Security and Application Security Engineer
Listed on 2025-11-24
-
IT/Tech
Cybersecurity, IT Consultant, Systems Engineer, Information Security
Beacon Technologies is seeking a Security and Security Application Security Engineer for our client partner. The Security and Application Security Engineer position is responsible for a combined effort of general infrastructure Cyber security as well position is focused on performing application security testing, design, and working in partnership with development teams throughout the organization. The scope of responsibility also includes but is not limited to static and dynamic application security testing, penetration testing, maturing the software development life cycle, and API security testing.
Successful candidates will be able to review application code and development environments for security concerns and best practices, making recommendations and assisting development teams in implementing recommendations from those assessments.
This position works closely and in partnership with the various teams and business units throughout the organization. The scope of responsibility includes but is not limited to the following networking technologies:
Vulnerability Management, Threat Analysis, Threat hunting, Security incident Management, general security hygiene, Internet, firewalls/DMZ, IP network and communications rooms (equipment, software/protocols, and cabling), monitoring, test systems/platforms, overall data security and encryption. The position also entails cloud-based technologies such as Amazon Web Services, and colocation solutions used in conjunction with on-premises data centers. The position will also be responsible for performing periodic compliance tasks as required, and/or assisting to maintain desired industry certifications for the organization.
Key Responsibilities:
- Strong communication skills, ability to convey and document security guidelines, requirements, and coding best practices.
- Operate as a liaison between the Security Team and the Development Teams.
- Preserve PCI and SOX Security Certification programs with a primary focus on ensuring compliance with the appropriate industry standards and security controls.
- Supporting incident response and architecture review whenever applications security expertise is needed.
- Integrating threat modeling practices into the SDLC.
- Work with other staff to perform periodic scans and evaluation of system security including areas such as patch management, penetration testing, vulnerability assessments, and other types of Info Sec-related tasks.
- Assist in identifying and communicating security exposures, information security incidents or non-compliance situations to IT management or the CISO as appropriate. Duties may also include collecting and documenting cyber security and incident response event data as necessary.
Skills
- Ideal candidate would have a dynamic security aptitude and a verifiable set of skills and experiences within the enterprise Information Security realm.
- Familiarity with Security Best Practices in common coding languages.
- Application Penetration Testing / API Security Testing.
- Software Development Life Cycle Design and Implementation.
- Static and Dynamic Application Testing Tools and Methods.
- Container and orchestration security (Kubernetes, Docker, Octopus, Git Hub, etc.).
- Familiarity with Application Security Testing Frameworks such as OWASP.
- Strong logical and analytical thinker; exceptional skills in security systems solutions.
- Ability to work both independently and as part of a local and/or remote technology team.
- Attention to detail and demonstrated history of using careful approaches to tasks being performed.
- Can anticipate risks and mitigate issues in the moment.
- Strong verbal and written communication skills.
- Basic networking skill set is required along with experience in securing wide area networks and a hybrid approach for on-premises/cloud/colocation technology environments across multiple locations. Demonstrated expertise of networking knowledge including a thorough understanding of the OSI model.
- Compliance – PCI-DSS, PCI-CP, SOX. PCI requirements and reporting, NIST regulatory and compliance environments, and demonstrated broad range of skills with security publications, privacy data identification/handing, security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).