Security Engineer
DFND Security, Inc.USA4d ago
SecurityEngineeringremotecurated-jd
Job description
Security Engineer at DFND Security, Inc.
About the role
DFND Security, Inc. is looking for a Security Engineer to manage vulnerability programs and lead threat modeling initiatives. You will work across engineering and product teams to integrate security into the software lifecycle and evaluate third-party vendor risks.
Key facts
What you'll do
- Oversee security findings from SAST, DAST, SCA, container, cloud, and infrastructure tools.
- Use ArmorCode or similar platforms to track, prioritize, and manage vulnerability remediation.
- Coordinate with engineering teams to validate and close security gaps based on business impact and exploitability.
- Create metrics and dashboards to track SLA compliance and program maturity.
- Conduct threat modeling sessions during design reviews using AI-assisted tools.
- Evaluate third-party SaaS providers and partners through SOC reports, questionnaires, and penetration test results.
- Perform risk assessments for new cloud services, APIs, and enterprise applications.
- Automate security workflows using APIs and scripting.
Requirements
- Bachelor degree in Cybersecurity, Computer Science, Information Systems, or equivalent work history.
- 5 to 7 plus years of professional experience in Security Engineering, Application Security, or Security Operations.
- Hands-on experience with ArmorCode or other Application Security Posture Management (ASPM) tools.
- Proficiency in managing vulnerability remediation across engineering departments.
- Deep knowledge of SSDLC, OWASP Top 10, CWE, and CVSS scoring.
- Experience with threat modeling frameworks like STRIDE, PASTA, or ATT&CK.
- Ability to perform third-party vendor security reviews.
- Strong communication skills to explain technical risks to business stakeholders.
Skills & tools
- Application Security
- Vulnerability Management
- ArmorCode
- Threat Modeling
- AI Security and AI Agents
- Third-Party Risk Management
- Vendor Security Reviews
- Secure SDLC
- Risk Assessment
- Cloud Security
- Security Automation
- DevSecOps
- OWASP
- CVSS
- SAST / DAST / SCA
- APIs
- GitHub
- Jira
- Agile
Practical notes
This position does not support sponsorship or third-party agencies.