Eccalon LLC logo
Eccalon LLCPosted 3 weeks ago
EXPIRED

Security Software Engineer On-site

On-siteDetroit, Michigan, United States

Full TimeBachelors DegreeSmall

Job Summary

Design and develop secure software with a security-first mindset embedded in every phase of the SDLC, from design and code review through CI/CD and cloud deployment. Conduct architecture reviews and code hardening to address OWASP Top 10 and DoD STIGs while automating security gates in pipelines using SAST, DAST, and dependency scanning. Lead code reviews, triage vulnerabilities within POA&M timelines, and support incident response for application-layer events. Implement IAM controls, JIT provisioning, and security logging to satisfy audit and continuous monitoring requirements in AWS Commercial, GovCloud, and Azure GCC High environments. Serve as the embedded security champion for engineering squads, delivering training and runbooks to raise the security bar across DevOps and SRE teams.

Required Qualifications

  • Bachelor's degree in Computer Science, Engineering, or related field—or equivalent experience
  • 3+ years of software engineering experience with a strong focus on security
  • Proficiency in one or more programming languages (e.g., JavaScript/TypeScript, Python, Go, C#)
  • Experience with secure coding practices and frameworks
  • Strong understanding of application security principles, including: OWASP Top 10, Secure API/REST design, Cryptography fundamentals, Authentication/authorization patterns
  • Experience with code scanning tools (SAST/DAST), threat modeling, and penetration testing
  • Familiarity with NIST 800-171, CMMC, or FedRAMP security control requirements and evidence collection
  • Hands-on experience with AWS and/or Azure security services (IAM, WAF, Security Hub, Defender, Sentinel)

Desired Qualifications

  • GCC High or GovCloud experience
  • Experience with container security (Docker, ECS)
  • Working knowledge of Zero Trust Architecture principles
  • Experience building DevSecOps pipelines in regulated environments; familiarity with tools like Prisma, Checkov, Snyk, or Aqua
  • Relevant certifications (any of the following): CISSP, CSSLP, or CASP+
  • OSCP
  • CEH
  • GIAC (GWAPT, GSEC, GWEB) or CCP/CCA (UK Cyber Essentials equivalent)
  • Experience securing microservices or event-driven architectures on ECS
  • Background in federal or cleared environments

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles