Security Engineer

2 months ago


Seattle, United States RED SKY Consulting Full time

Job Title: Security Engineer - Cloud

Location: Hybrid Onsite in Issaquah, WA or Chicago, IL 3x / Week

Type: Direct Hire


Bottom Line / In a Nutshell:

  • Ideally around 10 years in the industry 5+ years in Security Engineering
  • Security Engineering experience with ecommerce/Retail sites/services hosted in Cloud (Azure/GCP)
  • Experience with Security Tools and Frameworks
  • Bot management (Kasada, DFP, Noknok etc)
  • Experience working with CDN/WAFs like Fastly or Akamai
  • Security issue detection/debugging/mitigation experience, Scripting ability


Summary:

Security Engineers develop, design, implement, and integrate security systems used to safeguard enterprise assets against cyber-attack. Security Engineers drive innovation, influence delivery, and maximize performance. They deliver high quality artifacts, develop and run security tests and continuously tune security tools for optimization. Security Engineers identify gaps and inefficiencies and work with the business to implement solutions based on their requirements.


As part of the Digital Site Security team the Cloud Security Engineer will be focused on improving the security posture and delivery of new and enhanced security capabilities for our BC and BD properties.


Role & Responsibilities:

  • Provides security and technical expertise to support the development of security objects to satisfy business requirements.
  • Analyzes and administers security policies to control physical and virtual system access.
  • Identifies and investigates security issues and develops security solutions that address compliance requirements that can/ do impact security.
  • Identifies, develops, and implements mechanisms to detect security incidents in order to enhance compliance and support of the security standards and procedures.
  • Assesses business role requirements, reviews authorization roles, and supports authorizations
  • Demonstrates a comprehensive skill set with testing authorizations for multiple environments and coordinates testing with business/technical users
  • Validates system configurations to ensure the safety of information systems assets and protects information systems from intentional or inadvertent access or destruction.
  • Implements best practice when applying knowledge of information systems security standards/practices (e.g. Access control and system hardening, system audit and log file monitoring, security policies, and incident handling).
  • Designs and coordinates activities/engagements with other departments (loss prevention, legal, networking, etc.).
  • Identifies security gaps that expose us to potential exploit and develop short- and long-term prioritized remediation to address those gaps.
  • Develops and executes security controls, defenses, and countermeasures to intercept and prevent internal/external data infiltrations.
  • Determines strategy and protocol for network behavior, analysis techniques, and tool implementation.
  • Identifies and resolves problems often anticipating issues before they occur or before they grow; develops and evaluates options; and implements solutions that support the business.
  • Provides subject matter expertise in systems security policies, standards/practices, protocols, and technologies.
  • Configures, deploys, maintains, and supports security tools.
  • Protects confidentiality, integrity, and availability of information from being disclosed to unauthorized parties.
  • Creates dashboards, configures alerts, implements and supports security software platforms, and monitors tools/apps.
  • Identifies opportunities for streamlining, and increasing effectiveness through continuous process improvement.
  • Implements practices, processes, and procedures consistent with our information security policy and IT standards.
  • Develops and documents security events and incident handling procedures into Playbooks.
  • Ensures that incident documentation is comprehensive, accurate, and complete.
  • Triages, prioritizes, investigates, and coordinates security events and incident handling activities.
  • Collaborates with business partners, project teams, and team members to build secure solutions that protects data and enables the business with tools and processes that make sense and adapt to changing business needs both on-premises and in the cloud.
  • Works with internal and external auditors.
  • Designs, configures and maintains various degrees of security.
  • Works with stakeholders and Security Architects to identify security solutions that support their business requirements.
  • Partners with other Information Security groups to conduct security risk assessments on new solutions and systems, periodic security risk assessments on existing systems; and identifies and/or recommends appropriate security mitigations and best practices.

Required Skills:

  • 2+ years’ experience in Security Engineering.
  • Experience in offensive security roles, such as penetration testing or ethical hacking.
  • Experience with Security Engineering of sites hosted in Public Cloud (Google, Azure)
  • Experience working with WAFs and CDNs such as Akamai or Fastly.
  • Proficiency in scripting and programming languages (e.g. Python, JS, Java, SQL) for tool development and automation.
  • Strong understanding of operating systems, network protocols, and web application security.
  • Extensive experience with security tools and frameworks (e.g. Kasada, Microsoft DFP, Bloodhound, Cobalt Strike.).
  • Vast experience in performing code review to identify vulnerabilities.
  • A passion for cybersecurity and a commitment to staying current with emerging threats and industry trends.

Recommended Skills:

  • Bachelor's/Master's degree or equivalent experience in Computer Science, Information Security, or a related field.
  • One or more professional network and security certifications such as Security+, Network+, CCNA, GSEC, CISA or CISSP (or equivalent work experience).
  • Experience performing computer forensics.
  • Familiarity ITILv2/v3 processes such as Service Support, Service Delivery, or Continual Service Improvement.
  • Familiarity with Regulatory Compliance and industry standards, such as HIPAA, SOX, and PCI.
  • Familiarity in a DevOps or DevSecOps environment.



  • Seattle, United States Abnormal Security Full time

    Job DescriptionJob DescriptionAbout the RoleAbnormal Security is looking for a Senior Software Engineer who is passionate about Security & Privacy to join the Platform Security team building platform services and components of the company infrastructure to enforce secure-by-design and secure-by-default standards across the board. This role will design,...


  • Seattle, Washington, United States Abnormal Security Full time

    About the RoleAbnormal Security is a leading cybersecurity company that focuses on providing robust security solutions to protect its clients' infrastructure. We are seeking an experienced Senior Software Engineer who can join our Platform Security team and contribute to designing, developing, and maintaining secure-by-design platform services and...

  • Security Engineer

    3 days ago


    Seattle, Washington, United States Apple Full time

    About the RoleWe are seeking a highly skilled Security Site Reliability Engineer to join our dynamic team. As a critical member of our ASE Security dev team, you will play a key role in ensuring the security, reliability, and scalability of our systems and infrastructure.This is not a checkbox role; instead, you will define, advocate, and drive adoption for...


  • Seattle, Washington, United States Amazon Full time

    About the Job:We are looking for a highly motivated Security Engineering Lead to join our team. As a Security Engineering Lead, you will be responsible for leading a team of security engineers to design and implement secure systems and solutions.Responsibilities:Lead a team of security engineers to design and implement secure systems and solutionsCollaborate...

  • Security Engineer

    2 months ago


    seattle, United States RED SKY Consulting Full time

    Job Title: Security Engineer - CloudLocation: Hybrid Onsite in Issaquah, WA or Chicago, IL 3x / Week Type: Direct Hire Bottom Line / In a Nutshell: Ideally around 10 years in the industry 5+ years in Security EngineeringSecurity Engineering experience with ecommerce/Retail sites/services hosted in Cloud (Azure/GCP)Experience with Security Tools and...

  • Security Engineer

    2 months ago


    Seattle, United States RED SKY Consulting Full time

    Job Title: Security Engineer - CloudLocation: Hybrid Onsite in Issaquah, WA or Chicago, IL 3x / Week Type: Direct Hire Bottom Line / In a Nutshell: Ideally around 10 years in the industry 5+ years in Security EngineeringSecurity Engineering experience with ecommerce/Retail sites/services hosted in Cloud (Azure/GCP)Experience with Security Tools and...


  • Seattle, United States Actalent Full time

    Description: A growing multi-disciplinary design-build company is seeking security designers for numerous upcoming projects in Seattle. The ideal candidate will have 2+ years of experience within telecom design that was familiarity with Revit and will have electrical design experience. This is a great opportunity for an entry to mid level designer to grow...


  • Seattle, Washington, United States Amazon Full time

    Job DescriptionWe are seeking a highly skilled Senior Security Engineer to join our team at Amazon. As a key member of our AppSec organization, you will collaborate with software development teams to ensure the security of our customers' data while developing innovative services.Responsibilities:Creating threat models for various software projectsManual and...


  • Seattle, Washington, United States Apple Full time

    At Apple, we don't just build products – we craft experiences that revolutionize industries. Our diverse team of engineers and innovators inspire each other to create groundbreaking solutions. If you're passionate about designing and engineering systems that shape the future, join us as a Senior Software Engineer on our Apple Service Engineering (ASE)...


  • Seattle, Washington, United States Amazon Full time

    About the RoleWe are seeking a skilled Hardware Security Engineer to join our team. As a Hardware Security Engineer, you will play a key role in ensuring the security and integrity of our hardware-based systems and applications. You will be responsible for conducting security reviews, including penetration testing, analyzing threat models, and developing...


  • Seattle, Washington, United States Amazon Full time

    About the Job DescriptionWe are seeking a highly skilled Sr. Security Engineer, AppSec to join our team. As a Sr. Security Engineer, you will play a critical role in ensuring the security of Amazon's applications.Your primary responsibility will be to design, implement, and maintain secure architecture for our applications. This includes developing threat...


  • Seattle, Washington, United States Fred Hutchinson Cancer Center (Fred Hutch) Full time

    Job SummaryWe are seeking an IT Security Engineer with expertise in network defense and cybersecurity to join our team at Fred Hutch. As a key member of our IT department, you will play a crucial role in protecting our systems and data from cyber threats.


  • Seattle, Washington, United States Bank of America Full time

    Job DescriptionWe are looking for an experienced Application Security Engineer to join our team at Bank of America. As an Application Security Engineer, you will be responsible for designing and implementing secure software solutions that meet the needs of our business.About the RoleThis is an advanced technical role that requires a minimum of 6 years of...


  • Seattle, United States TEKsystems Full time

    Job DescriptionJob DescriptionJob Description – Cloud Security Engineer (IR) Our cybersecurity operation team (SecOp) is looking for a Cloud Security Engineer, who will join and help the team to perform Security Operations Center (SOC) duties, which focus on cloud incident response, malware analysis, and monitoring. This role will work with the team and...


  • Seattle, Washington, United States Amazon Full time

    About Amazon SecurityAmazon Security is responsible for maintaining customer trust and delivering delightful customer experiences. As a Senior Security Engineer, you will be part of a team that creates and maintains high-security standards across all of Amazon's products and services.


  • Seattle, Washington, United States Amazon Full time

    About AmazonAmazon is a leading technology company that operates on a global scale, committed to delivering exceptional customer experiences. Our organization values diversity, inclusivity, and innovation, making it an ideal place for talented professionals to grow their careers.Job OverviewWe are seeking an experienced software development engineer to join...


  • Seattle, United States Cognizant Full time

    Principal Security Engineer – IAM Experience: 12 + years Location: Remote The Principal Security Engineer - IAM is an expert in Identity management and privileged access. They are part of a team that develops, implements, and maintains identity and access management systems. The primary goals of this IAM Engineer are to ensure that only authorized...


  • Seattle, United States Aloden, Inc. Full time

    Security Test Engineer Only W2 (Citizen, GC) Location: Seattle, WA (Hybrid - 3 Days Onsite) Contract Role Candidate Preference: Local to Seattle, WA or nearby areas. Role Overview: As a Security Engineer/Tester, you will be responsible for performing authorized security assessments on critical, large-scale applications. You'll work proactively...


  • Seattle, Washington, United States Zscaler Full time

    About Zscaler.As a leading cloud security platform, we protect thousands of enterprise customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Our mission is to make the cloud a safe place to do business and a more enjoyable experience for enterprise users.We foster an inclusive and supportive...


  • Seattle, Washington, United States Amazon Full time

    At Amazon, we are seeking a talented Cloud Security Engineer to join our Malware Detonation team. As a key member of this team, you will play a crucial role in designing and implementing complex security services for AWS.The ideal candidate will have 3+ years of non-internship professional software development experience and a strong background in...