Senior Security Engineer - Application & Cloud Security
Listed on 2026-07-07
-
IT/Tech
Cybersecurity, Cloud Computing: Infrastructure & Operations
Job Title
Senior Security Engineer – Application & Cloud Security (Draper, Utah, In-Office)
About the PositionYou will play a critical role in securing modern cloud-native applications, CI/CD pipelines, APIs, infrastructure, and development ecosystems across the enterprise. The ideal candidate is a cybersecurity-minded engineer who previously worked as a software developer, Dev Ops engineer, platform engineer, or infrastructure engineer and still possesses strong coding and system-level troubleshooting skills. This role requires someone who can read and understand source code, work closely with engineering teams, threat hunt across modern environments, and help build scalable security capabilities directly into the software development lifecycle.
This position will work across Application Security, Cloud Security, and Engineering teams to help secure enterprise applications and cloud infrastructure, operating at scale.
- Work directly with software engineers, Dev Ops engineers, architects, and leadership to identify, prioritize, and remediate security vulnerabilities across applications and cloud environments.
- Perform hands‑on application security reviews, source code analysis, threat modeling, and architecture reviews for modern applications and APIs.
- Build, integrate, automate, and operationalize security controls within modern CI/CD pipelines.
- Secure Infrastructure as Code (IaC) environments using Terraform, Cloud Formation, Kubernetes, and related technologies.
- Develop and maintain automated security tooling and workflows across SAST, DAST, SCA, secrets scanning, container security, and cloud security platforms.
- Support incident response, threat hunting, forensic investigations, and remediation activities related to application and cloud environments.
- Identify and remediate security weaknesses involving APIs, authentication systems, secrets management, cloud infrastructure, containers, and microservices.
- Work closely with engineering teams to establish secure‑by‑default engineering practices and security guardrails.
- Assist with implementing and tuning WAF, API security, identity platforms, cloud security tooling, runtime protection, and logging/monitoring capabilities.
- Help operationalize modern security practices around: SSDLC, Software supply chain security, Cloud‑native security, Threat detection and response.
- Participate in security investigations involving fraud, insider threats, suspicious application activity, and cloud incidents.
- Provide technical leadership and mentorship across engineering and security teams.
- 5+ years of experience in Application Security, Dev Sec Ops , Cloud Security, Software Engineering, or related technical disciplines.
- Previous hands‑on experience as a software developer, Dev Ops engineer, platform engineer, infrastructure engineer, or similar engineering role.
- Experience securing modern CI/CD environments and integrating security into engineering workflows.
- Strong experience with Infrastructure as Code (IaC), including Terraform, Cloud Formation, Kubernetes, Helm, or similar technologies.
- Experience with public cloud platforms such as AWS, Azure, or GCP.
- Hands‑on experience with security tooling such as SAST, DAST, SCA, etc.
- Understanding of OWASP Top 10, API security risks, cloud‑native security threats, identity security, and modern attack techniques.
- Experience investigating and remediating vulnerabilities involving applications, APIs, authentication systems, cloud infrastructure, or software supply chain risks.
- Strong understanding of how to leverage AI tools and AI‑assisted engineering workflows securely and effectively within day‑to‑day operations.
- Experience using modern AI‑assisted development and security platforms such as Git Hub Copilot, Claude, ChatGPT, or similar tools to improve engineering productivity, threat analysis, code review, vulnerability research, automation, and operational efficiency.
- Ability to evaluate, validate, and securely operationalize AI‑generated output within enterprise engineering and cybersecurity environments.
- Understanding of the security implications, risks, and governance…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).