Taro Logo

Information Security Engineer

Security
Entry-Level Software Engineer
In-Person
1+ year of experience
Cybersecurity

Job Description

ProgressSoft is seeking an Information Security Engineer to strengthen their security posture across products and platforms. This role combines hands-on security engineering with collaborative teamwork alongside developers and DevOps teams. The position focuses on application security, including code reviews, vulnerability assessments, and implementing security best practices in the development lifecycle. The ideal candidate will have experience with Java security, OWASP standards, and modern security tools. This is an excellent opportunity for a security professional looking to make a significant impact in a dynamic environment while working with cutting-edge security technologies and methodologies. The role offers a perfect blend of technical challenges and professional growth opportunities in application and infrastructure security.

Last updated 4 days ago

Responsibilities For Information Security Engineer

  • Perform application security reviews, including Java code review, threat modeling, and vulnerability assessments
  • Identify and remediate security vulnerabilities in web, API, and mobile applications, with a focus on OWASP Top 10 risks
  • Collaborate with developers to integrate security best practices into the SDLC and CI/CD pipelines
  • Conduct penetration tests and manage third-party security assessments
  • Develop and enforce secure coding standards for Java and related frameworks
  • Support automation of security testing tools (SAST, DAST, SCA)
  • Implement and maintain security controls across servers, cloud environments, and networks
  • Support vulnerability management, patching, and configuration hardening
  • Monitor for security threats, investigate incidents, and support incident response

Requirements For Information Security Engineer

Java
  • Minimum 1 year of professional experience in security (application or infrastructure)
  • OR relevant certification such as OSCP, OSWE, or equivalent
  • Strong understanding of application security principles (OWASP Top 10, secure coding, threat modeling)
  • Familiarity with tools like Burp Suite, OWASP ZAP, SAST/DAST scanners, etc
  • Excellent problem-solving skills and ability to communicate technical findings clearly
  • Familiarity with Java-based applications and common frameworks (e.g., Spring)
  • Experience with DevSecOps and CI/CD pipeline security
  • Familiarity with infrastructure/cloud security

Related Jobs