← Back to jobs

Intime Infotech Inc Logo
Sr Security Engineer

Intime Infotech Inc

 

San Francisco, CA, USA

Posted On: 7 days ago
Experience: 5+ years
Availability: Onsite
Openings: 1
Category: Sr Security Engineer
Tenure: Contract - Corp-to-Corp
Related Jobs

No related jobs found

Description

 

DAY-TO-DAY RESPONSIBILITIES

  • Document trust boundaries, data flows, and architectural entry points to maintain up-to-date threat profiles for high-priority services.
  • Filter and triage findings from automated source and endpoint scanners, classifying severity and evaluating exception requests.
  • Construct minimal test environments and reproduction harnesses to validate exploitability and eliminate false positives.
  • Supervise and QA code patches generated by automated/agentic remediation tools, running unit and integration tests to check for regressions.
  • Route validated patches to product team code owners and coordinate end-to-end deployment verification within strict SLAs.
  • Conduct code reviews and ensure all fixes comply with secure coding standards (e.g., input validation, memory safety).

REQUIRED SKILLS

1. Threat Modeling

• Understanding of architectural trust boundaries, attack surfaces, and data flows.

• Familiarity with structured threat modeling frameworks (e.g., STRIDE, PASTA).

 

2. Triage & Policy Management

• Working knowledge of common vulnerability classifications (CWE, CVE, OWASP Top 10).

• Ability to interpret vulnerability scoring matrices and map findings to strict remediation SLAs.

 

3. Vulnerability Reproduction

• Proficiency in reading and writing code in at least two core languages (C++, Go, Java, Python).

• Ability to set up local test harnesses, mock dependencies, and build minimal PoCs.

 

4. Automated / Agentic Fixer QA

• High attention to detail during code reviews (spotting hallucinations, regressions, off-by-one errors).

• Understanding of secure coding standards (input validation, boundary checking, safe memory access).

 

NICE-TO-HAVES

• Experience conducting threat model reviews for large distributed / microservice systems.

• Ability to translate abstract system designs into concrete threat scenarios.

• Experience managing vulnerability queues and reviewing compliance exception requests.

• Familiarity with automated static/dynamic scanning tools.

• Practical experience with fuzz testing, unit test frameworks, and sandbox execution.

• Debugging complex runtime or logic errors across service boundaries.

• Experience debugging and prompt-tuning automated code generation tools.

 

Education

Bachelor's degree

Related Jobs

No related jobs found

← Back to jobs