CybersecurityJobs.io
← Back to all jobs

Job Description

RainFocus is seeking a mid-level, autonomous Security Engineer to help protect its digital assets, infrastructure, and application ecosystem. This role connects security across IT operations, software delivery, and risk management, with clear ownership areas spanning vulnerability management, secure development collaboration, incident handling, and oversight of key endpoints and security tooling.

Responsibilities

  • Own the vulnerability management program end-to-end, including continuous vulnerability scanning with Tenable and software composition analysis using SonarQube, driving remediation across teams, and validating findings with tools such as Burp Suite and Kali Linux.
  • Manage and triage the crowdsourced bug bounty program through BugCrowd, and monitor the organization’s external security posture rating via Bitsight.
  • Serve as the security voice during developer architecture meetings by reviewing code dependencies, supporting threat modeling for new features, and reinforcing secure coding practices.
  • Lead system impact analyses for proposed changes, represent security on the Change Control Board (CCB), and conduct threat modeling sessions for new systems, features, and infrastructure changes.
  • Triages and document security incidents using OneTrust and Jira, and collaborate with DevOps to ensure security tools are properly deployed across AWS environments and endpoint configurations.
  • Maintain “read-only/audit” oversight of endpoint detection and management and email security tools, including Sophos, JAMF, and BetterCloud, to support compliance and active alerting.
  • Administer security awareness learning modules through RF Academy and lead internal initiatives to keep security top-of-mind for employees.

Requirements

  • All candidates must be a US citizen.
  • 3–5 years of dedicated experience in a technical cybersecurity role (for example, Security Engineer, AppSec Engineer, or Senior Security Analyst).
  • Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure code dependencies (SCA).
  • Proven experience running enterprise vulnerability scanners, interpreting outputs, and driving remediation across cross-functional teams.
  • Foundational knowledge of cloud environments, specifically AWS, and securing cloud-native applications.
  • Excellent collaboration skills, including the ability to work directly with software developers and support fixing security issues without disrupting sprint execution.

Technologies

Tenable, SonarQube, Burp Suite, Kali Linux, BugCrowd, Bitsight, OneTrust, Jira, AWS, Sophos, JAMF, BetterCloud, RF Academy, OWASP Top 10, SCA, PCI-DSS, ISO 27001, SOC 2, CompTIA Security+, CEH, GIAC, CISSP, Python, PowerShell, Bash.

Preferred Experience and Tool Stack

  • Direct experience with the specific stack is a major plus, including Burp Suite, Kali Linux, BugCrowd, and SonarQube.
  • Experience with Tenable, Bitsight, and OneTrust is preferred.
  • Experience with Jira, AWS, Sophos, JAMF, PDQ, and BetterCloud is preferred.
  • CompTIA Security+, CEH, GIAC, or progress toward CISSP and other relevant certifications.
  • Basic scripting skills in Python, PowerShell, or Bash to automate security tasks or log analysis.
  • Experience maintaining compliance with PCI-DSS, ISO 27001, and SOC 2 frameworks.
  • Experience utilizing AI to improve productivity and efficiency, as well as reviewing AI tools, integrations, and features.

Benefits

  • Competitive salaries
  • Competitive benefits
  • 401k
  • Generous PTO
  • Countless other team building activities

Success Measures

  • Decreased time-to-remediation for vulnerabilities identified by Tenable and BugCrowd.
  • Active, constructive participation in developer sprint and architecture cycles, leading to fewer security defects reaching production.
  • Efficient tracking, documentation, and resolution of incidents within OneTrust.
  • Reduced number of security incidents and vulnerabilities.
  • Timely and effective incident response and resolution.
  • Successful implementation and adherence to security policies and procedures.
  • Positive feedback from internal teams on security awareness and training programs.
  • Successful completion of security audits and compliance assessments.

Location and Experience

Lehi, UT (remote). Minimum experience: 3 years.

Why Work at RainFocus

  • RainFocus delivers better insights, experiences, and marketing to millions of attendees at large-scale events.
  • In 2020, the company pivoted its product and services offering to continue growing and serving new clients and events.
  • As part of the RainFocus team, you can experience firsthand the impact of the platform at events around the world.

Similar Jobs