Security Engineer, Specialist
Listed on 2026-05-24
-
IT/Tech
Cybersecurity, Systems Engineer, Security Manager
Business Unit:
Adree
Function:
Security Engineer
Level:
Specialist
Job location:
HQ
Adree is looking for a Security Engineer to support our product development and engineering initiatives by leveraging deep application security and analytical expertise to articulate the value of secure, compliant digital solutions. In this role, you will work closely with stakeholders to understand technical requirements and business goals, and clearly demonstrate how enforceable security gates and robust vulnerability lifecycle management can address their needs.
You will be responsible for bridging the gap between security compliance and rapid delivery execution, collaborating across teams to operationalize automated security controls throughout the SDLC. By blending secrets management, automated scanning pipelines, and artifact trust mechanisms, you will ensure our digital products are highly secure, resilient, and fully audit-ready.
Key Responsibilities:- Engage with clients and stakeholders to gather security requirements and understand their digital transformation and compliance goals
- Deliver impactful presentations, security dashboards, and reporting frameworks showcasing vulnerability triage, remediation tracking, and pipeline safety metrics
- Support the engineering and Dev Ops teams in configuring and tuning Fortify SAST/DAST, establishing clear thresholds, and governing exception workflows
- Provide technical insights and application security expertise throughout the product lifecycle to automate SSL/TLS certificate renewals using Hashi Corp Vault and Cert-Manager in Kubernetes
- Collaborate with cross-functional teams (including Dev Ops and QA) to build secure pipelines, manage test environment controls, and enforce software supply chain visibility via SBOM integration
- Stay current with industry trends, OWASP frameworks, container security concepts, and threat modeling to position solution security effectively
- Conduct workshops and technical triage sessions internally and with clients to define Quality Gates, vulnerability SLAs, and secure secrets management patterns with Secur Envoy MFA
- Participate in Agile development processes and release alignments, producing required compliance evidence, scan outputs, approvals, and comprehensive release evidence packs
- Bachelor’s degree in Computer Science, Cyber Security, Software Engineering, or a related technical field.
- 4+ years of professional experience in Application Security (App Sec), Dev Sec Ops , or Security Engineering.
- Proven experience operationalizing enforceable security gates within CI/CD pipelines, preferably using Azure Dev Ops Server.
- Demonstrated experience with threat modeling, vulnerability management, and operating within government or highly regulated enterprise sectors is a strong plus.
- Deep proficiency in Secure SDLC principles, OWASP Top 10, container security concepts, and Kubernetes/Open Shift security basics.
- Strong hands‑on experience implementing image signing/verification (Sigstore/Cosign) and artifacts lifecycle security via JFrog Artifactory.
- Analytical skills to correlate security logs and monitoring alerts with enterprise platforms like App Dynamics, BMC, or Azure Monitoring.
- Excellent soft skills with an ability to influence without authority, deliver pragmatic risk‑based guidance, and handle security escalations calmly.
- Strong collaboration, structured reporting, and cross‑functional engineering alignment.
- Operationalization of automated Dev Sec Ops security gates across CI/CD pipelines
- Vulnerability lifecycle management including triage, SLA tracking, and remediation
- Automated software supply chain security (SBOM generation & container image signing)
- Secrets management integration and automated infrastructure certificate management
- Application security scanning optimization across SAST and DAST frameworks
- Regulatory compliance evidence gathering and release package auditing
- Azure Dev Ops Server & JFrog Artifactory secure workflow management
- Fortify SAST/DAST tuning & exception workflow design
- Hashi Corp Vault secrets management & Cert-Manager infrastructure
- Container & cluster security principles (Kubernetes / Red Hat Open Shift)
- Multi‑factor authentication access patterns (Secur Envoy MFA)
- Stakeholder relationship management & security governance
- Prioritization, risk‑based communication, and teamwork
- Travel for client‑facing activities
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).