> Markdown version of [/jobs/ext/1603533-lead-security-engineer](https://www.wearedevelopers.com/jobs/ext/1603533-lead-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Security Engineer - **Company:** Gartner, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $116,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** HTML, Java (Programming Language), JavaScript (Programming Language), .NET Framework, PHP (Programming Language), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, C Sharp (Programming Language), Cloud Computing, Cloud Computing Security, Cyber Security, Computer Programming, Continuous Integration, Perl (Programming Language), Python (Programming Language), Windows PowerShell, Ruby, Software Vulnerability Management, Web Applications, Policy as Code, Scripting, Google Cloud, Software Security, Infrastructure as Code (IaC), Devsecops, Vulnerability Analysis - **Published:** July 17, 2026 - **Apply:** https://www.dice.com/job-detail/37f01049-02d8-40c3-9d4a-c72f8e21b837 ## About the Role Ideal candidates will have 6-8 years of experience in a Security Engineering role with proven experience in DevSecOps, Cloud Security, and Application Security. Candidates should have strong independent critical thinking, problem-solving skills, and the ability to consistently evaluate and pivot based on the current organizational priorities. Must Have: * Experience using vulnerability scanning technologies, AST platforms, and cloud security tooling. * Formal experience with threat modeling. * Experience leading projects, initiatives, and resources through direct and indirect leadership. * Deep knowledge of Assessing and prioritization of Risk with an ability to think like a bad actor and use that context to conduct threat models. * Cloud experience (AWS, Azure, Google Cloud Platform) * Infrastructure as Code (IaC) and Policy as Code (PaC) Concepts. Nice to Have: * Familiarity with technical security controls, guidelines, and frameworks outlined by standards such as SOC2, ISO 27001/27013, NIST 800-53. * Ability to automate tasks and code solutions to repetitive problems. * Scripting or programming experience (Java, .NET, HTML, Ruby, PHP, Perl, C#, Python, JavaScript, PowerShell, Bash) * Experience with penetration testing and web application assessment. Who you are: * Proven communication, collaboration, and critical thinking skills. * Ability to build trusting, meaningful relationships with peers, stakeholders, partners and suppliers. * Ability to define and communicate risk in a business-relevant language to both non-technical and technical audiences. * Ability to apply expert knowledge to solve complex business/technical issues strategically. * Desire for life-long learning and continuous personal/professional development ## Description The Lead Security Engineer will be responsible for supporting Gartner's AppSec function. This individual will play an integral role in, executing daily vulnerability Assessments functions; working closely with Information Security partners, and technology stakeholders to identify risks/vulnerabilities and collaborate with key stakeholders on remediation, developing and tracking risk/vulnerability remediation and prioritize effort across our various business units, partnering to implement security tools, technologies and controls with an appropriate balance of security, business, and user experience, while providing education and training; and engineer automation solutions and/or security tool integrations to assist with day-to-day AppSec responsibilities. What you'll do: * Collaborate with business stakeholders to design secure applications, test applications for security weakness, and partner on remediation of identified issues. * Mentor engineers and security champions on practical threat modeling techniques * Triage and prioritize security risks, vulnerabilities, and exceptions in alignment with business impact and risk tolerance. * Coordinate the orchestration, automation, and management of security technologies and platforms. * Own day-to-day life cycle management, including identification, threat assessment, threat modeling and risk avoidance. * Create reasonable and actionable reports showing direct impact to the security posture. * Define and implement meaningful metrics to measure the effectiveness of security controls through KRIs and security scorecards. * Serve as a subject-matter-expert for Application Security; act as a first point of contact for critical issues, security risk assessments and triaging CI/CD issues with Partners and stakeholders. * Evaluate business and technical requirements to identify and implement tools, processes, and technologies to improve our security posture in our environments. * Use data to drive prioritization, highlight systemic issues, and influence roadmap decisions ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [The Resilience of the World Wide Web](https://www.wearedevelopers.com/videos/1281-the-resilience-of-the-world-wide-web) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)