×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Senior DevSecOps​/Security Engineer – Application & Cloud; Ecommerce

Job in Mount Pleasant, Charleston County, South Carolina, 29466, USA
Listing for: Thorne
Full Time position
Listed on 2026-06-26
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 150000 - 180000 USD Yearly USD 150000.00 180000.00 YEAR
Job Description & How to Apply Below
Position: Senior DevSecOps / Security Engineer – Application & Cloud (Ecommerce)

Senior Dev Sec Ops  / Security Engineer – Application & Cloud (Ecommerce)

Department: Information Technology

Employment Type: Full Time

Location: Remote

Compensation: $150,000 - $180,000 / year

Description

At Thorne, we work to deliver high-quality, science-backed solutions to empower individuals to take a proactive approach to their well-being. Each day begins with a mission to help others discover and achieve their best health. We count on our team members to challenge and push the boundaries to make that happen. At Thorne, you’ll be joining a team of more than 750 passionate individuals committed to our cause of providing superior health solutions at every age and life stage.

Thorne is seeking a Senior Dev Sec Ops  / Security Engineer – Application & Cloud (Ecommerce) to secure and scale our digital platforms, including , mobile applications, and emerging AI capabilities. This role sits at the intersection of application security, Dev Sec Ops , and AWS cloud infrastructure, with a strong focus on protecting ecommerce systems, customer data, and high-traffic web applications.

The ideal candidate will balance remediations and hands-on execution, ensuring systems are resilient, performant, and secure, while embedding security throughout the development lifecycle.

RESPONSIBILITIES
  • Application & Ecommerce Security:
    Identify and remediate vulnerabilities in Java-based applications (Spring Boot, APIs, microservices)
  • Address OWASP Top 10 and ecommerce-specific risks, including:
  • Injection (SQL/No

    SQL), XSS, CSRF
  • Broken authentication / session management
  • Business logic flaws (checkout, pricing, promotions, abuse scenarios)
  • Account takeover, credential stuffing, bot attacks
  • Secure checkout flows, payment integrations, subscriptions, and customer data handling
  • Conduct secure code reviews and support threat modeling for new features
  • API & Integration Security:
    Secure REST/GraphQL APIs (authentication, authorization, rate limiting)
  • Prevent API abuse, scraping, and data exfiltration
  • Implement and enforce secure patterns (OAuth2, JWT, token management)
  • Dev Sec Ops  & CI/CD Security:
    Implement and manage security tooling in CI/CD pipelines (SAST, DAST, SCA, secrets scanning)
  • Secure build and deployment pipelines
  • Enforce secure coding standards and automate policy checks
  • Own infrastructure-as-code security (Terraform) for app environments
  • AWS Cloud Security (Critical):
    Secure application workloads on AWS (EKS/ECS, EC2, Lambda, API Gateway, S3, RDS)
  • Implement and validate IAM roles and least privilege access
  • Network segmentation (VPCs, security groups, private/public boundaries)
  • Secrets management (AWS Secrets Manager, Parameter Store)
  • Data protection (encryption at rest/in transit)
  • Partner with Infra to ensure alignment with enterprise guardrails, while owning app-layer cloud security
  • Runtime Protection & Detection:
    Implement and tune WAF, bot protection, and rate limiting for ecommerce surfaces
  • Partner with Infra on Crowd Strike coverage for application workloads
  • Support detection and response improvements for Web/app-layer attacks and API abuse
  • Triage and remediate findings from Pen tests, Purple team exercises, and assumed breach scenarios
  • Security Program Execution:
    Translate security findings into prioritized engineering work
  • Partner with external security testing partners on risk prioritization (CTRM) tied to business impact
  • Drive adoption of security best practices across engineering teams
  • Act as a bridge between Ecom, Infrastructure, and external security partners
WHAT YOU NEED

Application & Ecommerce Security

  • Identify and remediate vulnerabilities in Java-based applications (Spring Boot, APIs, microservices)
  • Address OWASP Top 10 and ecommerce-specific risks, including:
  • Injection (SQL/No

    SQL), XSS, CSRF
  • Broken authentication / session management
  • Business logic flaws (checkout, pricing, promotions, abuse scenarios)
  • Account takeover, credential stuffing, bot attacks
  • Secure checkout flows, payment integrations, subscriptions, and customer data handling
  • Conduct secure code reviews and support threat modeling for new features
  • API & Integration Security
  • Secure REST/GraphQL APIs (authentication, authorization, rate limiting)
  • Prevent API abuse,…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary