Security Engineer (application Security)

Contentful Contentful · Enterprise · New York, NY · Security

Security Engineer role focused on application security, cloud-native infrastructure, and corporate environments. Responsibilities include managing alerts, leading initiatives like threat modeling and vulnerability identification, and embedding security practices. Requires experience with AWS, Kubernetes, Python, Terraform, and networking fundamentals.

What you'd actually do

  1. Lead initiatives and partner with teams to embed practical security safeguards and champion a security-first mindset across the business.
  2. Lead security assessments and remediation for cloud-native applications, infrastructure, and vendor integrations to proactively identify and address risk.
  3. Support vulnerability management by identifying, tracking, and partnering with teams to drive remediation of security issues across product and corporate environments.
  4. Develop and maintain security solutions through custom development and effective tool management to enhance efficiency and operational effectiveness.
  5. Leverage industry standards to develop hardening requirements and monitoring mechanisms that enforce and strengthen the security of systems and environments.

Skills

Required

  • AWS architecture, services, and security features
  • Python
  • Kubernetes and container security
  • Terraform
  • Networking knowledge (cloud networking, OSI model, TCP/IP, routing)
  • Embedding security in SDLC
  • Vulnerability management
  • Incident response
  • OWASP Top 10 mitigation
  • Communication skills

Nice to have

  • JavaScript
  • Go
  • authentication and authorization protocols (OAuth, SAML, JWT, IAM)

What the JD emphasized

  • Candidates must be located in the eastern time zone
  • 4+ years of security engineering, DevSecOps, or equivalent experience
  • Hands-on expertise with AWS architecture, services, and security features
  • Proficiency in Python to build and maintain security tools
  • Familiarity with Kubernetes and container security, including configuration and runtime protection
  • Experience using Terraform to build, deploy, and maintain infrastructure as code
  • Demonstrable ability to embed security considerations throughout the software development lifecycle
  • Hands-on involvement supporting vulnerability management and incident response functions
  • Experience identifying and mitigating OWASP Top 10 vulnerabilities in web applications and APIs