← Back to jobs

Technocraft Solutions Logo
IT Security Engineer

Technocraft Solutions

 

New York City, NY, USA

Posted On: 3 days ago
Experience: Not specified years
Availability: Onsite
Openings: 1
Category: IT Security Engineer
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

 NON-NEGOTIABLES
1. Threat Modeling
• Understanding of architectural trust boundaries, attack surfaces, and data flows.
• Familiarity with structured threat modeling frameworks (e.g., STRIDE, PASTA).
2. Triage & Policy Management
• Working knowledge of common vulnerability classifications (CWE, CVE, OWASP Top 10).
• Ability to interpret vulnerability scoring matrices and map findings to strict remediation SLAs.
3. Vulnerability Reproduction
• Proficiency in reading and writing code in at least two core languages (C++, Go, Java, Python).
• Ability to set up local test harnesses, mock dependencies, and build minimal PoCs.
4. Automated / Agentic Fixer QA
• High attention to detail during code reviews (spotting hallucinations, regressions, off-by-one
errors).
• Understanding of secure coding standards (input validation, boundary checking, safe memory
access).
NICE-TO-HAVES
• Experience conducting threat model reviews for large distributed / microservice systems.
• Ability to translate abstract system designs into concrete threat scenarios.
• Experience managing vulnerability queues and reviewing compliance exception requests.
• Familiarity with automated static/dynamic scanning tools.
• Practical experience with fuzz testing, unit test frameworks, and sandbox execution.
• Debugging complex runtime or logic errors across service boundaries.
• Experience debugging and prompt-tuning automated code generation tools.
• Familiarity with automated patch validation and differential testing.
POSITION OVERVIEW
• The Security Engineer will join an operational security pod acting as the crucial bridge
between automated security scanning/remediation systems and product code owners. The
mission of this role is to streamline threat modeling, eliminate triage noise, validate
exploitability through reproduction, verify automated/agentic patches, and shepherd open
security issues through to verified production resolution.
DAY-TO-DAY RESPONSIBILITIES
• Document trust boundaries, data flows, and architectural entry points to maintain up-todate
threat profiles for high-priority services.
• Filter and triage findings from automated source and endpoint scanners, classifying
severity and evaluating exception requests.
• Construct minimal test environments and reproduction harnesses to validate exploitability
and eliminate false positives.
• Supervise and QA code patches generated by automated/agentic remediation tools,
running unit and integration tests to check for regressions.
• Route validated patches to product team code owners and coordinate end-to-end
deployment verification within strict SLAs.
• Conduct code reviews and ensure all fixes comply with secure coding standards (e.g.,
input validation, memory safety).
REQUIRED SKILLS
1. Threat Modeling
• Understanding of architectural trust boundaries, attack surfaces, and data flows.
• Familiarity with structured threat modeling frameworks (e.g., STRIDE, PASTA).
2. Triage & Policy Management
• Working knowledge of common vulnerability classifications (CWE, CVE, OWASP Top 10).
• Ability to interpret vulnerability scoring matrices and map findings to strict remediation SLAs.
3. Vulnerability Reproduction
• Proficiency in reading and writing code in at least two core languages (C++, Go, Java, Python).
• Ability to set up local test harnesses, mock dependencies, and build minimal PoCs.
4. Automated / Agentic Fixer QA
• High attention to detail during code reviews (spotting hallucinations, regressions, off-by-one
errors).
• Understanding of secure coding standards (input validation, boundary checking, safe memory
access).
NICE-TO-HAVES
• Experience conducting threat model reviews for large distributed / microservice systems.
• Ability to translate abstract system designs into concrete threat scenarios.
• Experience managing vulnerability queues and reviewing compliance exception requests.
• Familiarity with automated static/dynamic scanning tools.
• Practical experience with fuzz testing, unit test frameworks, and sandbox execution.
• Debugging complex runtime or logic errors across service boundaries.
• Experience debugging and prompt-tuning automated code generation tools.
CANDIDATE PROFILE
An operational, hands-on Security Engineer with a strong software development background who excels at bridge-building between security automation and product development teams. The candidate should be highly methodical, possessing strong code analysis skills to spot hallucinated or regression-prone automated fixes and validate real-world exploitability.
Job Responsibilities
•
Map trust boundaries, data flows, and architectural entry points to maintain standardized threat profiles.
•
Triage findings from automated static and endpoint security scanners, classifying severity and managing exceptions.
•
Build minimal reproduction harnesses and test environments to confirm exploitability and eliminate false positives.
•
Review, test, and QA automated code patches generated by AI/agentic remediation engines, preventing regressions and ensuring compliance with secure coding standards

Education

Not specified

Related Jobs

No related jobs found

← Back to jobs