The Cybersecurity Engineer is responsible for the security of software applications, IT systems, and ensuring security best practices throughout Business Wire. This role involves assessing, identifying, and mitigating vulnerabilities in web applications, cloud, and IT systems. This position works closely with development teams to integrate security best practices during the software development process, from design to deployment. The is position works to educate technical and non-technical personnel about threats such as library exploits, phishing attacks, and social engineering. The Cybersecurity Engineer is responsible for ensuring the proper implementation and usage of security tools including vulnerability scanning, email security, and logging.
What You Will Do
- Assist in conducting application and cloud security assessments to identify potential risks and vulnerabilities.
- Collaborate with security and development teams to integrate security testing into the SDLC and support vulnerability management efforts.
- Support the development of cloud security architecture, ensuring it aligns with industry standards and best practices.
- Assist in triaging vulnerabilities and be engaged in engineering prioritization of findings.
- Conduct security assessments and assist in threat modeling exercises, contributing to the identification of potential security risks.
- Assist in vulnerability management by helping with penetration testing, remediation efforts, and security controls implementation.
- Help maintain security documentation and reports to ensure security requirements are followed during product development.
- Support incident response activities, assisting in investigating and resolving application security incidents.
- Collaborate with cross-functional teams to promote security awareness and follow established security best practices.
- Conduct educational exercises on security best practices, phishing, and social engineering.
- Support the continuous improvement of security tools, dashboards, and other resources for monitoring and improving product security.
What You Will Need
- 2 – 4 years of experience in application security with knowledge of AWS.
- Hands-on experience in designing secure Infrastructure solutions for AWS as well as on-prem applications, demonstrating proficiency in architecting robust and scalable security measures within cloud and on-prem environments.
- Understanding of security testing tools such as GitHub Advanced Security to encompass Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST), utilizing these tools effectively to identify and address potential vulnerabilities proactively.
- Experience in training and providing educational materials to increase security maturity.
- Experience in application security automation and interjecting security into CICD.
- Expertise in technical assessments, threat modeling, and cloud security architecture.
- Knowledge software security best practices, penetration testing, vulnerability management, and remediation advisory.
- Demonstrated proficiency in investigating and effectively managing security incidents pertaining to applications operating within AWS and on-prem environments.
- Strong problem-solving abilities and a deep understanding of cybersecurity principles and practices.
- The ability to communicate complex security concepts to technical and non-technical stakeholders.
- Previous software development experience is plus.
- Bachelor’s degree in computer science or related field.
What We Offer
- Ability to work remotely
- Excellent health benefits that begin on your first day of employment
- $100 monthly fitness allotment, a tuition reimbursement program, and enhanced mental health resources
- 401(k) plan with generous company match, and annual profit sharing contribution (subject to company performance)
- PTO, Floating Holidays, Wellness Day Off, Birthday Day Off, and more!
The base salary range for this position is $150K to $155K/year. Offered salary will be determined by several factors, including but not limited to: applicant’s education, experience, knowledge, skills and abilities, as well as internal equity and alignment with geographic market data. Business Wire reserves the right to modify this salary range at any time. Offered candidate must pass a background check.
Business Wire’s total rewards include:
Skills Required
- 2–4 years of experience in application security
- Knowledge of AWS
- Experience designing secure infrastructure solutions for AWS and on-premises applications
- Experience with GitHub Advanced Security, SAST, and DAST
- Experience training personnel and creating educational security materials
- Experience with application security automation and integrating security into CI/CD
- Expertise in technical assessments, threat modeling, and cloud security architecture
- Knowledge of software security best practices, penetration testing, vulnerability management, and remediation advisory
- Experience investigating and managing application security incidents in AWS and on-premises environments
- Strong problem-solving abilities and understanding of cybersecurity principles and practices
- Ability to communicate complex security concepts to technical and non-technical stakeholders
- Previous software development experience
- Bachelor’s degree in computer science or a related field
- Must pass a background check
What We Do
Business Wire, a wholly owned subsidiary of Berkshire Hathaway, is the global market leader in commercial news distribution. Thousands of member companies and organizations depend on Business Wire to transmit their full-text news releases, regulatory filings, photos and other multimedia content to journalists, financial professionals, investor services, regulatory authorities and the general public worldwide. Connect with us on Twitter, Facebook and Instagram at: @BusinessWire









