IT Security Engineer
Plexus WorldwideAbout the role
We’re hiring an Information Technology Security Engineer III!
About the position
Responsible for penetration testing a variety of environments based on methodical adherence to attack-scoring frameworks. Builds, deploys, and maintains new security automation and orchestration tooling to integrate scanning and monitoring for compliance within existing pipelines. Reviews and guides internal teams in developing more secure codebases, while educating them on best practices to build a strong “security-first” culture.
Who will love this job?
- A team steward, you are motivated to do your best work and strive to elevate the entire team
- A creative problem solver, you are energized by roadblocks and have a knack for troubleshooting problems in stride and solving them in a calm, cool, and collected manner.
- An efficient worker, you enjoy having multiples priorities at one time and multitask and without breaking a sweat.
What you'll do
In Depth Penetration Testing & Threat Modeling:
- Conducts ongoing internal and 3rd party vendor penetration testing and auditing aligned with compliance and legal objectives.
- Performs threat modeling in accordance with OWASP Top 10, MITRE ATT&CK, and similar attack-scoring frameworks.
- Monitors, tests, and proactively reports on current threats and vulnerabilities to respective teams.
- Researches and educates on emerging threats within similar environments and landscapes, along with offering remediation solutions for such.
Security Tooling, Automation, & Orchestration:
- Builds, ships, and maintains various security packages to internal application codebases for automation.
- Identifies vulnerable dependencies across the organization and works with individual teams to resolve them.
- Installs preventative programmatic measures to mitigate repeat vulnerability occurrences.
- Integrates security monitoring within existing CI/CD pipelines. Works with Ansible and Jenkins a plus.
- Builds complex regex pattern identification scripts and parsing to identify potential injection attempts.
- Builds and integrates APIs from disparate systems for orchestrated audits and scans.
Secure-SDLC (SSDLC) Guidance, Codebase Review & Support:
- Develops detailed security design and procedures across the enterprise to drive a standardized set of requirements and align with internal policies.
- Leads secure-SDLC and product security maturity efforts to adopt a shift-left approach to security.
- Conducts platform/service workload design and architecture reviews, as well as audit source code for compliance.
Monitoring, Logging, & Reporting: - Parses a variety of debug logs for determining behavioral baselines to formulate granular internal policies and standards.
- Orchestrates log ingestion into tools and tuning rulesets for advanced metrics reporting on enterprise-wide security posture.
- Builds leaderboards and reporting interfaces on current and forecasted KPIs and risk indicators.
Other General Duties:
- Provides product security related coaching and mentoring to elevate security expertise of development teams.
- Takes ownership of security decisions made in the engineering organization by helping organization members make clear decisions in alignment with organizational goals, backing decisions made, and taking responsibility for their success.
- Fosters a company-wide positive culture across by having conversations based on organizational strategy and principles to create alignment.
- Ensures security goals are understood and continuously worked towards across the organization.
- Takes ownership and responsibility for organizational security practices and processes and their continuous improvement.
- Effectively handles risk, change, and uncertainty across the organization.
- Facilitates organization-wide discussions, ensuring that everyone has an opportunity to share their opinion and be heard, and that discussion outcomes are tied to stated goals.
- Actively advances a culture of documentation and knowledge sharing across the organization.
- Ability to work off-h
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s