Security Engineer
Job Description
This role focuses on strengthening Application Security (AppSec) and AI Security by finding, evaluating, and reducing risk across software and AI delivery.
Responsibilities
- Identify, assess, and prioritize routine to moderately complex AppSec and AI Security risks, vulnerabilities, and control gaps through application, code, dependency, infrastructure-as-code, and AI workload scanning
- Document scan results and escalate high-impact or highly complex issues as appropriate
- Implement, maintain, and improve security controls and automation inside GitLab development and CI/CD workflows to surface issues earlier, support secure releases, and streamline remediation
- Review Terraform configurations and related cloud deployment patterns for security weaknesses, policy violations, and control gaps
- Validate remediation using established standards and processes
- Support configuration, monitoring, and continuous improvement of WAF protections for internet-facing applications and APIs, including services that enable AI capabilities
- Partner with engineering teams using Java, Python, and Go to interpret scanning outcomes, recommend practical fixes, encourage secure coding practices, and reduce recurring vulnerabilities
- Perform defined security assessments for applications, APIs, AI solutions, models, agents, and supporting data flows to evaluate control effectiveness and improvement opportunities
- Document assessment results and validate remediation efforts
- Collaborate with business, development, data, and technology stakeholders to document AppSec and AI Security requirements and implement solutions aligned to security needs and identified risks, with senior guidance for complex or cross-enterprise decisions
- Provide practical guidance on established security controls, risk management practices, and security-related standards; route novel, high-risk, or complex interpretations to senior security resources
- Develop and maintain security procedures, work instructions, standards, and technical documentation, including review and approval as required
- Support risk assessments, audits, and continuous improvement initiatives by providing evidence, completing assigned actions, and recommending improvements within scope
- Perform additional responsibilities consistent with the role’s scope and level, as assigned
Requirements
- 3+ years of related IT Security professional experience
- Bachelor’s degree; in lieu of a degree, an additional two years of relevant experience beyond the listed qualifications may be accepted
Technologies
- GitLab, CI/CD
- Terraform
- WAF
- Java, Python, Go
- AI
Benefits
- Medical, dental, and vision insurance
- Life insurance
- 401k
- Paid Time Off (PTO)
- Volunteer Paid Time Off (VPTO)
Licensure / Certifications
- Preferred: Amazon AWS Cloud Practitioner (Amazon)
Role Details
- Location: Eagan, MN (hybrid)
- Salary: USD 79,100 - 130,500 per year
- Hybrid designation: In-office two days each week with most teams designating at least one anchor day; the remainder of the week is remote
- Experience level: 3+ years