Security Engineer
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Why Seyfarth
At Seyfarth, we understand that great people are the key to our success, and we provide the opportunities to match. If you join us, you’ll work with state‑of‑the‑art technology in a friendly and professional environment, and we will continue to invest in your professional development. If you want the freedom to grow at a firm that is invested in your future, keep reading.
TheOpportunity
As a Security Engineer - Application Security & Technology Risk
, you will help evaluate and protect the Firm's technology environment by assessing the security risks associated with applications, SaaS platforms, browser extensions, integrations, and other technologies proposed for use within the Firm.
A significant part of this role will involve understanding how a technology works, the access and permissions it requires, the data it can access or process, how it integrates with the Firm's environment, and how it could potentially be abused or compromised. You will evaluate these technologies from both a defensive and adversarial perspective, considering vulnerabilities, software supply‑chain risk, authentication and authorization controls, configuration weaknesses, and the ways an attacker could leverage a compromised application or integration.
The successful candidate will combine strong technical security knowledge with the ability to translate security findings into practical, risk‑based recommendations for application owners, IT teams, and Firm leadership.
The Day‑To‑Day- Perform technical security assessments of software applications, SaaS platforms, browser extensions, integrations, AI‑enabled technologies, and other technologies proposed for use within the Firm.
- Evaluate application architecture, permissions, data access, administrative controls, authentication methods, APIs, OAuth integrations, third‑party dependencies, logging capabilities, and security configuration.
- Assess how compromised or malicious applications could be leveraged as an attack vector, including credential theft, data exposure, persistence, privilege escalation, lateral movement, command and control, and software supply‑chain compromise.
- Review vendor and application security documentation, vulnerability information, threat intelligence, software dependencies, and publicly available security research to identify potential risks.
- Evaluate authentication and authorization configurations including SSO, SAML, OAuth/OIDC, MFA, Microsoft Entra , Conditional Access policies, service principals, application registrations, API permissions, and privileged access requirements.
- Work with infrastructure, endpoint, cloud, identity, networking, and application teams to identify security design or configuration gaps and recommend practical remediation or compensating controls.
- Review existing deployed applications to determine business need, usage, software versions, support status, known vulnerabilities, available updates, and potential security exposure.
- Assist with application inventory and software lifecycle initiatives designed to identify unnecessary, obsolete, vulnerable, or unauthorized applications within the environment.
- Validate approved application deployments to confirm that software, security controls, permissions, integrations, and configurations were implemented according to approved requirements.
- Use vulnerability management, endpoint security, SIEM, identity, network, asset discovery, and other security telemetry to understand application behavior and identify potential security concerns.
- Support Security Operations with threat hunting, security investigations, incident response, and other operational security activities as needed.
- Clearly document findings, risk, technical impact, and recommended controls for both…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).