Implement and maintain security controls for applications and systems.
Conduct DAST, SAST, vulnerability scans, and penetration tests.
Develop and enforce security policies and best practices.
Monitor logs, investigate incidents, and respond to threats.
Collaborate with development teams to ensure secure coding practices.
Stay updated on emerging threats and industry standards.
Requirements: Desired Qualifications
Bachelor's degree in Computer Science, Cybersecurity, or equivalent experience.
3+ years of experience in security engineering, appsec, or penetration testing.
Expertise in security frameworks (NIST, ISO 27001, CIS Controls) or similar.
Experience with software composition analysis (SCA), SBOM generation, and open-source license compliance.
Experience with Nessus, Qualys or similar, DAST, and SAST tools.
Familiarity with cloud security (AWS, Azure, GCP).
Certifications such as CISSP, CEH, OSCP, or CISM are a plus.
Nice To Have Skills
OWASP Top 10 and web application security expertise.
Proficiency in Python, Bash or other languages for automation and familiarity with Linux OS
Experience securing CI/CD pipelines and DevSecOps practices.
Knowledge of container security (Docker, Kubernetes).
Understanding of IAM, Zero Trust, and compliance (GDPR, HIPAA, PCI-DSS).
Familiarity with SOC operations and incident response.
Strong communication skills for cross-team collaboration.
Background in forensics, red team, malware analysis, or reverse engineering.
This position is open to all candidates.