> Markdown version of [/jobs/ext/2433066-security-engineer](https://www.wearedevelopers.com/jobs/ext/2433066-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Greenstar Holdings, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $150,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Application Programming Interfaces (APIs), Agile Methodology, Artificial Intelligence, Amazon Web Services, Applications Architecture, Software System Penetration Testing, User Authentication, Microsoft Azure, Cloud Computing, Cloud Computing Security, Code Review, Collaborative Software, Cyber Security, Continuous Integration, Identity and Access Management, Issue Tracking Systems, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Open Web Application Security, Windows PowerShell, Scrum Methodology, Comptia Pentest+ CE, Red Team (Cyber Security), Secure Coding, Information Technology Security Auditing, Security Information and Event Management, Software Engineering, Systems Integration, Software Vulnerability Management, Web Applications, Scripting, Delivery Pipeline, Large Language Models, Software Security, Mitre Att&ck, Cyber Threat Analysis, Cross-Site Scripting (XSS), Information Technology, Tenable Nessus, RSA Archer Platform, Virtual Agents, Devsecops, Serverless Computing, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a9b7220971fc27c2 ## About the Role * Bachelor's degree in Computer Science, Information Security, Engineering, or related technical field, or equivalent professional experience * 5-7 years of experience in security engineering with demonstrated expertise in multiple security domains, including application security Technical Skills * Expert knowledge of vulnerability management platforms * Proficient in MITRE ATT&CK mapping for detection rules and incident response * Strong experience with SAST, DAST, and SCA tooling for application security * Deep understanding of application vulnerabilities (OWASP Top 10, injection flaws, XSS, authentication bypasses) * Hands-on scripting experience building cloud-based automation (serverless functions, event-driven pipelines, secrets management) * Experience with, or strong interest in, AI agent engineering and tool-integration protocols for security operations * Proficiency administering EDR platforms * Experience with SIEM administration * Solid understanding of IAM platforms and federation/SSO concepts * Proficiency in cloud security (AWS, Azure, or GCP) * Solid understanding of WAF configuration and audit * Proficiency in scripting and automation (Python required; PowerShell a plus) * Understanding of DevSecOps and secure CI/CD practices * Practical experience with AI-powered security tooling, including building or operating LLM-based agents, and awareness of emerging AI threats (prompt injection, tool/agent security risks) * Ability to produce dashboards and reporting for technical and executive audiences Platform & Domain Experience * SIEM administration * Security automation/orchestration, including AI agent-based automation * Vulnerability management platforms * EDR platforms * DLP platforms * GRC platforms * SAST tooling * DAST tooling * SCA / dependency scanning tooling * Cloud security (AWS, Azure, or GCP) * Threat intelligence platforms * Ticketing and collaboration platforms Soft Skills & Experience * Strong analytical thinking and problem-solving capabilities * Excellent communication skills for technical and business audiences * Strong Agile proficiency with ability to integrate security into sprint planning * Experience collaborating with development teams and partnering on secure coding * Ability to translate technical vulnerability findings into actionable remediation guidance * Strong written communication skills for security documentation, audit responses, and questionnaire completion * Act as escalation point for Security Analysts * Participate in project security reviews * Support sales team with security questionnaires * Participate in customer security calls Preferred Qualifications: Certifications * CySA+ (CompTIA) * Cloud Security certification (AWS, Azure, or GCP) * GIAC GSEC * Certified Ethical Hacker (CEH) * GIAC GWEB (Web Application Penetration Tester) * CompTIA PenTest+ (optional) * GIAC GCTI (Cyber Threat Intelligence) (optional) * SIEM Platform Certification (optional) Additional Experience * DevSecOps experience integrating SAST/DAST into CI/CD pipelines * Secure software development lifecycle (SSDLC) implementation experience * Compliance experience with SOC 2, ISO 27001, or industry-specific regulations * Experience with security audit preparation and vendor risk assessment programs * Threat intelligence analysis and integration experience * Experience coordinating third-party penetration testing * Security awareness training development and delivery * Experience building or integrating LLM-based agents/automation for security operations * Experience with container and Kubernetes security concepts ## Description We are seeking an experienced Security Engineer to join our growing security team in a multifaceted role that combines vulnerability management, application security, MITRE ATT&CK-based threat detection, AI-driven security automation, and security engineering expertise. This position requires a technical security professional with knowledge spanning cloud security, identity and access management (IAM), endpoint detection and response (EDR), SIEM administration, and hands-on scripting for automation development. The successful candidate will work closely with development teams, infrastructure teams, vendors, and internal stakeholders to optimize our security posture and manage enterprise risk., Application Security & Vulnerability Remediation * Lead application security vulnerability remediation efforts across development teams * Administer SAST tooling * Administer DAST tooling * Administer SCA and software composition / dependency scanning tools * Triage and validate vulnerability findings to reduce false positives * Provide remediation guidance to development teams on OWASP Top 10 and secure coding practices * Integrate scanning tools with ticketing systems and CI/CD pipelines * Generate AppSec metrics and reports * Provide security code review support Vulnerability Assessment & Management * Administer vulnerability management platforms * Configure scan policies, schedules, and asset groups * Validate and prioritize vulnerability findings using risk-based prioritization (CVSS + context) * Conduct expert analysis and risk scoring of vulnerabilities * Coordinate remediation with IT and development teams * Manage vulnerability exceptions and risk acceptances * Track vulnerability aging and SLA compliance * Generate management reports and dashboards * Participate in product vulnerability management meetings * Participate in Security by Design reviews MITRE ATT&CK & Threat Detection * Develop detection rules mapped to ATT&CK techniques * Implement ATT&CK-based alert triage workflows * Configure SIEM correlation rules using ATT&CK * Conduct gap analysis of ATT&CK coverage * Integrate threat intelligence feeds with ATT&CK mapping * Build ATT&CK-based hunting queries * Create ATT&CK-mapped incident reports AI-Driven Security Automation & Agent Engineering * Build and maintain scripted, cloud-based automation pipelines supporting the team's AI-driven security operations platform * Develop and tune AI agent prompts, verdict logic, and disposition rules for automated alert triage * Extend the team's internal tool-integration framework connecting security platforms for AI-assisted operations * Integrate automation with SIEM, EDR, and ticketing systems * Build automated enrichment and reporting workflows * Monitor and tune agent/automation performance and disposition accuracy * Develop custom integrations using APIs and cloud-native services * Maintain observability for automated security workflows Security Engineering & Architecture * Lead Tier 2/3 security incident investigation and response * Administer EDR, SIEM, and IAM platforms * Implement and tune detection rules and alerts * Manage cloud security configurations * Support penetration testing and red team activities * Conduct WAF/CDN rule audits and configuration reviews * Provide security engineering expertise for infrastructure and application architecture decisions * Support complex security investigations requiring deep technical analysis * Contribute to security design reviews and technical security standards Policy & Threat Intelligence * Draft and review security policies and procedures * Conduct policy gap analysis against frameworks * Analyze threat intelligence from multiple sources * Integrate threat feeds into detection and automation workflows * Implement IOC blocking and detection rules * Participate in information sharing communities (ISACs) * Create threat intelligence reports ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)