> Markdown version of [/jobs/ext/459364-security-engineer](https://www.wearedevelopers.com/jobs/ext/459364-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** CURINOS, INC. - **Location:** New York, NY, United States (Remote available) - **Experience:** Experienced - **Salary:** $100,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Computer-Aided Design, Amazon Web Services, Software System Penetration Testing, Audit Trail, Bash Shell, Cloud Computing Security, Cyber Security, Linux, Monitoring of Systems, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Secure Coding, Systems Integration, Software Vulnerability Management, Data Logging, Scripting, Software Security, Amazon Virtual Private Cloud (VPC), Kubernetes, Information Technology, BIG-IP Access Policy Manager (APM), CIS Benchmarks, Cloudwatch, Vulnerability Analysis - **Published:** June 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3481c1f0f24b3fd4 ## About the Role * AWS cloud security: hands-on experience with Amazon managed services, such as Security Hub, GuardDuty, CloudTrail, IAM, and VPC * CNAPP / cloud posture management: experience reviewing cloud posture findings, identifying misconfigurations, and supporting remediation efforts within a cloud security platform * Vulnerability management: proficiency with vulnerability scanning, prioritization, remediation tracking, and follow-up across a mixed asset inventory * Endpoint and network threat detection: working knowledge of endpoint and network detection workflows, including alert triage, investigation support, and response coordination * Application security tooling: familiarity with software composition analysis, secure development workflows, and integrating security findings into engineering processes * Linux and Kubernetes: working knowledge of Linux-based systems and Kubernetes environments, including security hardening, monitoring, and remediation support * Security frameworks: practical understanding of NIST 800-53, CIS Benchmarks, and/or ISO 27001, with the ability to apply control concepts to day-to-day security findings and operational activities, * 2-4 years of hands-on experience in security operations, security engineering, or security analyst roles * Demonstrable hands-on experience with several of the following areas: AWS security services, cloud security posture management vulnerability management, endpoint detection and response, network threat detection, or application security tooling * Experience with vulnerability management: scanning, prioritization, and remediation tracking * Solid understanding of cloud security principles in AWS (IAM, networking, logging, encryption), including hands-on experience with AWS CloudWatch (Logs, Metrics, Alarms, APM, and infrastructure monitoring) for visibility and alerting * Familiarity with observability and metrics tooling used to support monitoring, alerting, and security visibility. * Knowledge of security frameworks such as NIST 800-53, CIS Benchmarks, and ISO 27001 * Working knowledge of Python or Bash for basic security automation, scripting, or data gathering tasks * Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience * Certification desired (Security+, CySA+, AWS Security Specialty, CEH) but not required ## Description Curinos is looking for a detail-oriented Security Engineer to join our Information Security team. Operating in an AWS-native environment with select on-premises workload, this role will contribute across cloud security posture management, vulnerability management, threat detection, application security support, and incident response. The ideal candidate will have hands-on experience with modern cloud and security tooling and the ability to work across engineering and operations teams to reduce risk in a hybrid environment. This role will work closely with Information Security, Information Technology, and Engineering teams, executing established priorities while building broader depth across our security program., * Support day-to-day security operations and engineering activities across our cloud and hybrid environment, partnering with Information Security, IT, and Engineering teams to identify risks, coordinate remediation, and improve detection and response capabilities * Monitor and respond to findings in AWS Security Hub and Amazon Guard Duty, triaging alerts and coordinating remediation with engineering teams * Support cloud security posture management activities using a CNAPP platform, reviewing findings, assisting with risk prioritization, and coordinating remediation with asset owners * Perform vulnerability assessments and support the remediation lifecycle using an enterprise vulnerability management platform; assist with penetration test coordination and track findings through resolution * Support the triage of application security findings within development pipelines and partner with developers on remediation * Operate and monitor endpoint detection and response tooling for telemetry review, detections, and response support, escalating as needed * Review network detection and response alerts, tune signal quality, and escalate high-confidence threats for investigation * Support security incident investigation and response activities, contribute to root cause analysis, and assist with post-incident documentation and follow-up actions * Prepare weekly security posture and health reports for management review * Contribute to the automation of repetitive security operations tasks to improve team efficiency and consistency * Stay current with emerging threats, CVEs, and updates to the security controls and platforms used across our environment ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From Black Box to Glass Box : Bedrock AgentCore Observability](https://www.wearedevelopers.com/videos/2126-from-black-box-to-glass-box-bedrock-agentcore-observability) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [30 powerful AWS hacks in just 30 minutes: Boost your developer productivity](https://www.wearedevelopers.com/videos/1624-30-powerful-aws-hacks-in-just-30-minutes-boost-your-developer-productivity) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)