Security Engineer
uShipAbout the role
uShip is seeking a motivated Security Engineer to join our team full-time and help protect our systems, infrastructure, and data. You will contribute to implementing and supporting security controls to defend against current threats and maintain compliance with relevant standards and industry best practices. As a trusted resource in our collaborative, fast-paced environment, you will partner with IT, Development, and Product teams to proactively identify vulnerabilities, assist with incident response, and support ongoing enhancements to our security systems, processes, and practices.
Requirements
- 3+ years of demonstrated experience in systems (On-Prem, Hybrid, and Cloud) and application security, including infrastructure hardening and secure software development using security frameworks and best practice methodologies
- 3+ years of demonstrated security engineering within complex AWS environments as a primary focus
- 3+ years of demonstrated knowledge in common web application and infrastructure vulnerability detection, mitigation, remediation, and reporting with related security / penetration testing tools
- 2+ years of experience with EDR, Zero-Trust, Email, and SIEM security toolset deployment with Crowdstrike as a focus
- 2+ years working with a Security Operations Center internal and external
- 2+ years with securing virtual servers / services, CI/CD Pipelines (Github / GitHub Actions / GitHub Advanced Security), and microservices environments (including serverless) via Infrastructure as Code deployment methods (Terraform)
- Attention to detail and a commitment to delivering high-quality, secure applications, systems, and platforms
- Keeping current with information security news and provide updates to the team and business as needed
Preferred Experience
- Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or CompTIA Security+ / Pro
- Security Engineering and Administration within Azure / GCP environments.
- Cloudflare-based networking security and administration.
- Demonstrated experience with AI security and best practices
- Familiarity with secure coding practices in languages (including JavaScript, Node, C#, SQL) and DevSecOps practices such as SAST and DAST scanning.
- Possesses a solid understanding of authentication and authorization mechanisms and best practices (OAuth, SSO, SAML, JWT, MFA, Zero Trust with Okta and Zscaler as focuses)
- Strong analytical and problem-solving skills within a team environment
- Excellent communication skills, both written and verbal, including the ability to clearly articulate security risks to non-technical stakeholders
- Experience with weekly security communications and presentations to leadership
Responsibilities
- Security Assessment & Testing: Participate in regular security assessments of applications and systems, including static and dynamic analysis, penetration testing, and code reviews, to identify and mitigate vulnerabilities
- Security Integration in SDLC: Collaborate with development and product teams to integrate security measures throughout the software development lifecycle (SDLC), from design to production
- Vulnerability Management: Help identify, prioritize, and track security vulnerabilities; provide remediation recommendations, such as patching or secure coding fixes. Monitor threat intelligence feeds and assist in applying relevant protections.
- Threat Modeling: Work with development teams to perform threat modeling and risk assessments for new applications and features to identify potential security issues early in the development process to protect our systems, data, and users from advanced persistent threats
- Security Tooling & Automation: Assist in implementing and maintaining security tools and automation to detect vulnerabilities and monitor security posture.
- Incident Response & Investigation
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s