{"id":1508450,"url":"https://alion.io/job/brightspot-security-engineer","title":"Security Engineer","company":{"id":1972963,"name":"Brightspot","domain":"brightspot.com","url":"https://alion.io/company/brightspot-com","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"ADP","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Reston, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":125000,"max":130000,"currency":"USD","period":"year","gross":null,"usd_annual":130000},"salary_estimate":null,"experience_years_min":7,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Configuration Management","optional":false},{"name":"GCP","optional":false},{"name":"Pulumi","optional":false},{"name":"SOC 2","optional":false},{"name":"Terraform","optional":false},{"name":"SIEM","optional":true}],"status":"live","first_seen_at":"2026-09-16T18:32:00Z","employer_posted_date":"2026-09-16","last_verified_at":"2026-09-30T16:07:59Z","board_verified":true,"closed_at":null,"days_open":14,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":14},"description":"About the Company\nAt Brightspot, we help content-driven organizations turn content chaos into momentum. Our flexible, AI-powered content management platform (CMS) enables teams to move faster, collaborate more effectively, and scale with confidence. Since 2008, leading enterprises have partnered with Brightspot to transform fragmented ecosystems into streamlined, high-performing operations that drive growth, strengthen governance, and deliver real business impact.\nAbout the Role\nWe're looking for a hands-on Security Engineer to help protect our platform and strengthen our overall security posture. This is a highly technical, self-directed role for someone who enjoys getting into the details of infrastructure and application security, can drive projects from idea to completion with minimal oversight, and knows how to use AI tools as a force multiplier to move faster and dig deeper.\nYou'll split your time between hardening cloud infrastructure, investigating and resolving security issues, and partnering closely with Engineering, Platform, QA, and IT to make security a shared responsibility across the company. If you're someone who values ownership and autonomy and enjoys solving complex security challenges end-to-end, this role will give you room to make a real impact.\nResponsibilities\nDrive security projects independently from scoping through completion, working across teams to see initiatives through rather than handing them off after the design phase.\nContribute directly to the investigation of security issues, incidents, and alerts as a hands-on member of the response effort.\nIdentify security issues, develop plans for resolution, and, where appropriate, contribute code through pull requests.\nWork hands-on with Cloud Security Posture Management, vulnerability management, and GRC tooling to identify risks and drive them to closure.\nContinuously evaluate and strengthen existing security tools and processes to improve our overall security maturity.\nConduct external security assessments and operationalize the findings.\nPartner with engineering teams to securely integrate Infrastructure as Code tools, such as Terraform and Pulumi, into the development lifecycle.\nImprove alerting, monitoring, and production observability for security-relevant events.\nCollaborate closely with Engineering, Platform, QA, and IT to embed security into everyday workflows and help build a culture in which security is everyone's responsibility.\nClearly communicate risks and proposed solutions to both technical and non-technical audiences.\nQualifications\n7+ years of hands-on security engineering experience within a software development environment.\nProven experience as a hands-on security engineer, ideally in a SaaS or cloud-native environment.\nExperience securing cloud environments, such as AWS, Azure, or GCP, and working within modern DevOps pipelines.\nStrong self-direction, with the ability to identify problems, prioritize them, and drive them to resolution with minimal oversight.\nDeep understanding of networking and network security fundamentals, including segmentation, routing, firewalls, VPNs, TLS, and secure configuration management.\nExperience with Infrastructure as Code, particularly Terraform or Pulumi, and securing IaC workflows.\nSolid coding and scripting skills sufficient to investigate issues, build tooling, and contribute pull requests that directly address infrastructure vulnerabilities.\nProven track record of identifying vulnerabilities and driving remediation through completion in fast-paced environments.\nWorking knowledge of Cloud Security Posture Management platforms, vulnerability management tools, GRC and compliance tools, and Static Application Security Testing tools.\nFamiliarity with application security practices, including secure SDLC, code review, SAST, and DAST.\nExperience working at a company undergoing or maintaining SOC 2 Type 2 certification.\nPractical experience applying AI tools to security work, including investigation, code analysis, automation, and detection logic.\nExcellent cross-functional collaboration skills, with a track record of working effectively alongside Engineering, Platform, QA, and IT teams.\nAbility to clearly communicate technical risks and remediation plans to both engineering teams and non-technical stakeholders.\nPreferred Qualifications\nExperience operationalizing compliance frameworks, such as SOC 2 Type 2, in real production environments-not just passing an audit, but making the controls meaningful and sustainable.\nExperience coordinating with third-party vendors for penetration testing and managing findings through remediation.\nExperience building or tuning security monitoring and alerting pipelines, such as SIEM or cloud-native detection tooling.\nRelevant certifications, such as AWS or GCP security certifications, OSCP, or CISSP.\nCompensation & Benefits\nThe starting salary for this role is $125,000 with bonus potential.\nBenefits include health, dental, and vision insurance, 3 weeks paid vacation, paid sick leave, paid company holidays, Safe Harbor 401(k) with employer matching, continuing education stipend, and a 3-week paid sabbatical after your 5th anniversary.\nHybrid Expectations\nThis is a hybrid position. Candidates are expected to work on-site at our Reston office 2-3 days per week.","description_format":"text","description_chars":5316,"description_truncated":false,"requirements":{"experience_years_min":7,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Vision insurance"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","Software","CMS & Digital Experience Platforms"],"lifecycle":[{"event":"open","at":"2026-09-30T06:54:29Z"}],"liveness":{"score":67,"band":"ok","label":"Likely open","p_open":1,"p_active":0.744,"p_room":0.9,"age_days":14,"expected_fill_days":24,"reasons":["conf:13","win:mid"],"computed_at":"2026-10-01T05:45:00Z"},"pay":{"stated_usd_annual":130000,"is_top_pay":false},"html_url":"https://alion.io/job/brightspot-security-engineer","json_url":"https://alion.io/job/brightspot-security-engineer.json","meta":{"generated_at":"2026-10-01T18:19:42Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":603,"day_limit":5000,"remaining_today":4397,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}