×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior Security Engineer

Job in Cherry Hill, Camden County, New Jersey, 08358, USA
Listing for: Mach7 Technologies
Full Time position
Listed on 2026-07-18
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 120000 - 190000 USD Yearly USD 120000.00 190000.00 YEAR
Job Description & How to Apply Below

Burlington, United States | Posted on 07/13/2026

What You'll Do Application Security & Secure SDLC
  • Own and evolve the App Sec program across the entire SDLC — from design reviews to post‑deployment monitoring — for web, API, mobile, and shipped product deliverables
  • Build and maintain a living model of the product attack surface — mapping trust boundaries, data flows, exposed interfaces, and high‑value targets — and use it to drive prioritization across all security work‑streams
  • Conduct threat modeling and architecture security reviews for new features, services, and product releases across all delivery channels
  • Perform manual and automated secure code reviews across multiple languages (e.g., Python, Go, Type Script, C/C++)
  • Integrate and tune SAST, DAST, and SCA tooling within CI/CD pipelines (Git Hub Actions, Jenkins, or equivalent)
  • Triage and drive remediation of vulnerabilities surfaced through scanning, bug bounty, and pen tests
  • Develop and maintain a library of security standards, patterns, and guardrails applicable across product types
Third‑Party & Supply Chain Security
  • Own the Software Bill of Materials (SBOM) program — define generation, storage, and consumption processes across all product lines
  • Establish and maintain policies for evaluating, onboarding, and continuously monitoring third‑party dependencies and open‑source components
  • Triage and prioritize CVEs and license risks surfaced through SCA tooling, driving timely remediation with engineering teams
  • Define processes for responding to upstream supply chain incidents (e.g., compromised packages, malicious dependencies)
  • Collaborate with procurement and legal to assess security risk of third‑party vendors and integrations
  • Contribute to industry frameworks and internal standards around software supply‑chain security (SLSA, NIST SSDF, or equivalent)
  • Act as a trusted security advisor embedded within product engineering squads
  • Lead security training, lunch‑and‑learns, and developer education initiatives
  • Collaborate with the Platform team on secrets management, identity, and access controls
  • Work with the GRC function to translate compliance requirements (SOC 2, ISO 27001) into engineering controls
Incident & Vulnerability Management
  • Participate in the security on‑call rotation and lead security incident response investigations
  • Drive root‑cause analysis and communicate findings clearly to engineering leadership
  • Build and maintain metrics and dashboards to track the health of the App Sec program
  • Participate as a member of the Cybersecurity council, representing development in the organization. Report weekly on new threat intelligence as it relates to product security, and any actions that are being taken to remediate new findings.
What We’re Looking For Required
  • 5+ years of experience in security engineering, with a strong App Sec focus
  • Hands‑on experience with threat modeling frameworks (STRIDE, PASTA, or similar)
  • Proficiency with common App Sec tooling:
    Semgrep, Snyk, Burp Suite, OWASP ZAP, or equivalents
  • Deep understanding of web application vulnerabilities (OWASP Top 10, API security, auth/authz flaws)
  • Ability to read and reason about code in at least two languages; prior development experience a plus
  • Experience with software supply chain security — SBOM generation and analysis (CycloneDX, SPDX), SCA tooling, and dependency risk management
  • Strong written and verbal communication skills — you can explain risk to both engineers and executives
Preferred
  • Experience with cloud‑native environments (AWS, GCP, or Azure) and container/Kubernetes security
  • Familiarity with software supply‑chain frameworks such as SLSA, NIST SSDF, or OpenSSF Scorecards
  • Contributions to open‑source security tooling or security research
  • Relevant certifications: OSCP, CSSLP, GWEB, or similar
Who You Are
  • Experienced security professional with a strong background in application security and secure software development
  • Skilled at threat modeling, secure code reviews, and identifying real‑world risks across complex systems
  • Knowledgeable in web, API, mobile, and software supply‑chain security best practices
  • Comfortable working with developers to embed security throughout the SDLC
  • Proficient with security testing and vulnerability management tools, including SAST, DAST, and SCA solutions
  • Strong communicator who can translate technical risks into actionable recommendations
  • Collaborative, proactive, and driven to improve both product security and engineering security culture
  • Passionate about continuous learning, emerging threats, and helping teams build secure products at scale

Mach7 Technologies is proud to be an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees and applicants, regardless of race, ethnicity, religion, sex, sexual orientation, gender identity or expression, age, national origin, disability, veteran status, genetic information, or any other protected status under the law.

#J-18808-Ljbffr
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary