Stack Engineer Cybersecurity
• Undergraduate degree or equivalent experience
• 5+ years of development and testing experience in C# / .Net
• 5+ years of development experience on Microsoft SQL Server (preferred) or Oracle Database
• 5+ years Database Design/Programming (Stored Procedures/Functions)
• 5+ years of SDLC or DevOps/Agile experience
• 5+ years with Angular
• 5+ years working experience with API REST web services
• 5+ years experience with version management tools and implementing CI/CD pipelines (Git, AzureDevOps, SVN, etc.)
• 3+ years of hands-on experience remediating application security vulnerabilities, including upgrading vulnerable dependencies and resolving findings from SAST, DAST, or SCA tooling
• 2+ years Hands-on experience using AI-assisted development tools (GitHub Copilot, Claude, or similar) for code generation, code comprehension, refactoring, or test creation, with the judgment to validate and correct their output
• Excellent verbal and written communication
Desired Skills:
• Designs, codes, tests and debugs applications and components that meet all technical specifications, business requirements, and secure coding standards per assigned work items
• Remediates application security vulnerabilities identified through static (SAST), dynamic (DAST), and software composition analysis (SCA) scanning, prioritizing work by severity, exploitability, and remediation service level targets
• Analyzes scan findings to determine root cause, separate true positives from false positives, and recommend the appropriate code fix, configuration change, compensating control, or risk acceptance path
• Upgrades and patches vulnerable third-party libraries, frameworks, and end-of-life runtimes (.Net, Angular, database and reporting components), resolving the breaking changes and dependency conflicts those upgrades introduce
• Applies secure coding practices to eliminate common vulnerability classes, including injection, broken authentication and access control, insecure deserialization, weak cryptography, hard-coded secrets, and the remainder of the OWASP Top 10
• Uses AI-assisted development tools (GitHub Copilot and other enterprise-approved AI coding assistants) to accelerate comprehension of legacy code, generate candidate remediations, refactor safely, and produce unit and regression tests
• Reviews, tests, and takes full ownership of AI-generated code, confirming it is correct, secure, performant, and compliant with enterprise standards, so that closing one finding never introduces a new one
• Builds and strengthens automated test coverage so security fixes can be delivered quickly and confidently with minimal regression risk
• Integrates security, dependency, and secrets scanning into CI/CD pipelines so vulnerabilities are surfaced and resolved early in the development lifecycle
• Work closely with lead engineers to develop the best technical design and approach for new product development and for remediation of systemic security findings
• Collaborates closely with Business Analysts, Information Security, and application owners on developing requirements and assists with estimating remediation effort
• Instill best practices for secure software development and documentation, assure designs meet requirements, and deliver high-quality work on budget and on-time.
• Translate business requirements into technical solutions, recommend alternative technical and business approaches, and lead engineering efforts to meet timelines with optimal solutions
• Ability to take on a complex technical problem that is not well-defined, decompose into manageable tasks, provide proper estimates, and lead/coordinate other team members to collectively deliver the end solution
• Excellent organizational skills and focus on accuracy and attention to detail.
• Excellent analytical, problem solving and troubleshooting abilities
• Work with team to achieve timely resolution of all security findings, meeting or exceeding Service Level Agreements
• Reports remediation progress, backlog burn-down, and residual risk clearly to engineering and business stakeholders
• Ability to prioritize tasks and work concurrently on multiple tasks