> Markdown version of [/jobs/ext/3464216-security-engineer](https://www.wearedevelopers.com/jobs/ext/3464216-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Tixy Services LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Agile Methodology, Artificial Intelligence, Amazon Web Services, JIRA, Microsoft Azure, Bash Shell, Burp Suite, Cloud Computing, Cloud Computing Security, Computer Networks, Cursor, Github, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Network Security, OAuth, OpenID, Open Web Application Security, Windows PowerShell, Systems Development Life Cycle, Role-Based Access Control, Kusto Query Language, Security Assertion Markup Language (SAML), Secure Coding, Security Information and Event Management, Software Vulnerability Management, Data Logging, Scripting, Google Cloud, Cloud Platform System, Okta, GitHub Copilot, Sonatype, Software Security, Veracode, Amazon Virtual Private Cloud (VPC), Gitlab, Cloudformation, Bicep, Nessus, Checkmarx, Virtual Agents, Terraform, Prisma Cloud Platform, Splunk, Qualys, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 17, 2026 - **Apply:** https://www.dice.com/job-detail/64da4950-fb9d-43d9-9f53-ad581b0460f5 ## About the Role * - Mid: 4-7 years owning security engineering work across cloud, application, and infrastructure domains * - Experience designing and implementing IAM, encryption, network, and logging controls in AWS, Azure, or Google Cloud Platform * - Experience integrating security tooling (SAST, DAST, SCA, IaC scanning, CSPM) into CI/CD pipelines * - Experience leading threat modeling and security design reviews * - Experience contributing to incident response, detection engineering, and vulnerability management * - Hands-on experience using agentic AI tools in real delivery work, evaluated on demonstrated proficiency and judgment rather than tenure * **Skills** * - Strong cloud security expertise in AWS, Azure, or Google Cloud Platform (IAM, KMS, VPC, Security Hub/Defender/SCC) * - Application security expertise (OWASP Top 10, secure coding, threat modeling, secure SDLC) * - Deep familiarity with vulnerability management (Wiz, Prisma Cloud, Tenable, Qualys) and SAST/DAST/SCA tools (Snyk, Checkmarx, Veracode, Semgrep) * - Infrastructure-as-code (Terraform, CloudFormation, Bicep) with IaC security scanning (Checkov, tfsec) * - Container and Kubernetes security (image scanning, admission controllers, network policies, RBAC) * - Detection engineering and SIEM content (Splunk, Sentinel, Chronicle) including KQL/SPL/YARA-L * - Identity protocols (OAuth2, OIDC, SAML) and IdP configuration (Okta, Entra ID, Auth0) * - Scripting in Python, Bash, or PowerShell for automation and tooling * - Understanding of compliance frameworks (SOC 2, HIPAA, PCI, ISO 27001, NIST CSF, FedRAMP) and ability to map controls * - Incident response participation including triage, investigation, and post-incident reviews * - Strong communication skills for working with developers and platform teams * **Delivery Methods** * - Agile or hybrid project delivery models * - Leads security workstreams within sprint cadence and partners with engineering teams on remediation * **Tools** * AWS, Azure, Google Cloud Platform, Wiz or Prisma Cloud, Snyk or Checkmarx, Splunk or Sentinel, Terraform, Checkov or tfsec, Burp Suite, Nessus or Qualys, Okta or Entra ID, GitHub or GitLab, JIRA or ADO, AI Tools (Claude, Cursor, GitHub Copilot) * **Certifications (Preferred)** * AWS Certified Security - Specialty, Azure SC-200/SC-100, Google Cloud Platform Professional Cloud Security Engineer, CISSP (in progress acceptable), OSCP, CKS ## Description * JD: The Security Engineer designs and implements controls that protect customer applications, cloud environments, and data. * The Mid Security Engineer owns security workstreams end-to-end: threat modeling on new services, hardening cloud infrastructure, integrating security tooling into CI/CD pipelines, tuning detection, and leading remediation work with developers and platform teams. They translate security requirements into engineering work and operate as a trusted technical contributor inside delivery teams. * **Core Responsibilities** * - Conduct threat modeling and security design reviews on new and existing applications and services. * - Mid: Owns threat models for assigned services and translates findings into actionable engineering tickets. * - Design and implement IAM, encryption, network, and logging controls in cloud environments (AWS, Azure, Google Cloud Platform). * - Mid: Builds reusable IAM, KMS, and network security patterns in infrastructure-as-code. * - Integrate and tune security tooling (SAST, DAST, SCA, secret scanning, IaC scanning, CSPM) in CI/CD pipelines. * - Mid: Owns tool configuration, false-positive tuning, and policy-as-code rule development. * - Build and tune detection content in SIEM and cloud-native security tools; participate in incident response. * - Mid: Authors detection rules, writes runbooks, and leads triage on routine security incidents. * - Lead vulnerability management and remediation work across application, infrastructure, and container environments. * - Mid: Owns the remediation backlog and partners with engineering teams on prioritization and fixes. * - Map controls compliance frameworks (SOC 2, HIPAA, PCI, ISO 27001, NIST) and support audit evidence collection. * - Mid: Maintains control mappings and produces audit-ready evidence for assigned scope. * - Collaborate with developers, platform engineers, and architects to embed security into delivery practices. * - Mid: Pairs with engineering teams, runs secure-coding sessions, and influences design decisions early. * - Use agentic AI tools (e.g., Claude, Cursor, GitHub Copilot, Coco, or similar) in real delivery work, following and the client's agentic AI operating model and usage guidelines. * - Mid: Independently incorporates agentic AI tools into day-to-day delivery work, follows and client's operating model for responsible use (review, validation, disclosure where required), and can speak to where they've caught or corrected AI-introduced errors. ## Related Videos - [GitOps for the people](https://www.wearedevelopers.com/videos/461-gitops-for-the-people) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)