> Markdown version of [/jobs/ext/604301-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/604301-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** FULLSTEAM INC. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $122,254.0 - $130,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Burp Suite, Cyber Security, Computer Programming, Digital Assets, Github, PCI Data Security Standards, Software Vulnerability Management, Scripting, Postman, Prompt Engineering, Sonatype, Information Technology, Nessus, Human in the Loop, Qualys, Static Application Security Testing, Dynamic Application Security Testing - **Published:** June 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=33d6da91ba65d677 ## About the Role Do you have experience in Project management in technology?, Do you have a Bachelor's degree?, * 8+ years of Information Technology / Security experience with 2-4+ years of hands-on experience in vulnerability management, attack surface management, or related security functions * Working knowledge of security tools such as Wiz, Snyk, Qualys, Nessus, MS Defender, or similar platforms * Experience with vulnerability prioritization frameworks (CVSS, EPSS, risk-based scoring) * Experience with application security testing concepts and tools (SAST, DAST, IAST, Burp Suite, Postman, GitHub, etc.) * Basic scripting or programming experience in any language, or a strong desire to develop this skill * Ability to produce clear, actionable security reporting for both technical and non-technical audiences * Hands-on experience with AI-assisted security workflows (prompt engineering, agent development, MCP tooling) * Experience developing or contributing to process documentation * Ability to work independently in a fully remote environment while managing multiple concurrent priorities * Experience working in a multi-business-unit or enterprise environment * Genuine curiosity and desire to grow Minimum Qualifications: * CISSP or equivalent certification (GIAC, CISM, CRISC) * Bachelor's degree in cybersecurity or equivalent work experience * Hands-on Defensive or Offensive security training or work experience * Project management knowledge, training and/or certifications ## Description This position is part of the Fullsteam InfoSec Team which is directly responsible for working with Business Units and Fullsteam Corporate on security initiatives and response. At Fullsteam, we're committed to protecting our digital assets and delivering the highest standard of security across our business. As we continue to scale our security programs, we're looking for a passionate security professional to join our Proactive Security team. We're a small, high-ownership team tackling vulnerability and risk exposure across a broad surface; infrastructure, applications, software, AI systems, and external attack surface. This isn't a ticket queue role; you'll have real ownership across the full vulnerability lifecycle, contribute to automation and tooling, and work directly alongside security leadership. If you thrive in a fast-paced environment and want to help shape a growing VM program, we want to hear from you. Primary Responsibilities: * Contribute to and help mature our vulnerability management program, ensuring identified risks are remediated according to SLAs across the enterprise and business units * Identify and report known vulnerabilities across infrastructure (cloud and on-prem), applications, software, AI systems, and external attack surface * Monitor external attack surface exposures and contribute to remediation prioritization * Produce vulnerability metrics, trending reports, and risk summaries for security leadership and business unit stakeholders * Support alignment of the VM program with industry regulations and standards (PCI-DSS, SOC2, NIST CSF, ISO 27001) * Collaborate with Security, IT, and BU Engineering teams to drive effective and measurable vulnerability and risk exposure outcomes * Contribute to risk management and governance functions (e.g., risk register, key metrics, vulnerability reports) * Develop and contribute to AI-assisted HITL (Human in the Loop) automation and workflows for Proactive Security initiatives ## Related Videos - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [ Secure Code Superstars: Empowering Developers and Surpassing Security Challenges Together](https://www.wearedevelopers.com/videos/422-secure-code-superstars-empowering-developers-and-surpassing-security-challenges-together) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)