1 day ago
Base Salary
$130k - $150k/yr
Responsibilities
- Lead development and governance of application security standards, secure architecture principles, and threat-modeling practices.
- Conduct security assessments and threat modeling for Agentic AI, LLM, and autonomous AI workflows.
- Analyze and tune WAF configurations, review F5 and Akamai logs, investigate anomalies, and implement approved rule exceptions.
- Integrate and optimize SAST, DAST, and SCA tools within development pipelines and DevSecOps processes.
- Partner with software engineering teams on vulnerability identification, code-level remediation, application security reviews, and secure coding practices.
- Lead security awareness and Security Champion initiatives, including mentoring developers and engineering teams.
- Evaluate cloud-native applications across Azure, GCP, and OCI and support controls that prevent deployment of unresolved critical or high-risk vulnerabilities.
- Drive vulnerability management, remediation tracking, reporting, developer enablement, and continuous application security improvements.
Requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field, or an equivalent combination of education and experience.
- At least 3 years of experience in Application Security, Security Engineering, DevSecOps, or a related cybersecurity discipline.
- Experience identifying and remediating vulnerabilities in application code and software development environments.
- Experience with enterprise WAF platforms such as Akamai App & API Protector, F5 Advanced WAF, or similar technologies.
- Experience securing cloud-native workloads in Azure, GCP, and/or OCI environments.
- Experience with Docker, Kubernetes, security-tool integration, and development workflows.
- Knowledge of OWASP Top 10, CWE, secure API design, and application security best practices.
- Preferred experience includes securing AI-enabled or LLM-based applications, autonomous agent workflows, and IaC using Terraform, Ansible, or Bicep.
- Preferred certifications include Microsoft Certified: Azure Security Engineer Associate, GCP Professional Cloud Security Engineer, CISSP, CSSLP, CASE, or GWEB.
- Preferred experience includes Akamai or F5 enterprise environments, Security Champion programs, mentoring, and scalable security framework development.
Benefits
- Competitive pay, paid time off, holidays, floating Diversity Days, bereavement leave, volunteer time, jury duty leave, family bonding leave, and prenatal care leave.
- 401(k) retirement plan with up to 5% company match.
- Health, prescription, dental, vision, life, disability, accidental death, business travel, legal services, identity theft, accident, critical illness, and hospital indemnity insurance.
- Employee Assistance Program, tuition reimbursement, adoption assistance, and tax-advantaged health, dependent care, and commuter accounts.
- Based in Charlotte, NC or Chicago, IL, with onsite work Monday through Thursday and remote work on Fridays.
- Employment may require passing a pre-employment drug test after a conditional offer.
Tech Stack
Categories
About RXO, Inc.
RXO, Inc. is an asset-light transportation and logistics provider that brokers truckload capacity and offers managed transportation for shippers across North America. The company operates a digital freight marketplace and TMS integrations connecting customers with a large network of third-party carriers; it was spun off from XPO Logistics in 2022 and is headquartered in Charlotte, North Carolina. RXO is a publicly traded company on the NYSE.