Security Engineer

Horizontal Talent
Brooklyn Park, MN, United States
3 days ago
Apply on www.jofdav.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$39,520.0 - $66,560.0
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Microsoft Azure Cloud Engineering Code Review Fuzz Testing Machine Learning Open Web Application Security Secure Coding Software Engineering Software Vulnerability Management
+8 more
Large Language Models Software Security Kubernetes Devsecops Static Application Security Testing Vulnerability Analysis Programming Languages Dynamic Application Security Testing

Job description

Join a dynamic security team driving the next generation of application and AI security practices. This 12-month Security Engineer opportunity supports enterprise initiatives by strengthening secure development, validating vulnerabilities, and helping teams build safer applications and AI-enabled services. Responsibilities

  • Collaborate with engineering and cybersecurity partners to evaluate and implement application and AI security practices, tooling, and operational processes.
  • Review application code, APIs, automation workflows, and AI-enabled services to identify security risks and improvement opportunities.
  • Analyze results from security testing tools and validate findings, including assessing impact, filtering false positives, and guiding remediation efforts.
  • Support dynamic application security testing and other vulnerability assessment methods across the development lifecycle.
  • Integrate and help maintain automated security testing within CI/CD pipelines and secure SDLC workflows.
  • Contribute to threat modeling and security design reviews for applications, AI-enabled solutions, and machine-learning systems.
  • Research emerging AI/LLM security tools, methods, and attack techniques to help advance security capabilities.
  • Develop clear documentation, standards, and repeatable processes to support application security and vulnerability management.
  • Participate in proof-of-concept evaluations of new security technologies and solutions.

Requirements

  • 4+ years of relevant technical experience in application security, product security, cybersecurity engineering, or software engineering.
  • Hands-on experience validating findings from automated security tools and determining severity, impact, and remediation steps.
  • Experience with dynamic application security testing and application vulnerability assessment practices.
  • Ability to perform security-focused code reviews and identify common application vulnerabilities in at least one modern programming language.
  • Working knowledge of OWASP Top 10, API security risks, secure coding principles, and secure SDLC practices.
  • Experience supporting security activities in CI/CD pipelines and across the software development lifecycle.
  • Strong communication skills with the ability to explain technical findings and recommendations to engineering teams.

Preferred Skills

  • Experience in enterprise DevSecOps environments.
  • Familiarity with AI/LLM security, adversarial testing concepts, or AI security frameworks.
  • Experience helping secure AI-enabled applications or evaluating emerging AI-related security risks.
  • Background working with AWS, Azure, or GCP environments.
  • Exposure to SAST, software composition analysis, or runtime application security tools.
  • Experience securing cloud-native, containerized, or Kubernetes-based applications.
  • Relevant certifications such as CSSLP, CISSP, OSCP, GSEC, or GIAC application security credentials.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

1:15 min

Deploying local container pods to Kubernetes clusters

Stevan Le Meur Stevan Le Meur · World Congress 2024

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

56 sec

The hidden costs of delayed peer code reviews

Tim Gilboy Tim Gilboy

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

Videos

See all

Related articles

See all