Source description
About the role
The Information Security Engineer is responsible for designing, implementing, and engineering security controls across applications, infrastructure, identity, network, and cloud environments. This role emphasizes security engineering, detection development, vulnerability mitigation, and application security over day?to?day alert operations. The ideal candidate builds and improves security capabilities, develops detections, integrates security into application and infrastructure pipelines, and works directly with engineering teams to prevent, detect, and contain threats by design. Responsibilities: Design, implement, and evolve security controls and architectures across applications, identity, endpoints, and network layers Engineer and maintain security telemetry and integrations across SIEM/MDR, EDR, firewalls, identity platforms, and cloud services to enable reliable downstream detection and analysis Develop and maintain detection logic, correlation rules, and security instrumentation based on threat models and MITRE ATT&CK techniques Perform root?cause analysis and technical validation for security findings to improve control effectiveness (not routine alert handling) Partner with application teams on application security engineering, including secure design reviews, authentication and authorization validation, and remediation of OWASP Top 10 and API security issues Support and integrate SAST, DAST, and SCA tooling into development workflows, validating findings and recommended fixes with engineering teams Engineer vulnerability and exposure management processes, prioritizing issues based on exploitability, reachability, and business impact Design and review identity and access controls, including Entra ID policies, privileged access models, and service?to?service authentication Contribute technical input to secure architecture reviews, risk assessments, and control design, producing clear technical standards and reusable security patterns Requirements: Bachelor?s degree in Information Technology, Cybersecurity, or related field, or equivalent hands-on experience 5?8+ years of experience in Information Security Engineering, with 2-3 years in Application Security. Exposure to Vulnerability Management. Strong hands?on experience with application security testing and vulnerability assessment, including Veracode (SAST/DAST/SCA) and Cobalt for penetration testing coordination and remediation validation Strong experience monitoring security events, logs, and alerts using SIEM platforms (Arctic Wolf preferred) Practical knowledge of Fortinet firewalls, including rule validation Proven experience using vulnerability scanner like OpenVAS, along with tools such as Nuclei, OWASP ZAP, Trivy, and Nikto Experience integrating security scanning tools into CI/CD pipelines and engineering workflows Strong knowledge of networking and infrastructure fundamentals (TCP/IP, DNS, HTTP/S, basic routing and switching) Ability to validate vulnerabilities manually and prioritize remediation based on exploitability, exposure, and business impact Experience working closely with application and platform engineering teams, providing practical remediation guidance Strong analytical, documentation, and communication skills with an engineering?first mindset Proficiency with Microsoft 365 applications (Excel, Word, PowerPoint) Certifications: CompTIA Security+/any firewall admin certificate (must have) At least one of the following advanced practitioner certifications: ISC2 Systems Security Certified Practitioner (SSCP) EC?Council Incident Handler (ECIR) CEH CCNA/CCNA Security Azure/AWS Security Preferred: CompTIA Cybersecurity Analyst (CySA+) CompTIA Advanced Security Practitioner (CASP+) Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
More at FINZLY INC