Logo for Mindlance

Security Engineer III

Role overview

Qualifications

  • 7 years of experience in software engineering, security engineering, DevSecOps, application security automation, or enterprise platform engineering.
  • 7 years of advanced Python development experience, including architecting and delivering enterprise-grade automation.
  • Hands-on TypeScript or JavaScript experience for automation services.
  • Strong understanding of application security concepts and secure SDLC practices.

Responsibilities

  • Design, develop, enhance, and maintain enterprise security automation capabilities.
  • Build scalable automation services, validators, APIs, and integration components using Python and TypeScript.
  • Work with AWS services and cloud-native architecture patterns to support automation workflows.
  • Collaborate with various teams to translate security intent into scalable automation.

Key facts

Hard skills

Other skills

  • Communication

About the company

Mindlance logo

Mindlance

Staffing & Recruiting

Founded in 1999, Mindlance is one of the largest diversity-owned staffing firms in the US and has been on SIA’s list of Fastest Growing US Staffing Firms for 10 years. Mindlance has also been recognized as one of the consistently best performing partners to industry-leading MSP programs including Allegis, Kelly, TAPFIN, PROUnlimited, Pontoon, GRI, WorkforceLogiq and Agile-1.What started with contingent staffing has developed to a comprehensive portfolio of workforce solutions. Along with industry specific, talent-centric staffing across a range of specializations- Technology, Engineering, Scientific, Clinical Research, Digital, Creative, Marketing, Profession, Mindlance provides Managed Recruitment services- RPO and Direct + Diverse Sourcing, and Pay+ Services- EoR/Payroll, IC Compliance and AoR.Mindlance is also generating alternative talent pipelines that prioritize diversity through three Diverse Talent Acceleration offerings: (1) RebootTalent, a diverse returning talent acceleration service (2) Mindlance Diversphere, a private diverse talent pool aggregated from a network of diversity partnerships and (3) Quintrix Solutions, an upskilling recruit-train-deploy service.With a year-over-year growth rate of 20% and an annual revenue of over $400 million and growing, the Mindlance story is one of calculable achievement, made meaningful by the commitment to grow a mindful way that creates balance in the work and societal ecosystem.Visit www.mindlance.com to learn more about us and our latest job openings.STAFFING INDUSTRY ANALYSTS RECOGNITIONS:Fastest Growing U.S. Staffing Firms (2022, 2021, 2019, 2018, 2017, 2016, 2015, 2014, 2013, 2012, 2011)Largest U.S. Staffing Firms (2022, 2021, 2020, 2019, 2018, 2017, 2016, 2015)Largest Diversity-Owned U.S. Staffing Firms (2022, 2021, 2020, 2019, 2018, 2017, 2016, 2015)Largest IT Staffing Firms (2022, 2021, 2020, 2019, 2018, 2017)Largest Clinical & Scientific Staffing Firms (2022, 2021, 2020, 2019, 2018, 2017)

Company details

Company typeLarge
IndustryStaffing & Recruiting
Company size1001 - 5000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description


The client is seeking a Senior Security Automation Engineer to help design, build, and scale an enterprise security automation platform that improves security control validation, evidence collection, compliance reporting, and integration with secure software development workflows. This role is intended for a hands-on engineer who can build production-quality automation using Python and TypeScript, work effectively with AWS-based infrastructure, understand application security requirements and controls, and use AI technologies daily to improve engineering speed, analysis quality, and automation maturity. The position will support Client Application Security organization by advancing automated, evidence-based security validation across enterprise applications and development pipelines, including AI components that support AI-enabled secure SDLC (AIDLC) capabilities.
Key Responsibilities
Design, develop, enhance, and maintain enterprise security automation capabilities that support security control validation, evidence collection, compliance decisions, and reporting across enterprise applications.
Build scalable automation services, validators, APIs, data processing logic, and integration components using Python and TypeScript.
Work with AWS services and cloud-native architecture patterns to support secure, resilient, and scalable automation workflows, including data ingestion, processing, storage, and integration with enterprise security data sources.
Analyze security requirements, OWASP ASVS controls, secure software development expectations, control objectives, and tool outputs to define practical automation criteria and validation logic.
Develop automation that helps identify missing security evidence, validate secure implementation patterns, support auditability, and improve confidence in application compliance posture.
Integrate security automation capabilities into secure software development workflows, including CI/CD pipelines, developer feedback loops, source code repositories, and enterprise engineering platforms such as Harness or similar tools.
Use AI tools and agentic technologies as part of daily engineering work to accelerate design, coding, analysis, testing, documentation, troubleshooting, and security validation research.
Design and build AI-enabled components, services, and workflow integrations that support AI-enabled secure SDLC (AIDLC) capabilities, including intelligent validation assistance, control mapping support, evidence analysis, and developer security feedback.
Collaborate with Application Security architects, control owners, DevSecOps engineers, cloud teams, platform teams, compliance stakeholders, and application teams to translate security intent into scalable automation.
Produce clear technical documentation, implementation guidance, test evidence, and operational runbooks that allow automation logic to be reviewed, maintained, and scaled across the enterprise.
Required Qualifications
7 years of experience in software engineering, security engineering, DevSecOps, application security automation, or enterprise platform engineering.
7 years of advanced Python development experience, including architecting and delivering enterprise-grade automation, backend services, API integrations, security tooling workflows, and scalable data processing solutions in complex production environments.
Hands-on TypeScript or JavaScript experience, especially for automation services, platform tooling, developer experience workflows, or frontend/backend integration work.
Working knowledge of AWS infrastructure and cloud-native services, with the ability to understand and support secure automation architectures deployed in AWS.
Strong understanding of application security concepts, including SAST, DAST, SCA, secrets scanning, secure coding, API security, vulnerability management, and secure SDLC practices.
Ability to understand security controls and translate high-level requirements into scalable automation solutions, measurable validation logic, auditable evidence collection, and repeatable control-testing
Experience integrating with enterprise systems, APIs, data sources, CI/CD platforms, source code repositories, dashboards, or security tools.
Familiarity with GitHub, GitHub Advanced Security, CodeQL, pull request workflows, and code scanning concepts.
Ability to use AI technologies fluently and responsibly in daily engineering work to improve productivity, quality, analysis, testing, and documentation.
Familiarity with modern AI technologies and practical experience using or building AI-assisted components, workflow automations, or engineering productivity capabilities that can support AI-enabled secure SDLC (AIDLC) use cases.
Strong communication skills with the ability to explain automation design, security logic, implementation assumptions, and limitations to technical and non-technical stakeholders.
Preferred Qualifications
Experience building or supporting compliance automation, control validation, evidence collection, policy-as-code, or audit-readiness platforms.
Experience with OWASP ASVS, NIST 800-53, OWASP Top 10, CWE, secure coding standards, or enterprise security control frameworks.
Experience with Harness, GitHub Actions, Jenkins, or similar CI/CD platforms, including security gate integration, pipeline validation, or developer workflow automation.
Experience developing custom CodeQL queries, security validators, or rule-based detection logic to identify secure or insecure code patterns.
Experience with AI-assisted software development, AI-enabled secure SDLC (AIDLC), AI component development, security agents, prompt engineering, semantic code analysis, or AI-supported compliance validation.
Experience integrating with security tools such as SAST, DAST, SCA, secret scanning, vulnerability management, cloud security, asset discovery, ITSM, SIEM, or enterprise data lake platforms.
Experience with AWS services commonly used for automation and data processing, such as Lambda, S3, IAM, Glue, DynamoDB, API Gateway, CloudWatch, Step Functions, or related services.
Experience designing resilient microservices, event-driven workflows, ETL-style pipelines, or modular automation frameworks.
Background in application security architecture, DevSecOps enablement, cloud security, secure software patterns, or developer platform engineering.
Experience working in aviation, transportation, financial services, healthcare, or another highly regulated enterprise environment.
Ideal Candidate Profile for Sourcing Suppliers
The strongest candidate is a software engineer or platform engineer with security experience, not a traditional security analyst. They should be capable of designing, building, and maintaining enterprise-scale automation systems using Python and modern cloud technologies.
Prioritize candidates who have built internal platforms, automation services, developer tooling, workflow orchestration systems, APIs, or cloud-native applications.
Look for demonstrated proficiency with Python, TypeScript/JavaScript, AWS, APIs, data pipelines, and distributed system integration.
Candidates should understand secure software development practices and be able to translate security requirements and controls into automated validation and enforcement capabilities.
Candidates must be comfortable leveraging AI technologies daily and should ideally have experience building AI-enabled components, agents, workflow automations, or developer productivity solutions.
Strong candidates will have experience integrating capabilities into GitHub, CI/CD pipelines, developer workflows, and engineering platforms such as Harness.
Experience with AI-enabled SDLC (AIDLC), GitHub Advanced Security, CodeQL, security automation, developer platforms, or large-scale enterprise engineering initiatives is high

EEO:

“Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of – Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.”

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Engineer Related jobs

Other jobs at Mindlance

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.