996,562open jobs
59,446companies
165,965added this week
Browse all
Salary
$125k – $130k per year
Location
Hybrid (Reston, United States)
Seniority
Senior · 7+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 30, 2026. First seen by Alion on Sep 16, 2026.

Overview
Company
Impact
Profile match
Brightspot is the enterprise CMS and content operations platform powering AP, NBC Sports and Whole Foods. AI-powered, flexible and built to grow with you.

About the Company

At Brightspot, we help content-driven organizations turn content chaos into momentum. Our flexible, AI-powered content management platform (CMS) enables teams to move faster, collaborate more effectively, and scale with confidence. Since 2008, leading enterprises have partnered with Brightspot to transform fragmented ecosystems into streamlined, high-performing operations that drive growth, strengthen governance, and deliver real business impact.

About the Role

We're looking for a hands-on Security Engineer to help protect our platform and strengthen our overall security posture. This is a highly technical, self-directed role for someone who enjoys getting into the details of infrastructure and application security, can drive projects from idea to completion with minimal oversight, and knows how to use AI tools as a force multiplier to move faster and dig deeper.

You'll split your time between hardening cloud infrastructure, investigating and resolving security issues, and partnering closely with Engineering, Platform, QA, and IT to make security a shared responsibility across the company. If you're someone who values ownership and autonomy and enjoys solving complex security challenges end-to-end, this role will give you room to make a real impact.

Responsibilities

  • Drive security projects independently from scoping through completion, working across teams to see initiatives through rather than handing them off after the design phase.
  • Contribute directly to the investigation of security issues, incidents, and alerts as a hands-on member of the response effort.
  • Identify security issues, develop plans for resolution, and, where appropriate, contribute code through pull requests.
  • Work hands-on with Cloud Security Posture Management, vulnerability management, and GRC tooling to identify risks and drive them to closure.
  • Continuously evaluate and strengthen existing security tools and processes to improve our overall security maturity.
  • Conduct external security assessments and operationalize the findings.
  • Partner with engineering teams to securely integrate Infrastructure as Code tools, such as Terraform and Pulumi, into the development lifecycle.
  • Improve alerting, monitoring, and production observability for security-relevant events.
  • Collaborate closely with Engineering, Platform, QA, and IT to embed security into everyday workflows and help build a culture in which security is everyone's responsibility.
  • Clearly communicate risks and proposed solutions to both technical and non-technical audiences.

Qualifications

  • 7+ years of hands-on security engineering experience within a software development environment.
  • Proven experience as a hands-on security engineer, ideally in a SaaS or cloud-native environment.
  • Experience securing cloud environments, such as AWS, Azure, or GCP, and working within modern DevOps pipelines.
  • Strong self-direction, with the ability to identify problems, prioritize them, and drive them to resolution with minimal oversight.
  • Deep understanding of networking and network security fundamentals, including segmentation, routing, firewalls, VPNs, TLS, and secure configuration management.
  • Experience with Infrastructure as Code, particularly Terraform or Pulumi, and securing IaC workflows.
  • Solid coding and scripting skills sufficient to investigate issues, build tooling, and contribute pull requests that directly address infrastructure vulnerabilities.
  • Proven track record of identifying vulnerabilities and driving remediation through completion in fast-paced environments.
  • Working knowledge of Cloud Security Posture Management platforms, vulnerability management tools, GRC and compliance tools, and Static Application Security Testing tools.
  • Familiarity with application security practices, including secure SDLC, code review, SAST, and DAST.
  • Experience working at a company undergoing or maintaining SOC 2 Type 2 certification.
  • Practical experience applying AI tools to security work, including investigation, code analysis, automation, and detection logic.
  • Excellent cross-functional collaboration skills, with a track record of working effectively alongside Engineering, Platform, QA, and IT teams.
  • Ability to clearly communicate technical risks and remediation plans to both engineering teams and non-technical stakeholders.

Preferred Qualifications

  • Experience operationalizing compliance frameworks, such as SOC 2 Type 2, in real production environments-not just passing an audit, but making the controls meaningful and sustainable.
  • Experience coordinating with third-party vendors for penetration testing and managing findings through remediation.
  • Experience building or tuning security monitoring and alerting pipelines, such as SIEM or cloud-native detection tooling.
  • Relevant certifications, such as AWS or GCP security certifications, OSCP, or CISSP.

Compensation & Benefits

  • The starting salary for this role is $125,000 with bonus potential.
  • Benefits include health, dental, and vision insurance, 3 weeks paid vacation, paid sick leave, paid company holidays, Safe Harbor 401(k) with employer matching, continuing education stipend, and a 3-week paid sabbatical after your 5th anniversary.

Hybrid Expectations

  • This is a hybrid position. Candidates are expected to work on-site at our Reston office 2-3 days per week.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
996,562 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Reston
≈ $105k – $207k per year (Estimated) • In office • 6+ years exp • Atlanta
DevOps
Azure
Cybersecurity
MITRE ATT&CK
Cyber Kill Chain
Diamond Model
DLP
Apply
≈ $108k – $212k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Atlanta
DevOps
GCP
Azure
AWS
Cybersecurity
Zero Trust
Apply
$200k – $290k per year • Remote (United States) • Full-Time
DevOps
AWS
IAM
Cybersecurity
NIST 800-171
Apply
DevSecOps Engineer 2 days ago
$132k – $202k per year • Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • New York
Python
JavaScript
PowerShell
DevOps
Terraform
Azure DevOps
GitHub Actions
CloudFormation
GitLab CI
Azure
CI/CD
Jenkins
Git
AWS
Kubernetes
Bicep
GitHub
Cybersecurity
Snyk
ISO 27001
Open Policy Agent
Wiz
MITRE ATT&CK
OWASP Top 10
SOC 2
HIPAA
Threat Modeling
Dependabot
Sysdig Secure
Apply
DevSecOps Engineer 1 day ago
≈ $117k – $229k per year (Estimated) • In office • TS/SCI • 5+ years exp • San Diego
Python
PowerShell
DevOps
Terraform
Ansible
Helm
Azure DevOps
Loki
CloudFormation
K3s
Prometheus
Azure
CI/CD
AWS
Kubernetes
Grafana
Platform Engineering
Bicep
Cybersecurity
SonarQube
NIST 800-171
Zero Trust
SBOM
Apply
In office • Contractor • Bengaluru
DevOps
Terraform
Ansible
GCP
Azure
AWS
Kubernetes
DNS
BGP
Apply
≈ $22k – $44k per year (Estimated) • In office • Bengaluru
Python
Rust
SQL
C#
DevOps
GCP
Azure
CI/CD
AWS
Analytics
ETL/ELT
Apply
≈ $108k – $212k per year (Estimated) • In office • 5+ years exp • Bachelor's Degree • Atlanta
DevOps
GCP
Azure
AWS
Cybersecurity
Zero Trust
Apply
≈ $13k – $32k per year (Estimated) • Equity • Hybrid • Full-Time • 1+ year exp • Bangkok
PowerShell
C#
Bash
COBOL
COBOL
IBM MQ
Databases
MS SQL
DevOps
Terraform
Puppet
Ansible
Helm
GitHub Actions
Chef
Datadog
Azure
CI/CD
Git
Kubernetes
Configuration Management
Linux
Windows
Management
Agile
QA
Postman
SoapUI
Apply
In office • Full-Time • 4+ years exp • Bachelor's Degree • Bengaluru
Python
JavaScript
TypeScript
SQL
Python
Flask
Django
Databases
PostgreSQL
DynamoDB
Amazon Aurora
Frontend
Zustand
Redux
React.js
Mobile
State Management
DevOps
Terraform
GitHub Actions
AWS CDK
CI/CD
Jenkins
Git
AWS
Docker
AWS Lambda
Amazon EC2
GitHub
Amazon S3
API Gateway
Apply
≈ $150k – $279k per year (Estimated) • Hybrid • 5+ years exp • Reston
AI/ML
AI Agents
Apply
$209k – $313k per year • Equity • In office • TS/SCI • Full-Time • 8+ years exp • Reston • Washington
Cybersecurity
GDPR
NIST 800-53
NIST 800-171
FedRAMP
Apply
$164k – $246k per year • Equity • In office • TS/SCI • Full-Time • 5+ years exp • Bachelor's Degree • Reston
Python
DevOps
Splunk
Terraform
Terragrunt
Prometheus
GitLab CI
CI/CD
GitOps
ArgoCD
Jenkins
AWS
Docker
Kubernetes
Grafana
Platform Engineering
Cybersecurity
NIST 800-53
FedRAMP
Zero Trust
Apply
$170k – $260k per year • In office • TS/SCI • 10+ years exp • Reston
Python
Bash
DevOps
Podman
CI/CD
Jenkins
Git
AWS
Docker
Amazon EC2
GitLab
Amazon S3
Linux
Apply
$170k – $260k per year • In office • TS/SCI • 10+ years exp • Reston
Python
Bash
DevOps
Podman
CI/CD
Jenkins
Git
AWS
Docker
Amazon EC2
GitLab
Amazon S3
Linux
Apply
$170k – $260k per year • In office • TS/SCI • 10+ years exp • Reston
Python
Bash
DevOps
Podman
CI/CD
Jenkins
Git
AWS
Docker
Amazon EC2
GitLab
Amazon S3
Linux
Apply
See all jobs
This is one of many
996,562 more open roles from verified company boards, updated every day.