Transamerica logo
TransamericaPosted 1 month ago

Intermediate Cyber Security Engineer

$70,000–$84,000 year

On-siteDenver, Colorado, United States or Philadelphia, Pennsylvania, United States

Full TimeLarge

Job Summary

Conduct daily vulnerability assessments across diverse on-premise and cloud infrastructure, identifying weaknesses against industry best practices and NIST CSF standards. Gather and analyze security data to draft reports, create dashboards, and track key indicators for departmental use. Support the secure SDLC by assisting with static and dynamic application security testing, validating vulnerabilities, and coordinating remediation with development teams. Enhance the vulnerability management lifecycle through automation of intake, prioritization, and continuous process improvement. Serve as an application security ambassador to promote secure coding practices and guide employees on reducing application risk.

Required Qualifications

  • Bachelor's degree with emphasis in Computer Science, MIS, Auditing, Finance, or Business
  • 1 to 3 years of cyber security engineering work experience
  • Experience with one or more application security domain areas, including secure coding, security within the SDLC, application threat modeling, static and dynamic application security testing, software composition analysis, API security, web application firewalls (WAF), container security, vulnerability validation and remediation, application data protection, and alignment with applicable security standards and control frameworks
  • Knowledge of applicable control frameworks such as: NIST CSF
  • Strong foundation in core security technologies and advanced persistent threat (APT) controls, including SIEM, endpoint security platforms, firewalls, intrusion detection and prevention systems, data loss prevention, syslog servers, vulnerability scanners, web application firewalls, threat intelligence feeds, digital forensics, and application allowlisting
  • 2-3 years of related work experience with application security
  • Working knowledge of one or more vulnerability management systems including Rapid7, ServiceNow Vulnerability Response (VR), Synk, CrowdStrike, etc.
  • Hands-on experience with application security, dynamic scanning, static scanning, and container security
  • Experience with systems such as ServiceNow, JIRA or equivalent
  • Ability to fluently read, write and speak English
  • Strong background in creating and automating vulnerability reports and dashboards including trending and graphing data
  • This is a hybrid position requiring three days in office per week in our Denver or Cedar Rapids hub location
  • Applicants must be authorized to work for any employer in the U.S.
  • Relocation assistance will not be provided for this position

Desired Qualifications

  • Certifications - OSCP, CISSP, CEH and/or CompTIA Security+/CySA/CASP+
  • Experience in Insurance, Financial Services or other Fin-Tech Industries
  • Preference given to candidates with Transamerica products, systems and/or domain knowledge

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce