About Hubnest
Hubnest builds vertical specific product engines for industries that require high operational precision. Founded in 2014, the company has spent twelve years embedded in the operational realities of the industries it serves, developing four purpose built products used by organizations across field services, political and civic operations, continuing care, and enterprise security.
Security Engineer
You will defend Hubnest's proprietary systems and sensitive client data against external and internal threats. You proactively identify vulnerabilities, engineer defensive mechanisms, and enforce security protocols across all engineering teams.
What You Will Be Doing
- Conduct ongoing vulnerability assessments and internal penetration tests against Hubnest's four distinct products.
- Implement and manage automated Static Application Security Testing and Dynamic Application Security Testing in the CI/CD pipeline.
- Monitor centralized SIEM dashboards to detect, analyze, and hunt anomalous network behavior and unauthorized access attempts.
- Perform manual code reviews of complex pull requests, targeting OWASP Top 10 vulnerabilities including XSS, SQLi, and CSRF.
- Respond as the technical lead during active security incidents, executing containment, eradication, and forensic analysis protocols.
- Review and harden AWS cloud infrastructure configurations, eliminating misconfigurations and overly permissive IAM roles.
- Collaborate with the Compliance Analyst to map technical security controls to SOC 2, HIPAA, and GDPR frameworks.
- Document incident response playbooks, disaster recovery strategies, and internal security standard operating procedures.
- Maintain endpoint detection and response solutions across all distributed company hardware.
- Execute third-party vendor risk assessments prior to the procurement of any new software tooling.
- Train the software engineering department semi-annually on secure coding practices and emerging threat vectors.
What We Are Looking For
- 5+ years of professional experience in Application Security, Cloud Security, or Offensive Security roles.
- 4+ years of hands-on experience securing AWS cloud environments and auditing complex IAM policies.
- 3+ years of verifiable experience utilizing industry-standard penetration testing tools such as Burp Suite Pro, Metasploit, Nmap, and Nessus.
- 3+ years of experience implementing and tuning SAST/DAST tools such as SonarQube, Checkmarx, or Veracode within CI/CD pipelines.
- 2+ years of experience serving as a primary technical responder during active cybersecurity incidents or data breaches.
- 3+ years of experience reading and auditing application source code in Python, JavaScript, and Go to identify vulnerabilities.
- 2+ years of direct, hands-on experience mapping technical engineering controls to SOC 2 Type II or HIPAA compliance requirements.
- 2+ years of experience utilizing SIEM platforms such as Splunk, Datadog Security, or ELK Stack to write custom detection rules.
- Current certification required: CISSP, OSCP, AWS Certified Security Specialty, or equivalent.
- Commitment to maintaining discretion and ethical standards regarding sensitive client data.
- Bachelor's degree in Cybersecurity, Computer Science, Information Security, or equivalent practical experience.
What We Offer
- Competitive compensation commensurate with experience
- Comprehensive health, dental, and vision coverage
- Flexible working arrangements
- Learning and development budget
- Paid time off and statutory holidays
Equal Opportunity Employment
Hubnest is an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, national origin, age, disability, genetic information, or any other characteristic protected by applicable federal, state, or local law.
How to Apply
Submit your application through our contact page. Select "Career Opportunity" and include the role title in your message. We review every application and will be in touch if there is a fit.