Software Product Security Engineer

Posted:
4/16/2025, 2:02:39 PM

Experience Level(s):
Expert or higher ⋅ Senior

Field(s):
IT & Security ⋅ Software Engineering

Orion Innovation is a premier, award-winning, global business and technology services firm.  Orion delivers game-changing business transformation and product development rooted in digital strategy, experience design, and engineering, with a unique combination of agility, scale, and maturity.  We work with a wide range of clients across many industries including financial services, professional services, telecommunications and media, consumer products, automotive, industrial automation, professional sports and entertainment, life sciences, ecommerce, and education.

Summary: 

This role involves collaborating with Software Engineering and Infosec teams to ensure the security of software products throughout their lifecycle. Responsibilities include identifying, triaging, and mitigating vulnerabilities, promoting security best practices, and supporting secure software development processes.

Key Responsibilities:

  • Define and refine security requirements in collaboration with development, regulatory, and information security teams.
  • Enhance software development security processes and evangelize security best practices.
  • Conduct security reviews of products and features, including risk assessments and threat modeling.
  • Implement security in CI/CD pipelines and build automation.
  • Automate security testing and compliance checks.
  • Implement and manage security controls for software products (e.g., access control, encryption).
  • Develop, deploy, and support security tooling (e.g., vulnerability scanning, SIEM systems).
  • Utilize existing security tools and frameworks where possible.

Qualifications:

  • MS degree in computer science, cybersecurity, or equivalent experience.
  • 10+ years of software development or security engineering experience, ideally with complex data or process management applications.
  • 5+ years of experience in Java and another high-level language (Python, C++, Go).
  • 5+ years of experience in cloud and infrastructure security.
  • Excellent communication skills.
  • Commitment to security and privacy best practices.
  • Background in Secure Software Development Lifecycle (SSDLC).

Knowledge, Skills, and Abilities:

  • Experience in the healthcare industry and handling sensitive data.
  • Familiarity with regulatory compliance (FDA PMA, IVDR, GDPR, HIPAA).
  • Proficiency in vulnerability scanning and tools.
  • Expertise in cloud security best practices.
  • Strong Java programming skills.
  • Experience with CI/CD security integration.
  • Knowledge of REST API and web service security.
  • Understanding of relational database and SQL security practices.

Nice to Have:

  • Security certifications (CISSP, CEH/OSCP).
  • Cloud pipeline orchestration (WDL, NextFlow)

Orion is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, citizenship status, disability status, genetic information, protected veteran status, or any other characteristic protected by law.

Candidate Privacy Policy

Orion Systems Integrators, LLC and its subsidiaries and its affiliates (collectively, “Orion,” “we” or “us”) are committed to protecting your privacy. This Candidate Privacy Policy (orioninc.com) (“Notice”) explains:

  • What information we collect during our application and recruitment process and why we collect it;
  • How we handle that information; and
  • How to access and update that information.

Your use of Orion services is governed by any applicable terms in this notice and our general Privacy Policy.