Logo for Seyfarth Shaw LLP

Security Engineer

Role overview

Qualifications

  • At least three years of experience in cybersecurity, security engineering, application security, vulnerability management, penetration testing, security operations, or a related technical information technology role.
  • Strong understanding of common vulnerabilities, attack techniques, and ways attackers compromise applications, endpoints, identities, cloud services, and enterprise environments.
  • Familiarity with offensive security and penetration testing methodologies.
  • Strong analytical and troubleshooting skills with attention to technical detail.

Responsibilities

  • Perform technical security assessments of software applications, SaaS platforms, browser extensions, integrations, and other technologies proposed for use within the Firm.
  • Evaluate application architecture, permissions, data access, administrative controls, authentication methods, and security configuration.
  • Assess how compromised or malicious applications could be leveraged as an attack vector.
  • Review existing deployed applications to determine business need, usage, software versions, support status, known vulnerabilities, available updates, and potential security exposure.

Key facts

Hard skills

Other skills

  • Communication
  • Analytical Skills
  • Troubleshooting (Problem Solving)
  • Detail Oriented
  • Teamwork

About the company

Seyfarth Shaw LLP logo

Seyfarth Shaw LLP

Legal Services

High stakes. High volume. High impact. Our high-caliber legal representation and advanced delivery capabilities allow us to take on our clients’ unique challenges and opportunities―no matter the scale or complexity. Whether navigating complex litigation, negotiating transformational deals, or advising on cross-border projects, our attorneys achieve exceptional legal outcomes. Our drive for excellence leads us to seek out better ways to work with our clients and each other. We have been first-to-market on many legal service delivery innovations―and we continue to break new ground with our clients every day. This long history of excellence and innovation has created a culture with a sense of purpose and belonging for all. In turn, our culture drives our commitment to the growth of our clients, the diversity of our people, and the resilience of our workforce. *Our London office operates as Seyfarth Shaw (UK) LLP, an affiliate of Seyfarth Shaw LLP. Our Australian practice operates as Seyfarth Shaw Australia, an Australian multidisciplinary partnership affiliated with Seyfarth Shaw LLP. For more information please visit www.seyfarth.com.

Company details

Company typeSME
IndustryLegal Services
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Why Seyfarth:

At Seyfarth, we understand that great people are the key to our success, and we provide the opportunities to match. If you join us, you’ll work with state-of-the-art technology in a friendly and professional environment, and we will continue to invest in your professional development. If you want the freedom to grow at a firm that is invested in your future, keep reading.

The Opportunity:

As a Security Engineer – Application Security & Technology Risk, you will help evaluate and protect the Firm's technology environment by assessing the security risks associated with applications, SaaS platforms, browser extensions, integrations, and other technologies proposed for use within the Firm.

A significant part of this role will involve understanding how a technology works, the access and permissions it requires, the data it can access or process, how it integrates with the Firm's environment, and how it could potentially be abused or compromised. You will evaluate these technologies from both a defensive and adversarial perspective, considering vulnerabilities, software supply-chain risk, authentication and authorization controls, configuration weaknesses, and the ways an attacker could leverage a compromised application or integration.

The successful candidate will combine strong technical security knowledge with the ability to translate security findings into practical, risk-based recommendations for application owners, IT teams, and Firm leadership.

The Day-To-Day:

On any given day, you will work with Security, IT, application owners, project teams, vendors, and other stakeholders on a variety of technology assessments and security initiatives. You will:

  • Perform technical security assessments of software applications, SaaS platforms, browser extensions, integrations, AI-enabled technologies, and other technologies proposed for use within the Firm.
  • Evaluate application architecture, permissions, data access, administrative controls, authentication methods, APIs, OAuth integrations, third-party dependencies, logging capabilities, and security configuration.
  • Assess how compromised or malicious applications could be leveraged as an attack vector, including credential theft, data exposure, persistence, privilege escalation, lateral movement, command and control, and software supply-chain compromise.
  • Review vendor and application security documentation, vulnerability information, threat intelligence, software dependencies, and publicly available security research to identify potential risks.
  • Evaluate authentication and authorization configurations including SSO, SAML, OAuth/OIDC, MFA, Microsoft Entra ID integrations, Conditional Access policies, service principals, application registrations, API permissions, and privileged access requirements.
  • Work with infrastructure, endpoint, cloud, identity, networking, and application teams to identify security design or configuration gaps and recommend practical remediation or compensating controls.
  • Review existing deployed applications to determine business need, usage, software versions, support status, known vulnerabilities, available updates, and potential security exposure.
  • Assist with application inventory and software lifecycle initiatives designed to identify unnecessary, obsolete, vulnerable, or unauthorized applications within the environment.
  • Validate approved application deployments to confirm that software, security controls, permissions, integrations, and configurations were implemented according to approved requirements.
  • Use vulnerability management, endpoint security, SIEM, identity, network, asset discovery, and other security telemetry to understand application behavior and identify potential security concerns.
  • Support Security Operations with threat hunting, security investigations, incident response, and other operational security activities as needed.
  • Clearly document findings, risk, technical impact, and recommended controls for both technical and non-technical audiences.
  • Exercise independent judgment, curiosity, and initiative when investigating unfamiliar technologies and security risks.
You Have:
  • At least three years of experience in cybersecurity, security engineering, application security, vulnerability management, penetration testing, security operations, or a related technical information technology role.
  • Strong understanding of common vulnerabilities, attack techniques, and the ways attackers compromise applications, endpoints, identities, cloud services, and enterprise environments.
  • Strong understanding of software supply-chain risk, including compromised software updates, malicious dependencies, third-party libraries, browser extensions, package repositories, software signing, and vendor compromise.
  • Familiarity with offensive security and penetration testing methodologies and the ability to apply an attacker mindset when evaluating new technologies.
  • Experience evaluating applications or SaaS platforms from a security perspective, including permissions, architecture, integrations, authentication, authorization, data access, and administrative controls.
  • Working knowledge of modern identity and authentication technologies including SSO, SAML, OAuth 2.0, OpenID Connect, MFA, Microsoft Entra ID, enterprise application registrations, and Conditional Access.
  • Understanding of Windows and cloud security concepts, endpoint security controls, networking, APIs, and common enterprise application deployment models.
  • Experience working with security technologies such as vulnerability scanners, endpoint detection and response platforms, SIEM platforms, identity security tools, network security platforms, or application security testing tools.
  • Familiarity with tools such as Qualys, CrowdStrike Falcon, Microsoft Sentinel, Microsoft Entra ID, Burp Suite, or comparable security platforms is preferred.
  • Ability to research unfamiliar technologies, understand how they operate, identify meaningful security concerns, and distinguish theoretical risk from realistic enterprise risk.
  • Strong analytical and troubleshooting skills with attention to technical detail.
  • Ability to communicate security findings clearly and work collaboratively with technical teams, application owners, vendors, and business stakeholders.
  • Scripting, API, or automation experience with PowerShell, Python, or similar technologies is preferred.
  • A strong desire to continuously learn about emerging technologies, vulnerabilities, attack techniques, and changes in the cyber threat landscape.
What We Provide:

Seyfarth provides competitive salary and benefits at all levels, and our culture embraces the entrepreneurial spirit of its professionals like no other firm. Our professional staff are a collaborative team, helping to define the unique client experience offered by the firm. We understand that it takes more than attorneys to build a successful legal practice; everyone participates in our commitment to excellence.

More About Seyfarth:

With approximately 1,000 lawyers across 19 offices, Seyfarth Shaw LLP provides advisory, litigation, and transactional legal services to clients worldwide. Learn more about The Seyfarth Experience at www.seyfarth.com/careers/.

Seyfarth Shaw is committed to equal employment opportunity and providing reasonable accommodations to applicants with physical and/or mental disabilities. We value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation, physical or mental disability, medical condition, military and veteran status, gender identity or expression, genetic information, change of sex or transgender status, genetic information or any other basis protected by federal, state or local law.

If you would like more information about your EEO rights as an applicant under the law, please click EEO is the LAW and the Supplement poster through the following link: https://www.eeoc.gov/sites/default/files/migrated_files/employers/poster_screen_reader_optimized.pdf

Location Specific Language:

The salary range for this role is $118,000 to $135,000 annually, which is based on a 40 hour work week. This range is only applicable for jobs to be performed in Chicago. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee’s pay within the salary range will be based on numerous factors including, but not limited to, relevant education, qualifications, experience, skills, and business or organizational needs. This job is also eligible for an annual merit increase and bonus pay. 

We offer a comprehensive package of benefits including paid time off, medical/dental/vision insurance, and 401(k).

#LI-Remote

This position is based in Atlanta, GA 30309

This position is based in Charlotte, NC 28202

This position is based in Chicago, IL 60606

This position is based in Dallas, TX 75201

This position is based in Houston, TX 77002

This position is based in Miami, FL 33131

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Seyfarth Shaw LLP

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.