Software Security Engineer

Stefanini
Dearborn, MI, United States
4 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) JavaScript (Programming Language) Spring Security Amazon Web Services Apache Tomcat Software System Penetration Testing Microsoft Azure Burp Suite Cloud Computing Configuration Management Cyber Security Continuous Integration
+24 more
Linux DevOps Identity and Access Management Information Systems Security Architecture Professional Python (Programming Language) Network Security Systems Development Life Cycle Salesforce.Com Secure Coding Software Engineering Software Vulnerability Management Pega Data Logging Google Cloud ReactJS Spring-boot Software Security Technical Debt Information Technology Restful APIs Dynatrace Static Application Security Testing Programming Languages Dynamic Application Security Testing

Job description

We are looking for a Software Security Engineer with experience across software development, cybersecurity, cloud, DevOps, and IT. The ideal candidate can translate security risks into practical solutions, support vulnerability remediation, automate security processes, and contribute to compliance initiatives.

Key ResponsibilitiesPerform security plan reviews and secure code reviews for flagship services, products, and partner applications.Guide development teams in triaging and remediating findings from SAST, DAST, SCA, bug bounty programs, and vulnerability assessments.Develop automation scripts and tools to help identify and remediate security vulnerabilities.Serve as a security advocate within development teams and promote secure software development practices.Collaborate with software architects, developers, and DevOps teams to integrate security throughout the SDLC and CI/CD pipelines.Provide guidance on secure architecture, API security, IAM, logging, encryption, data protection, and secure coding practices across Azure, Google Cloud Platform, and AWS environments.Define and maintain security best practices based on current threats and vulnerabilities.Ensure access controls, data encryption, and data anonymization requirements are followed.Partner with incident response teams during security incidents and incorporate lessons learned into product and system hardening.Work with engineering teams to ensure security vulnerabilities are addressed within established SLAs.Support software supply-chain security, SBOM requirements, technical debt, and upgrade planning.Maintain security requirements, test plans, and other cybersecurity documentation.Support cybersecurity compliance activities, risk assessments, and related security requirements.Communicate complex technical risks clearly to both technical and business stakeholders.

Requirements

Required SkillsCybersecurity / Application SecuritySoftware Development and Secure SDLCScripting and automationWeb applications and web technologiesTCP/IP and network fundamentalsSoftware development lifecycleTroubleshooting and problem solvingData integrity and data modelingSecurity vulnerability remediationExperience working with developers and DevOps teamsExperience with at least two programming languages, or advanced proficiency in oneStrong communication and analytical skills

Preferred SkillsExperience with Java, JavaScript, Python, Spring Security, Spring Boot, Linux, React, REST/API security, IAM, cloud computing, Azure, Google Cloud Platform, AWS, Burp Suite, Dynatrace, Salesforce, Pega, Apache Tomcat, penetration testing, network security, risk management, ISO 27001, configuration management, and security compliance.

Experience Required6+ years of IT experience, 4+ years of software development experiencePractical experience in two coding languages or advanced practical experience in oneExperience with application security, cybersecurity, or secure software development preferredExperience supporting cybersecurity compliance activities is a plusCISSP, CISA, CISM, or similar certifications are highly valued

Education requiredBachelor’s degree

Education preferredMaster’s degree

About the company

The Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application, and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like the Americas, Europe, Africa, and Asia, and more than four hundred clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting company with a global presence. We are a CMM Level 5 company.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all