Senior Security Engineer

ScienceJobs.Org
Norfolk, VA, United States
1 day ago
Apply on sciencejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Amazon Web Services Microsoft Azure Bash Shell Cloud Computing Cloud Computing Security Cloud Engineering Continuous Integration Identity and Access Management Intrusion Detection Systems Virtual Private Networks (VPN) Python (Programming Language) Network Security
+10 more
Lightweight Directory Access Protocols (LDAP) OAuth OpenID Windows PowerShell Security Information and Event Management Diagnostic Tools Scripting Computer Equipment Information Technology Devsecops

Job description

The Senior Security Engineer will serve as a technical leader within the security engineering team, overseeing various Security Tooling and project initiatives while providing mentorship, guidance, and strategic direction for security engineering efforts. This position will support the Security Engineering Manager by coordinating projects, ensuring alignment with security best practices, and assisting in the development of security engineering staff., This is a remote position, requiring a traditional 40-hour work week. Computer equipment will be supplied for remote work; high-speed internet is the responsibility of the employee. The equipment provided to staff with approved telework agreements enables them to deliver vital services to University faculty, staff, and students from remote locations. Many of our operations can and should continue as usual, even when the main physical campus is closed. Therefore, all division employees with an approved telework agreement are generally expected to work during official University closures.

Should travel be required, budgetary constraints may limit where the successful candidate can reside. In addition, existing payroll limitations on locations a remote employee may work from could limit the selection of the final candidate.

Requirements

Strong IAM knowledge, including familiarity with LDAP, OAuth, OpenID, and cloud-native identity services Proficiency in cloud security tools such as Cloud Access Security Brokers (CASB), Cloud Security Posture Management (CPSM), Cloud Identity Entitlement Management (CIEM), or Cloud Workload Protection (CWP) Advanced scripting and automation skills with Python, PowerShell, Bash or other scripting languages. Strong understanding of modern security frameworks. Knowledge of encryption standards, network security, and VPN infrastructure. In-depth knowledge of security monitoring and detection tools (e.g., SIEM, IDS/IPS, EDR). Experience leading agile IT projects and coordinating cross-functional teams, and implementing security frameworks (NIST, CIS, etc) Strong analytical, organizational, and problem-solving skills. Excellent communication skills, with the ability to convey complex security concepts to both technical and non-technical audiences. Demonstrated ability to mentor junior engineers, collaborate effectively across departments, and drive security culture improvements., Master’s degree in Computer Science or a related field of study required. Or a bachelor’s degree in Computer Science or other related field of study with related work experience equivalent to a master’s degree in the proceeding fields Leadership experience. Experience with cloud security operations, cloud -native security solutions, DevSecOps, CI/CD security practices. Familiarity with security frameworks and standards (ISO 27001, NIST, CIS). Knowledge of state privacy laws. Certifications such as CISSP, CCSP, AWS, Azure, or GCP.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on sciencejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all