Overview
The Lead Cybersecurity Engineer will serve as a key partner to software development teams, focusing on integrating security directly into the Software Development Lifecycle (SDLC). This role is responsible for the security engineering of cloud environments (AWS, Azure) and vulnerability management for both Infrastructure as Code (IaC) and application code.
Key Responsibilities
-
Security by Design: Implement and consult on secure development practices.
-
DevSecOps Integration: Integrate security practices into DevOps pipelines.
-
Vulnerability Management: Manage, analyze, and track security risks to remediation using tools like CodeQL, Rapid7, penetration testing outputs, and bug bounties.
-
Developer Collaboration: Serve as a trusted advisor to software engineers, architects, and product owners, providing context-aware guidance and documenting security architectures.
-
Security Test Onboarding: Collect and communicate scope/access details for penetration testing and handle assessment outputs through defect management.
Qualifications & Requirements< data-path-to-node="14">
Education & Experience
-
Bachelor''s Degree in Computer Science or a related field with 8+ years in information security, OR
-
Master''s Degree with 6+ years of experience.
< data-path-to-node="16">
Technical Skills (Required)
-
Application Security: Deep understanding of vulnerabilities and remediation (OWASP, CWE/CVE, SANS 25).
-
Broad Security Knowledge: Enterprise security architecture, threat modeling, vulnerability assessment, risk analysis, defense-in-depth, IAM, and API security.
-
Cloud Security: Hands-on experience with AWS and/or MS Azure.
-
Development & Scripting: Proficiency in one or more languages (Java, Python, .NET, JS) and automation scripting to streamline security processes.
-
Certifications: Professional certification such as CISSP, CCSP, GWAPT, GWEB, or AWS Security Specialty.
< data-path-to-node="18">
Technical Skills (Desired / Nice-to-Have)
< data-path-to-node="20">
Soft Skills
โ ๏ธ
Candidate Screening Criteria / Red Flags
-
Location Constraint: Candidates must be local to Chicago, IL; Peoria, IL; or Dallas, TX. Non-local candidates will not be considered.
-
Tenure: Candidates with a history of job-hopping/choppy tenure will not be considered.