Symosis Security is a cybersecurity engineering firm helping Fortune 500, enterprise, healthcare, financial services, and public sector organizations secure modern applications, cloud platforms, AI technologies, and enterprise environments. They are seeking a hands-on Senior Security Engineer to lead security architecture reviews, threat modeling, AI security assessments, cloud security reviews, and security engineering initiatives while working directly with client engineering teams.
Responsibilities:
- Perform technical security assessments for SaaS applications, cloud environments, AI solutions, APIs, and third-party integrations
- Conduct deep security architecture reviews and technical threat modeling for cloud-native applications and distributed systems
- Assess cloud security with a strong emphasis on Microsoft Azure (AWS/GCP experience is a plus)
- Review authentication, authorization, IAM, OAuth/OIDC, SAML, secrets management, encryption, logging, and network security controls
- Assess AI-enabled applications, LLMs, AI agents, Model Context Protocol (MCP), Retrieval-Augmented Generation (RAG), and modern AI architectures for security risks
- Review application architecture, GitHub repositories, CI/CD pipelines, Infrastructure as Code, and secure software development practices
- Develop actionable remediation recommendations and present findings to engineering and security teams
- Perform web, API, cloud, and Active Directory penetration testing and participate in red team exercises as needed
- Independently manage client engagements from kickoff through delivery
Requirements:
- 5-7+ years of experience in Application Security, Cloud Security, Security Engineering, or Security Architecture
- Experience conducting technical security assessments, architecture reviews, and threat modeling
- Strong expertise in Microsoft Azure security; AWS and GCP experience are a plus
- Strong understanding of: Cloud Security, Identity & Access Management, OAuth, OIDC, and SAML, API Security, Threat Modeling (STRIDE or similar), Secure SDLC, GitHub and CI/CD
- Experience applying security methodologies including MITRE ATT&CK, OWASP Top 10, OWASP API Security Top 10, NIST CSF, and CIS Controls
- Excellent communication, presentation, and technical writing skills
- Experience securing AI-enabled applications and GenAI platforms
- Understanding of LLM security, AI agents, MCP, RAG, prompt injection, AI governance, and secure AI application design
- Hands-on software development experience with Python, Java, JavaScript/TypeScript, Go, C#, or similar
- Experience using AI-assisted development tools such as GitHub Copilot, Cursor, Claude Code, Gemini, or similar
- Experience with Microsoft 365, Entra ID, Okta, SailPoint, Kubernetes, Terraform, CI/CD, SSPM platforms, or security automation
- Experience performing penetration testing, Active Directory security assessments, and red or purple team engagements