> Markdown version of [/jobs/ext/570766-security-engineer-tester](https://www.wearedevelopers.com/jobs/ext/570766-security-engineer-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer/Tester - **Company:** Genesis10 - **Location:** Seattle, WA, United States - **Experience:** Experienced - **Salary:** $104,874.0 - $121,514.0 - **Contract:** Temporary to permanent - **Skills:** Static Program Analysis, Cyber Security, Digital Signature, Fiddler (Software), Hardware Security Module, Identity and Access Management, Mobile Application Software, OAuth, OpenID, Open Web Application Security, Security Assertion Markup Language (SAML), Secure Coding, Single Sign-On, Software Engineering, Web Applications, Enterprise Software Applications, Cloud Platform System, Software Security, Information Technology - **Published:** June 18, 2026 - **Apply:** https://www.dice.com/job-detail/32c6433d-eff2-409a-b5cd-25ed745ce87e ## About the Role * 3+ years of experience in software development/testing with large-scale enterprise applications * Primary skill in manual and automated software testing * Deep understanding of different web application technologies, web protocols (HTTP, HTTPS, etc.), and browser technologies * In-depth domain understanding of application security in terms of Identity and Access Management (IAM) and different authentication technologies * Proven expertise on different security testing tools (Proxy tools like Fiddler, Black box security testing tools like Burp, Static Security Code analysis tools) * Deep understanding of different application security vulnerabilities such as OWASP Top 10, SANS Top 25, CWE, and attack patterns (CAPEC) * Bachelor's Degree in Computer Science or equivalent experience * Must be self-directed, able to work independently, as well as work in a team-oriented and fast-paced environment Desired skills: * Working experience on different security technologies and standards like Single Sign On (SSO) using SAML/OpenID, OAuth protocols, etc * Good understanding of Cryptographic algorithms and standards like Symmetric/Asymmetric crypto techniques, digital signatures, JWS/JWE tokens, Hardware Security Modules (HSMs), etc * Understanding of security vulnerabilities related to Cloud environments is an added advantage * Well-known security certifications is an added advantage * Understanding of Threat Modeling concepts and Secure Development Life Cycle processes * Mobile Application Security familiarity is desirable ## Description As a Security Engineer/Tester, you will perform authorized security testing on complex, massive scale, and highly critical applications. This role involves working within the development team to proactively identify security vulnerabilities (OWASP Top 10, SANS Top 25, CWE) early in the development cycle. You will act as a liaison between the InfoSec and development teams, helping to understand and remediate security issues. Responsibilities: * Perform authorized security testing on complex and highly critical applications * Work in a team-oriented and fast-paced environment * Maintain awareness of varied application security domains like authentication, authorization, identity management, and cryptography * Present findings to Leadership, Management, and Development teams to help them understand risks and make informed decisions on mitigations and controls ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) ## Related Articles - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)