Back to jobs
Logo of RainFocus
RainFocus
Actively hiring

Cybersecurity Engineer (Remote)

Workplace
Remote
Commitment
Full-time
Seniority
Mid-Level
Posted
Location
Lehi, United States

As a Cybersecurity Engineer at RainFocus, you will safeguard the organization's digital assets, infrastructure, and application ecosystem. This mid-level, autonomous role bridges IT operations, software development, and risk management. You will manage vulnerability management, bug bounty programs, secure development collaboration, and incident management, working closely with developers and DevOps to ensure robust security practices.

Responsibilities

  • Vulnerability & Application Security Management: Own the vulnerability management program end-to-end: oversee continuous vulnerability scanning (Tenable) and software composition analysis/code dependencies (Sonarqube), drive remediation across teams, and replicate and validate discovered vulnerabilities using tools like Burp Suite and Kali Linux.
  • Crowdsourced Security & Threat Intel: Manage and triage our crowdsourced bug bounty program (BugCrowd) and monitor our external security posture rating (Bitsight).
  • Secure Development Collaboration: Act as the security voice in developer architecture meetings. Partner with engineering teams to review code dependencies, threat-model new features, and ensure secure coding practices.
  • Risk & Change Management: Own and conduct system impact analyses for proposed changes, represent security on the Change Control Board (CCB), and lead threat modeling sessions for new systems, features, and infrastructure changes.
  • Incident Management & Operations: Triage and document security incidents within OneTrust and Jira. Collaborate with DevOps to ensure security tools are properly deployed across AWS environments and endpoint configurations.
  • Endpoint & Tool Oversight: Maintain a "read-only/audit" oversight of our endpoint detection, MDM, and email security tools (Sophos, JAMF, BetterCloud) to ensure compliance and active alerting.
  • Security Awareness & Culture: Administer the security awareness learning modules (RF Academy) and lead internal initiatives to keep security top-of-mind for all employees.

Requirements

  • Citizenship: All candidates must be a US citizen.
  • Experience: 3–5 years of dedicated experience in a technical cybersecurity role (e.g., Security Engineer, AppSec Engineer, or Senior Security Analyst, etc.).
  • Application Security: Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure code dependencies (SCA).
  • Vulnerability Assessment: Proven experience running enterprise vulnerability scanners, interpreting results, and driving remediation across cross-functional teams.
  • Cloud & Infrastructure: Foundational knowledge of cloud environments (specifically AWS) and securing cloud-native applications.
  • Communication: Excellent collaboration skills. You must be able to sit down with software developers, understand their sprint goals, and help them fix security bugs without breaking their workflow.

Nice to have

  • AppSec/PenTesting: Burp Suite, Kali Linux, BugCrowd, Sonarqube
  • SecOps & Vulnerability: Tenable, Bitsight, OneTrust
  • IT & Endpoint Ecosystem: Jira, AWS, Sophos, JAMF, PDQ, BetterCloud
  • Certifications: CompTIA Security+, CEH, GIAC, or progress toward a CISSP, or other relevant certifications
  • Automation: Basic scripting skills (Python, PowerShell, or Bash) to automate repetitive security tasks or log analysis.
  • Security Frameworks: Experience with maintaining compliance with PCI-DSS, ISO 27001, and SOC 2 frameworks.
  • Artificial Intelligence: Experience utilizing AI to improve productivity and efficiency, as well as experience reviewing AI tools, integrations, and features.

Benefits

  • As a member of the RainFocus team, you will have the opportunity to experience first-hand the impact of our platform at events around the world. Additionally, RainFocus offers competitive salaries, competitive benefits, 401k, generous PTO, and countless other team building activities.