Citizenship: All candidates must be a US citizen
Experience: 3–5 years of dedicated experience in a technical cybersecurity role (e.g., Security Engineer, AppSec Engineer, or Senior Security Analyst, etc.)
Application Security: Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure code dependencies (SCA)
Vulnerability Assessment: Proven experience running enterprise vulnerability scanners, interpreting results, and driving remediation across cross-functional teams
Cloud & Infrastructure: Foundational knowledge of cloud environments (specifically AWS) and securing cloud-native applications
Communication: Excellent collaboration skills. You must be able to sit down with software developers, understand their sprint goals, and help them fix security bugs without breaking their workflow
Preferred Experience & Tool Stack
Direct experience with our specific stack is a massive plus
AppSec/PenTesting: Burp Suite, Kali Linux, BugCrowd, Sonarqube
SecOps & Vulnerability: Tenable, Bitsight, OneTrust
IT & Endpoint Ecosystem: Jira, AWS, Sophos, JAMF, PDQ, BetterCloud
Certifications: CompTIA Security+, CEH, GIAC, or progress toward a CISSP, or other relevant certifications
Automation: Basic scripting skills (Python, PowerShell, or Bash) to automate repetitive security tasks or log analysis
Security Frameworks: Experience with maintaining compliance with PCI-DSS, ISO 27001, and SOC 2 frameworks
Artificial Intelligence: Experience utilizing AI to improve productivity and efficiency, as well as experience reviewing AI tools, integrations, and features