Dispel

Moving Target Defense-based remote access systems for people and machines.

Senior Security Architect

Security EngineerSecurity EngineerFull TimeRemoteTeam 51-200Since 2014H1B No SponsorCompany SiteLinkedIn

Location

Texas

Posted

59 days ago

Salary

$100K - $134K / year

Bachelor Degree8 yrs expEnglishAWSAzureCloudCyber SecurityGoogle Cloud PlatformPythonGo

Job Description

• Plan and execute internal red team engagements against the ZTE platform and corporate infrastructure • Conduct regular penetration testing of applications, APIs, cloud infrastructure (AWS GovCloud), and network segments • Develop and maintain adversary emulation capabilities aligned with MITRE ATT&CK for ICS • Document findings with actionable remediation guidance and track to resolution • Coordinate with external penetration testing firms for annual assessments • Lead threat modeling sessions for new features and architectural changes using STRIDE, PASTA, or attack trees • Review and approve security architecture for product changes before implementation • Participate in Change Control Board (CCB) reviews with security sign-off authority • Define security requirements and acceptance criteria for development teams • Maintain threat models for ZTE components including Moving Target Defense, access control, session recording, and password vaulting • Design and implement deception technologies and honeypots within the product and infrastructure • Collaborate with SOC to develop detection rules based on offensive findings • Create purple team exercises bridging red team operations with blue team response • Develop adversary playbooks that inform SOC runbooks • Implement and maintain security controls in CI/CD pipelines (SAST, DAST, SCA, secrets scanning, container scanning) • Define and enforce security gates for code promotion • Review infrastructure-as-code for security misconfigurations • Integrate security testing into GitHub workflows • Establish software supply chain security controls (SBOM generation, dependency verification) • Stand up and operationalize vulnerability management program in coordination with SOC • Define vulnerability severity thresholds, SLAs, and escalation procedures • Triage and prioritize vulnerabilities based on exploitability and business context • Track remediation progress and report metrics to leadership • Partner with SOC team on playbook development for incident response • Provide offensive perspective on detection gaps and coverage • Support SOC maturation through training, tabletop exercises, and purple team activities • Contribute to SIEM rule development and tuning (Google SecOps)

Job Requirements

  • 8-12 years of experience in cybersecurity with 5+ years in offensive security, application security, or security architecture
  • Demonstrated experience conducting penetration testing and red team operations
  • Strong knowledge of cloud security (AWS required; Azure/GCP beneficial)
  • Experience with CI/CD security tooling and DevSecOps practices
  • Hands-on experience with threat modeling methodologies
  • Proficiency in at least one scripting/programming language (Python, Go, Bash)
  • Understanding of OT/ICS security concepts and protocols
  • Experience with vulnerability management tools and processes
  • Excellent written and verbal communication skills

Benefits

  • Competitive salary and performance bonus
  • Comprehensive health, dental, and vision insurance
  • 401(k) with company match
  • Opportunity for incentive units grant
  • Generous paid time off and holidays
  • Flexible work environment with opportunities for remote work

Related Categories

Related Job Pages

More Security Engineer Jobs

Staff Security Engineer

Chainguard

Making the software supply chain secure by default.

Security Engineer59 days ago
Full TimeRemoteTeam 51-200Since 2021H1B Sponsor

Design and deploy security controls at Chainguard

CloudLinuxMacOSOpen SourcePythonGo
United States
$170K - $190K / year

Account Executive, Cybersecurity

Funded.club

Stress-free hiring for startups

Security Engineer59 days ago
Full TimeRemoteTeam 51-200Since 2019H1B No Sponsor

Account Executive selling SaaS solutions to enterprise clients at Legit Security

Massachusetts
Security Engineer59 days ago
Full TimeRemoteTeam 51-200Since 2019H1B No Sponsor

Senior Technical Account Manager driving solution success in cybersecurity.

AzureCloudJenkins
United States

Principal Product Manager, Application Security Testing

GitLab

Build software faster. The One DevOps Platform enables your entire org to collaborate around your code. We're hiring.

Security Engineer59 days ago
Full TimeRemoteTeam 1,001-5,000Since 2014H1B No Sponsor

Principal Product Manager driving application security product strategy at GitLab

United States
$145.6K - $312K / year