Senior Security Engineer

Mach7 Technologies - Burlington, VT

Hiring: Senior Security Engineer Company: Mach7 Technologies Location: Burlington, VT Job Posted Time: 2026-09-16 14:29:33 Employment Type: Remote Target Skills & Keywords : AWS, Azure, C, C++, CI/CD, DAST, Embedded Systems, GCP, GitHub Actions, Jenkins, Kubernetes, Microservices, OWASP, Python, Risk Management, Root Cause Analysis, SAST, SBOM, SCA, SOC 2, Snyk, TypeScript About the job Experience: •5+ years of experience in security engineering, with a strong AppSec focus Required Skills: •A critical part of this role is developing and maintaining a deep understanding of our product attack surface, how components interact, what's exposed, and where real risk lives. That understanding is what transforms security tooling output into prioritized, meaningful action across threat modeling, vulnerability management, and supply chain risk. •This is a high-impact role for someone who is equally comfortable reading source code, threat modeling a new microservice, and coaching a developer through a secure code review. •Own and evolve the AppSec program across the entire SDLC — from design reviews to post-deployment monitoring — for web, API, mobile, and shipped product deliverables •Build and maintain a living model of the product attack surface — mapping trust boundaries, data flows, exposed interfaces, and high-value targets — and use it to drive prioritization across all security workstreams •Conduct threat modeling and architecture security reviews for new features, services, and product releases across all delivery channels •Perform manual and automated secure code reviews across multiple languages (e.g. Python, Go, TypeScript, C/C++) •Integrate and tune SAST, DAST, and SCA tooling within CI/CD pipelines (GitHub Actions, Jenkins, or equivalent) •Triage and drive remediation of vulnerabilities surfaced through scanning, bug bounty, and pen tests Qualifications: •Operational familiarity with software supply chain frameworks such as SLSA, NIST SSDF, or OpenSSF Scorecards •Contributions to open-source security tooling or security research •Relevant certifications: OSCP, CSSLP, GWEB, or similar •We recognize that candidates bring diverse experiences and backgrounds. If you don’t meet every requirement, we still encourage you to apply! Many strong candidates don’t check every box. We value potential, growth, and impact as much as experience. •Skilled at threat modeling, secure code reviews, and identifying real-world risks across complex systems. •Knowledgeable in web, API, mobile, and software supply chain security best practices. •Comfortable working with developers to embed security throughout the SDLC. •Proficient with security testing and vulnerability management tools, including SAST, DAST, and SCA solutions. •Strong communicator who can translate technical risks into actionable recommendations. •Collaborative, proactive, and driven to improve both product security and engineering security culture. Compensation: •Flexible work environment (work from home / hybrid options) Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!