Transamerica

Intermediate Cyber Security Engineer

Transamerica
Apply
25 days ago
Philadelphia, PA, USA or Denver, CO, USAEntry Level / Mid Level

Base Salary

$70k - $84k/yr

Responsibilities

  • Identify weaknesses and vulnerabilities and support application of security frameworks and regulatory standards such as NIST CSF.
  • Gather and analyze data and create reports, dashboards, key indicators, and project materials.
  • Review security vulnerabilities across on-premise and cloud infrastructure.
  • Support administrative, technical, and physical safeguards protecting company information and technology services.
  • Assist with secure SDLC practices, static and dynamic application security testing, vulnerability validation, remediation tracking, and application risk reduction.
  • Research, develop, and implement information security policy, process, procedural, and technology improvements.
  • Enhance and automate the vulnerability management lifecycle, including intake, prioritization, tracking, reporting, and continuous improvement.
  • Promote secure coding and provide guidance on secure SDLC requirements, vulnerability testing, remediation, and application data handling.
  • Collaborate with business partners, legal, internal audit, risk, technology specialists, development teams, and other stakeholders.

Requirements

  • Bachelor’s degree emphasizing Computer Science, MIS, Auditing, Finance, or Business, or equivalent education and experience.
  • One to three years of cybersecurity engineering experience is required.
  • Two to three years of related application security experience is stated in the qualifications.
  • Experience in application security domains such as secure coding, SDLC security, threat modeling, SAST, DAST, software composition analysis, API security, WAF, container security, vulnerability remediation, and application data protection.
  • Knowledge of control frameworks such as NIST CSF.
  • Foundation in security technologies and controls including SIEM, endpoint security, firewalls, intrusion detection and prevention, data loss prevention, vulnerability scanning, threat intelligence, digital forensics, and application allowlisting.
  • Working knowledge of vulnerability-management systems such as Rapid7, ServiceNow Vulnerability Response, Snyk, or CrowdStrike.
  • Hands-on experience with application security, dynamic scanning, static scanning, and container security.
  • Experience with ServiceNow, JIRA, or an equivalent system.
  • Ability to fluently read, write, and speak English and create automated vulnerability reports and dashboards.
  • Preferred qualifications include OSCP, CISSP, CEH, CompTIA Security+, CySA, or CASP+ certifications and experience in insurance, financial services, or fintech.

Benefits

  • Hybrid work requiring three days in the office weekly in Denver or Cedar Rapids; occasional and potentially international travel may be required.
  • Competitive pay, an annual bonus opportunity, pension plan, 401(k) match, employee stock purchase plan, and tuition reimbursement.
  • Medical, dental, vision, disability insurance, employee discounts, and employee assistance resources.
  • Paid time off starting at 160 hours annually in the first year and ten paid holidays annually.
  • Wellness coaching and reward dollars, parental leave, adoption assistance, backup care, and volunteer PTO.
  • Career training and development, employee resource groups, inclusion programs, recognition programs, referral bonuses, and matching gifts.

Categories

Transamerica

About Transamerica

10,000+ employees
Contact me