Bright Vision Technologies
Cybersecurity Engineer – Applications
Rol remoto de Application Security Engineer con fit claro de ubicación del candidato.
Publicado18 jul 2026
Países elegibles1 país aceptado
Señal de senioritySenior
Modelo de trabajoRemoto
Ubicaciones aceptadas para candidatos
Estados Unidos
Resumen del rol
Cybersecurity Engineer – Applications
Requisitos y responsabilidades
Contenido del rol extraído en secciones para revisar más rápido.
Details
- Conduct threat modeling and security architecture reviews for new and existing applications and services.
- Perform manual code reviews, secure design consultations, and pair with engineering teams on hardening critical components.
- Operate and tune SAST, DAST, IAST, SCA, and secret-scanning tools across CI/CD pipelines.
- Drive vulnerability management workflows including triage, prioritization, owner assignment, and SLA tracking.
- Build paved-road libraries and frameworks that make secure patterns the default for engineering teams.
- Lead red-team and purple-team exercises against internal applications and drive remediation of identified weaknesses.
- Implement and operate runtime protections including WAF, RASP, bot protection, and abuse-detection mechanisms.
- Design and enforce secure authentication, authorization, session management, and cryptographic patterns.
- Partner with infrastructure and platform teams to harden container, Kubernetes, and cloud environments.
- Develop and deliver application security training, lunch-and-learns, and onboarding content for engineering staff.
- Respond to security incidents involving application vulnerabilities or active exploitation.
- Track and apply emerging threats and CVEs that may affect the application portfolio.
- Maintain comprehensive, current technical documentation — including architecture diagrams, design decisions, configuration references, runbooks, and operational procedures — so that the system remains supportable, auditable, and easy to onboard new engineers onto over time.
- Stay current with application security research and emerging defensive tooling.
- Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
- Five or more years of application security or security engineering experience.
- Strong understanding of OWASP Top 10, common vulnerability classes, and modern exploit patterns.
- Hands-on experience performing code review across at least two major languages.
- Deep familiarity with SAST, DAST, SCA, and CI/CD-integrated security tooling.
- Strong understanding of authentication, authorization, and cryptographic primitives.
- Experience with cloud security and modern infrastructure controls.
- Strong communication skills with technical and non-technical audiences.
- Proficiency in at least one programming language for tooling and automation.
- Experience working closely with engineering teams in an Agile environment.
- Industry certifications such as OSCP, OSCE, GWAPT, or CISSP.
- Experience with offensive security tooling and red-team operations.
- Bug bounty experience, public CVEs, or open-source security contributions.
- Familiarity with AI/LLM application security considerations.
- Exposure to regulated industries with strict compliance requirements.
Roles similares
Mantén una lista de respaldo.
Stack
Usa estas tags para comparar roles remotos similares.
Elegibilidad de ubicación
Candidatos deberían aplicar solo cuando el país del perfil aparece aquí.
Tu perfilPaís no definidoInicia sesión para comparar tu país con este rol.
Flujo de contratación
WithMira muestra el rol y luego envía candidatos a la aplicación de la empresa.
1Revisa fit del rol, stack y elegibilidad de ubicación en WithMira.
2Abre la página de aplicación de la empresa desde el link rastreado.
3Guarda el rol o suscríbete a oportunidades similares antes de salir.