Solvd

Security Engineer

Solvd Georgia, United States

IT Services and IT Consulting · 501-1,000 employees

20 h ago
Remote security Senior (5-10 yrs) Full-time Poland
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

You will define and validate application security controls across the full lifecycle of a high-traffic digital news platform. This includes performing threat modeling, reviewing API and integration security, and coordinating vulnerability management efforts.

What they look for

Application Security Threat Modeling Architecture Review OAuth OIDC RBAC Privileged Access Management API Security Secrets Management Vulnerability Scanning Penetration Testing Encryption GDPR Privacy Engineering Security Logging Incident Response

Requirements

Candidates must have at least 5 years of experience in application security and deep knowledge of authentication patterns and secure architecture. Proficiency in GDPR compliance, secrets management, and security assessment methodologies is essential for this role.

Full description

Solvd Inc. is a rapidly growing AI-native consulting and technology services firm delivering enterprise transformation across cloud, data, software engineering, and artificial intelligence. We work with industry-leading organizations to design, build, and operationalize technology solutions that drive measurable business outcomes.

Following the acquisition of Tooploox, a premier AI and product development company, Solvd now offers true end-to-end delivery—from strategic advisory and solution design to custom AI development and enterprise-scale implementation. Our capability centers combine deep technical expertise, proven delivery methodologies, and sector-specific knowledge to address complex business challenges quickly and effectively.

We are looking for an Application Security Engineer to join a greenfield digital news platform build for a major international news brand. Security is not a pre-launch checklist here — it is an engineering requirement embedded across every phase of delivery, from architecture through launch and into multi-year support.

You'll be the security authority on a full-lifecycle engagement, validating controls across a composable CMS, video pipeline, advertising integrations, personalisation services, and public-facing APIs — on a platform designed to sustain extreme traffic during breaking-news events.

What you'll do

  • Define and validate application and platform security controls across all delivery phases.
  • Perform architecture and threat-model reviews at design stage and as the platform evolves.
  • Review authentication, authorization, and privileged-access controls across CMS, APIs, and integrated services.
  • Validate API and integration security across a composable, multi-vendor platform architecture.
  • Review secrets, credentials, and token-management practices across the full stack.
  • Support vulnerability scanning and penetration-testing activities — coordinating findings and remediation.
  • Validate encryption and secure data handling across storage, transit, and third-party integrations.
  • Review security logging, monitoring, and incident-response requirements.
  • Support GDPR and privacy engineering requirements throughout delivery.
  • Conduct third-party security assessments for integrated services and vendors.
  • Provide remediation guidance and produce security acceptance evidence ahead of launch.

Basic qualifications

  • 5+ years of experience in application security, security engineering, or a closely related role.
  • Experience performing threat modelling and architecture security reviews on complex, multi-component platforms.
  • Strong knowledge of authentication and authorization patterns — OAuth, OIDC, RBAC, privileged access management.
  • Hands-on experience validating API security and reviewing integration patterns across third-party services.
  • Solid understanding of secrets management, credential handling, and token lifecycle best practices.
  • Experience supporting or coordinating vulnerability scanning and penetration testing programmes.
  • Knowledge of encryption standards and secure data handling practices across storage and transit.
  • Familiarity with GDPR and privacy-by-design engineering requirements.
  • Ability to produce clear remediation guidance and security acceptance documentation for engineering and delivery teams.

Preferred qualifications

  • Experience securing composable CMS or media platform architectures — AEM, Amplience, or similar.
  • Background working on high-traffic, public-facing platforms where availability and security intersect.
  • Experience with security logging and monitoring tooling — SIEM, alerting, incident response playbooks.
  • Familiarity with third-party vendor security assessment processes.
  • Relevant certification — CISSP, OSCP, CEH, or equivalent.
  • Experience working within a phased, full-lifecycle delivery programme alongside engineering and architecture teams.

When you join Solvd, you'll…

  • Shape real-world AI-driven projects across key industries, working with clients from startup innovation to enterprise transformation.
  • Be part of a global team with equal opportunities for collaboration across continents and cultures.
  • Thrive in an inclusive environment that prioritizes continuous learning, innovation, and ethical AI standards.

Ready to make an impact?

If you're excited to build things that matter, champion responsible AI, and grow with some of the industry’s sharpest minds. Apply today and let’s innovate together.

Solvd is an equal opportunity employer.

Similar roles