Security Engineer

Posted 2 Days Ago
2 Locations
Remote
Senior level
Information Technology • Software • Consulting
The Role
The Application Security Engineer will define and validate security controls for a high-traffic digital news platform. Responsibilities include threat modeling, architecture reviews, authentication and authorization assessment, API and integration security, secrets management, vulnerability and penetration testing coordination, encryption validation, security monitoring, GDPR privacy engineering, vendor assessments, and remediation documentation.
Summary Generated by Built In

Solvd Inc. is a rapidly growing AI-native consulting and technology services firm delivering enterprise transformation across cloud, data, software engineering, and artificial intelligence. We work with industry-leading organizations to design, build, and operationalize technology solutions that drive measurable business outcomes.

Following the acquisition of Tooploox, a premier AI and product development company, Solvd now offers true end-to-end delivery—from strategic advisory and solution design to custom AI development and enterprise-scale implementation. Our capability centers combine deep technical expertise, proven delivery methodologies, and sector-specific knowledge to address complex business challenges quickly and effectively.

We are looking for an Application Security Engineer to join a greenfield digital news platform build for a major international news brand. Security is not a pre-launch checklist here — it is an engineering requirement embedded across every phase of delivery, from architecture through launch and into multi-year support.

You'll be the security authority on a full-lifecycle engagement, validating controls across a composable CMS, video pipeline, advertising integrations, personalisation services, and public-facing APIs — on a platform designed to sustain extreme traffic during breaking-news events.


What you'll do
  • Define and validate application and platform security controls across all delivery phases.

  • Perform architecture and threat-model reviews at design stage and as the platform evolves.

  • Review authentication, authorization, and privileged-access controls across CMS, APIs, and integrated services.

  • Validate API and integration security across a composable, multi-vendor platform architecture.

  • Review secrets, credentials, and token-management practices across the full stack.

  • Support vulnerability scanning and penetration-testing activities — coordinating findings and remediation.

  • Validate encryption and secure data handling across storage, transit, and third-party integrations.

  • Review security logging, monitoring, and incident-response requirements.

  • Support GDPR and privacy engineering requirements throughout delivery.

  • Conduct third-party security assessments for integrated services and vendors.

  • Provide remediation guidance and produce security acceptance evidence ahead of launch.

Basic qualifications
  • 5+ years of experience in application security, security engineering, or a closely related role.

  • Experience performing threat modelling and architecture security reviews on complex, multi-component platforms.

  • Strong knowledge of authentication and authorization patterns — OAuth, OIDC, RBAC, privileged access management.

  • Hands-on experience validating API security and reviewing integration patterns across third-party services.

  • Solid understanding of secrets management, credential handling, and token lifecycle best practices.

  • Experience supporting or coordinating vulnerability scanning and penetration testing programmes.

  • Knowledge of encryption standards and secure data handling practices across storage and transit.

  • Familiarity with GDPR and privacy-by-design engineering requirements.

  • Ability to produce clear remediation guidance and security acceptance documentation for engineering and delivery teams.

Preferred qualifications
  • Experience securing composable CMS or media platform architectures — AEM, Amplience, or similar.

  • Background working on high-traffic, public-facing platforms where availability and security intersect.

  • Experience with security logging and monitoring tooling — SIEM, alerting, incident response playbooks.

  • Familiarity with third-party vendor security assessment processes.

  • Relevant certification — CISSP, OSCP, CEH, or equivalent.

  • Experience working within a phased, full-lifecycle delivery programme alongside engineering and architecture teams.

When you join Solvd, you'll…

  • Shape real-world AI-driven projects across key industries, working with clients from startup innovation to enterprise transformation.

  • Be part of a global team with equal opportunities for collaboration across continents and cultures.

  • Thrive in an inclusive environment that prioritizes continuous learning, innovation, and ethical AI standards.

Ready to make an impact?

If you're excited to build things that matter, champion responsible AI, and grow with some of the industry’s sharpest minds. Apply today and let’s innovate together.

Solvd is an equal opportunity employer.

Skills Required

  • 5+ years of experience in application security, security engineering, or a closely related role
  • Experience performing threat modeling and architecture security reviews on complex, multi-component platforms
  • Strong knowledge of authentication and authorization patterns, including OAuth, OIDC, RBAC, and privileged access management
  • Hands-on experience validating API security and reviewing third-party integration patterns
  • Understanding of secrets management, credential handling, and token lifecycle best practices
  • Experience supporting or coordinating vulnerability scanning and penetration testing programs
  • Knowledge of encryption standards and secure data handling across storage and transit
  • Familiarity with GDPR and privacy-by-design engineering requirements
  • Ability to produce remediation guidance and security acceptance documentation
  • Experience securing composable CMS or media platform architectures such as AEM or Amplience
  • Experience with high-traffic, public-facing platforms where availability and security intersect
  • Experience with security logging and monitoring tools, SIEM, alerting, and incident-response playbooks
  • Familiarity with third-party vendor security assessment processes
  • CISSP, OSCP, CEH, or equivalent certification
  • Experience working in phased, full-lifecycle delivery programs with engineering and architecture teams
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Saratoga Springs, UT
708 Employees
Year Founded: 2011

What We Do

Solvd is an end-to-end software engineering and consulting company with over 800 employees located across eight countries in Latin America, North America, and Europe. The company is headquartered in California and has 7 development centers in Ukraine, Poland, Georgia, Argentina, Brazil, and Mexico, as well as a sales office in Hungary. Solvd is partnering with leading technology companies such as Amazon and Adobe. It delivers exceptional engineering and digital solutions to Fortune 500 clients across high-growth industries including financial services, retail & e-commerce, healthcare & life sciences, social media, software & Hi-Tech, etc. The services list covers all aspects and needs of modern businesses, including software product development, digital experience and design, DevOps and cloud, data, and AI/ML services. Moreover, Solvd transformed its deep expertise in QA into a rich intellectual property library, which includes Zebrunner, an innovative proprietary quality management platform. To get more information about Solvd and Zebrunner, please visit https://www.solvd.com and https://zebrunner.com.

Similar Jobs

Pencil Logo Pencil

Security Engineer

Artificial Intelligence
Remote
27 Locations
23 Employees

Varonis Logo Varonis

Security Engineer

Security • Software
In-Office or Remote
Kraków, Małopolskie, POL
1894 Employees

Ciklum Logo Ciklum

Security Engineer

Information Technology • Consulting
Remote
Poland
2995 Employees

OLX Logo OLX

Security Engineer

Marketing Tech • Software
Remote
2 Locations
4321 Employees

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account