Sobre esta vaga de Associate Security Engineer na Bridgeway Benefit Technologies
Bridgeway is seeking an Associate Security Engineer who will support the development and maintenance of security programs across corporate, engineering, product, compliance, and governance functions. The Associate Security Engineer will assist in building scalable and efficient security solutions that enable other teams to operate securely. This role combines aspects of software engineering, systems administration, operations, compliance, and risk management, contributing to efforts that keep Bridgeway personnel and systems aligned with compliance and security best practices.
This is a remote position with preference given to East Coast candidates.
Responsibilities:
- Assist in designing and implementing scalable and reliable security solutions with guidance from senior engineers.
- Assist in developing and implementing infrastructure-as-code (IaC) solutions to enforce security policies and automate cloud configurations.
- Support the maintenance and enhancement of CI/CD pipelines, automate repetitive tasks, and help improve system efficiency.
- Collaborate closely with development and platform engineering teams to support their security needs.
- Actively seek mentorship from senior engineers and share learnings with peers.
- Complete smaller tasks independently and contribute to mid-level and larger-scale security projects with senior guidance.
- Assist in maintaining SIEM solutions and log ingestion pipelines to support monitoring, alerting, and threat detection.
- Assist in developing incident response playbooks for various alert types and participate in related testing to help ensure operational readiness.
- Monitor emerging threats and assist in operationalizing threat intelligence tools, including alert mapping using the MITRE ATT&CK framework.
- Support vulnerability management and cloud security posture management, including code/dependency scanning, WAF, and DLP configurations.
- Collaborate with application teams to implement enterprise app governance and mobile application management (MAM).
- Assist in developing and applying hardening guidelines for cloud workstations and servers, and in reviewing firewall rules, network security groups, and domain controllers, to help ensure secure configurations.
- Collaborate with product teams to integrate security into SDLC and feature design reviews.
- Support the review of customer and vendor contract security clauses under senior guidance.
- Assist in coordinating phishing simulations, security awareness campaigns (e.g., KnowBe4), and coaching initiatives, helping deliver guidance and training materials to employees.
- Assist in coordinating third-party penetration testing efforts to support mobile and web app security.
- Help maintain compliance documentation for customers and vendors, and contribute to network diagrams and dataflow documentation with other teams.
- Participate in an on-call rotation, providing timely response to security incidents outside regular business hours as needed.
Requirements:
- 1+ years of professional engineering experience and a familiarity with information security
- Foundational knowledge of cloud platforms
- Basic proficiency in scripting and automation
- Basic understanding of version control
- Intermediate proficiency with IaC and CI/CD pipeline tools
- Basic understanding of containerization and orchestration concepts (e.g., ECS, ACA, K8s, Docker)
- Strong analytical and troubleshooting skills with the ability to identify critical issues and escalate with recommendations
- Bachelors in Information Technology, Software Development, or related field