Lead Engineer, Information Security (Application Security)
Ai Security
Application Security
Cloud Native Security
Cloud Platforms
DevSecOps
Dynamic Application Security Testing
Engineer
Information Security
InfoSec
Owasp Top Ten
Security Automation
Security Standards
Security Testing
Solution Architecture
Static Application Security Testing
Static Code Analysis
Technical Lead
Threat Modeling
Web Application Firewall
Web Security
Job Description
RXO is hiring a Lead Engineer to strengthen application security across a multi-cloud environment in a senior individual contributor capacity. This role focuses on scaling secure application architecture, embedding security into the SDLC and DevSecOps workflows, and partnering with engineering teams to surface and remediate risks, including cloud-native initiatives and AI-driven solutions.
What you’ll do
- Lead development and governance of application security standards, secure architecture principles, and threat modeling practices across the enterprise.
- Perform security assessments and threat modeling for emerging technologies, including Agentic AI solutions, Large Language Models (LLMs), and autonomous AI workflows.
- Analyze and tune Web Application Firewall (WAF) configurations to support secure application behavior.
- Integrate and optimize automated security tools, including SAST, DAST, and Software Composition Analysis (SCA), within CI/CD pipelines and DevSecOps processes.
- Partner with software engineering teams to identify vulnerabilities and provide code-level remediation guidance aligned with secure coding best practices.
- Lead and support security awareness efforts, including mentoring developers and facilitating Security Champion programs across engineering teams.
- Evaluate cloud-native applications and services across Azure, GCP, and Oracle Cloud Infrastructure (OCI) to ensure alignment with security standards.
- Support the implementation of security controls in development pipelines, including mechanisms to prevent deployments with unresolved critical or high-risk vulnerabilities.
- Drive continuous improvement initiatives to enhance application security processes, tooling, and developer enablement.
What you bring
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field (or equivalent combination of education and experience).
- 3+ years of experience in Application Security, Security Engineering, DevSecOps, or a related cybersecurity discipline.
- Experience identifying and remediating security vulnerabilities within application code and software development environments.
- Experience working with enterprise WAF platforms such as Akamai App & API Protector, F5 Advanced WAF, or similar technologies.
- Experience securing cloud-native workloads and applications within Azure, GCP, and/or OCI.
- Experience with container technologies, including Docker and Kubernetes.
- Experience integrating security tools into CI/CD pipelines and development workflows.
- Knowledge of OWASP Top 10, Common Weakness Enumeration (CWE), secure API design principles, and application security best practices.
- Strong analytical, problem-solving, and communication skills with the ability to collaborate across technical teams.
Technologies you’ll work with
- Web Application Firewall (WAF)
- Akamai App & API Protector, F5 Advanced WAF
- SAST, DAST, Software Composition Analysis (SCA)
- CI/CD, DevSecOps
- Azure, Google Cloud Platform (GCP), Oracle Cloud Infrastructure (OCI)
- Docker, Kubernetes
- OWASP Top 10, Common Weakness Enumeration (CWE)
- Agentic AI solutions, Large Language Models (LLMs)
Benefits
- Comprehensive medical, dental, and vision plans
- 401(k) retirement plan with up to 5% company match
- Pre-tax accounts to help streamline eligible expenses
- Company-paid disability and life insurance
- Employee Assistance Program (EAP)
- Career and Leadership Development Programs
- Paid time off, company holidays, and volunteer days
It’d be great if you also have
- Experience securing AI-enabled applications, LLM-based solutions, or autonomous agent workflows
- Microsoft Certified: Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, CISSP, CSSLP, CASE, GWEB, or related security certifications
- Experience with Akamai and/or F5 security platforms in large-scale enterprise environments
- Experience leading Security Champion programs or mentoring engineering teams on secure development practices
- Ability to influence cross-functional teams and drive security improvements through collaboration and technical expertise
- Experience developing scalable security frameworks that support innovation while managing enterprise risk
Similar Jobs
A