IT Security Engineer III

Kforce Inc.
San Diego, CA, United States
12 days ago
Apply on www.kforce.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Software System Penetration Testing Cyber Security Issue Tracking Systems Mobile Application Software Python (Programming Language) Open Web Application Security Web Applications Scripting Large Language Models GWAPT
+2 more
Information Technology Vulnerability Analysis

Job description

A client with Kforce is seeking an IT Security Engineer III to join their team in San Diego, CA. Summary: Come join one of the most dynamic security teams in the industry! At the client, we work closely with security researchers and our development teams to protect our customers, products and services from the latest emerging threats. We are looking for a seasoned IT Security Engineer III to act as a member of our Offensive Security Group team. You will leverage your experience to analyze, triage, report and track through remediation, potential findings from programs such as bug bounty, vulnerability disclosure and penetration testing. Additionally, you will provide augmented support to our penetration testing team penetration testing as part of our responsible AI component. Responsibilities:

  • Triage incoming bug bounty reports while assessing severity and impact
  • Provide input into high-quality reports to enable stakeholders understanding of the impact and required remediations based on identified defects and security deficiencies
  • Build relationships with, and act as a liaison between, product teams, security teams and security researchers
  • Communicating effectively and professionally with internal and external stakeholders
  • Collaborating with stakeholders to track vulnerability through resolution
  • Maintain awareness of new attack vectors, 0-days, tools and other developments in the space
  • Collaborating with the security teams for further vulnerability analysis
  • Supporting responsible AI pentest backlog
  • Other security testing duties as assigned

Requirements

  • BS in Computer Science, Cybersecurity, or related field
  • Professional level certifications (OSCP, GPEN, GWAPT, etc.)
  • 3+ years in a computer security role, including at least 2 years of experience in offensive security
  • Experience in Fintech
  • Experience triaging vulnerability reports
  • Android/iOS security testing or programming experience
  • Experience with security testing one or more of the following: web applications, APIs, desktop apps, mobile apps, source code auditing, LLMs, AI
  • Experience with Claude Code, Codex
  • Experience across multiple security disciplines
  • Experience with task ticketing systems
  • Experience communicating risks to product teams and report writing
  • Deep understanding of OWASP Top 10 Vulnerabilities
  • Active in the security community: research/white papers, blogs, talks, presentations, recent bug bounty submissions
  • Python, or similar scripting language
  • Proven results utilizing vulnerability scanning, penetration testing and/or bug bounty tools, techniques and proof-of-concepts
  • Good written and verbal communication skills
  • Ability to analyze and reproduce vulnerability reports while assessing severity and impact

Benefits & conditions

The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.

We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.

Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce’s sole discretion unless and until paid and may be modified in its discretion consistent with the law.

About the company

By clicking “Apply Today” you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.kforce.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all