Sobre esta vaga de Lead Engineer, Information Security (Application Security) na RXO
Accelerate your career at RXO
RXO is a leading provider of transportation solutions. With cutting-edge technology at the center, we're revolutionizing the industry with our massive network and commitment to finding solutions for every challenge. We create more efficient ways for shippers and carriers to transport goods across North America.
At RXO, we're looking for a Lead Engineer, Application Security to help strengthen and scale our application security program across a multi-cloud environment. In this role, you'll serve as a senior individual contributor responsible for driving secure application architecture, integrating security into the software development lifecycle, and partnering closely with engineering teams to identify and remediate security risks. You'll play a key role in securing modern cloud-native applications, supporting AI initiatives, and advancing our overall security posture.
This position is based out of RXO headquarters located at 11215 N Community House Road, Charlotte, NC 28277 and follows a four-day onsite work schedule Monday through Thursday, with remote work on Fridays.
What your day-to-day will look like:
Lead the development and governance of application security standards, secure architecture principles, and threat modeling practices across the enterprise.
Conduct security assessments and threat modeling for emerging technologies, including Agentic AI solutions, Large Language Models (LLMs), and autonomous AI workflows.
Analyze and tune Web Application Firewall (WAF) configurations, including reviewing F5 and Akamai logs, investigating anomalies, and implementing approved rule exceptions.
Integrate and optimize automated security tools, including SAST, DAST, and Software Composition Analysis (SCA), within CI/CD pipelines and DevSecOps processes.
Partner with software engineering teams to identify vulnerabilities and provide code-level remediation guidance aligned with secure coding best practices.
Lead and support security awareness initiatives, including mentoring developers and facilitating Security Champion programs across engineering teams.
Perform application security reviews and contribute to risk identification, vulnerability management, remediation tracking, and reporting efforts.
Evaluate cloud-native applications and services across Azure, Google Cloud Platform (GCP), and Oracle Cloud Infrastructure (OCI) environments to ensure adherence to security standards.
Support the implementation of security controls within development pipelines, including mechanisms to prevent deployments with unresolved critical or high-risk vulnerabilities.
Drive continuous improvement initiatives to enhance application security processes, tooling, and developer enablement.
At a minimum, you'll need:
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or equivalent combination of education and experience.
3+ years of experience in Application Security, Security Engineering, DevSecOps, or a related cybersecurity discipline.
Experience identifying and remediating security vulnerabilities within application code and software development environments.
Experience working with enterprise WAF platforms such as Akamai App & API Protector, F5 Advanced WAF, or similar technologies.
Experience securing cloud-native workloads and applications within Azure, GCP, and/or OCI environments.
Experience with container technologies, including Docker and Kubernetes.
Experience integrating security tools into CI/CD pipelines and development workflows.
Knowledge of OWASP Top 10, Common Weakness Enumeration (CWE), secure API design principles, and application security best practices.
Strong analytical, problem-solving, and communication skills with the ability to collaborate across technical teams.
It'd be great if you also have:
Experience securing AI-enabled applications, LLM-based solutions, or autonomous agent workflows.
Experience reviewing and securing Infrastructure as Code (IaC) technologies such as Terraform, Ansible, or Bicep.
Microsoft Certified: Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, CISSP, CSSLP, CASE, GWEB, or related security certifications.
Experience with Akamai and/or F5 security platforms in large-scale enterprise environments.
Experience leading Security Champion programs or mentoring engineering teams on secure development practices.
Ability to influence cross-functional teams and drive security improvements through collaboration and technical expertise.
Experience developing scalable security frameworks that support innovation while managing enterprise risk.
Does this sound like you? Check out what else RXO has to offer.
Why Join Us:
Our Benefits
Comprehensive medical, dental, and vision plans
401(k) retirement plan with up to 5% company match
Pre-tax accounts to help streamline eligible expenses
Company-paid disability and life insurance
Employee Assistance Program (EAP)
Career and Leadership Development Programs
Paid time off, company holidays, and volunteer days
Our Culture
Our values are the key to our unique culture and our ability to deliver for everyone we serve.
We do great things when we are inclusive and work together. To perform with excellence, we learn from one another, value diverse perspectives, operate safely and build strong relationships.
The Next Step
Ready to join our team? We'd love to hear from you. Fill out an application now and join our talent community to learn about future opportunities. We are proud to be an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. All applicants who receive a conditional offer of employment may be required to take and pass a pre-employment drug test. The above statements are not an exhaustive list of all required responsibilities, duties, and skills for this job classification. Review RXO's candidate privacy statement here and RXO's Privacy Notice to California Job Applicants here.