, OSEP, GWAPT, AWS Certified Security Specialty, AWS Solutions Architect, CISSP or equivalent practical experience. ## Description * Lead security reviews for web applications, APIs, microservices, AWS workloads, internal platforms and AI-enabled products. * Perform advanced application security testing using SAST, DAST, SCA, manual code review, API testing and business logic testing. * Identify vulnerabilities across authentication, authorization, session management, access control, injection, SSRF, deserialization, insecure file handling, data exposure and insecure API design. * Conduct threat modeling for new products, critical features, AWS architectures, AI workflows, identity systems and high-risk data flows. * Build and improve secure SDLC processes, including security requirements, code scanning, dependency review, CI/CD security gates and release risk assessments. * Review infrastructure-as-code templates such as Terraform, CloudFormation, AWS CDK, Helm charts and Kubernetes manifests for security misconfigurations. * Assess AWS environments for IAM weaknesses, exposed services, insecure networking, public S3 buckets, secrets leakage, logging gaps, encryption issues, workload risks and privilege escalation paths. * Review AWS IAM policies, roles, trust relationships, permission boundaries, service control policies, identity federation and cross-account access patterns. * Assess AWS services such as EC2, S3, Lambda, ECS, EKS, RDS, API Gateway, CloudFront, WAF, KMS, Secrets Manager, Systems Manager, ECR, VPC, Route 53 and IAM Identity Center. * Conduct red team exercises, adversary simulations, attack path analysis and controlled exploitation to validate real-world risk. * Develop proof-of-concept exploits, custom scripts and automation to reproduce vulnerabilities and demonstrate business impact. * Evaluate containerized and Kubernetes environments, including EKS, for workload isolation, RBAC issues, exposed services, image risks, secrets handling and runtime security gaps. * Assess CI/CD pipelines for insecure workflows, overprivileged tokens, secrets exposure, supply chain risks, artifact integrity and deployment abuse paths. * Perform software composition analysis to identify vulnerable dependencies, license risks, malicious packages, transitive dependency exposure and supply chain weaknesses. * Use SIEM and security telemetry to support investigations, validate attack paths, improve detections and measure control effectiveness. * Build detection logic, threat hunting queries, dashboards and alerting workflows using SIEM platforms such as Splunk, Microsoft Sentinel, Elastic, Chronicle or AWS-native telemetry. * Use AWS security services such as GuardDuty, Security Hub, CloudTrail, AWS Config, Inspector, Detective, Macie, IAM Access Analyzer, Security Lake and CloudWatch to improve visibility and detection coverage. * Automate security workflows using Python, Bash, PowerShell, Go or similar scripting languages. * Develop threat automation for vulnerability enrichment, alert triage, AWS posture checks, attack simulation, evidence collection and remediation tracking. * Partner with DevOps and platform teams to improve secrets management, identity controls, network segmentation, logging, monitoring and secure deployment patterns. * Assess AI and LLM-based systems for risks such as prompt injection, indirect prompt injection, data leakage, insecure tool use, excessive agency, jailbreaks, model abuse, retrieval poisoning and unsafe agent behavior. * Review AI workloads using AWS services such as Amazon Bedrock, SageMaker, Lambda, API Gateway, S3, KMS and IAM for secure design, data protection and access control. * Produce clear technical reports with evidence, exploitability, impact, likelihood, risk rating and actionable remediation guidance. * Mentor engineers and security team members on secure coding, AWS security, offensive testing, threat modeling and AI security risks., * SAST, DAST, SCA, secrets scanning, IaC scanning and AWS posture checks are implemented with practical tuning and low operational noise. * High-risk application and AWS vulnerabilities are identified early, validated accurately and remediated with engineering partnership. * Threat models are used to influence architecture decisions before systems reach production. * Red team findings translate into improved controls, stronger detections and reduced attack paths. * SIEM, AWS logs and security telemetry are used to validate security controls and detect realistic abuse scenarios. * Security automation reduces manual review effort and accelerates vulnerability management, investigation and remediation. * AI-enabled systems are reviewed for emerging threats before they are released or scaled. * Engineering teams view security as a technical partner that helps them ship resilient products. ## Related Videos - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)