{"id":2115895,"url":"https://alion.io/job/evisit-software-engineer-security-focus","title":"Software Engineer, Security Focus","company":{"id":8356,"name":"Evisit","domain":"evisit.net","url":"https://alion.io/company/evisit","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workable","truth_index":null},"role":"Backend","role_family":"Backend","seniority":"senior","employment_type":"full_time","work_mode":"remote","remote_scope":"stated_countries","remote_scope_basis":"board_field","remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Mesa, United States"],"countries":["US"],"hiring_countries":["US"],"hiring_countries_total":1,"salary":null,"salary_estimate":{"min_usd":136000,"max_usd":235000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":957},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"AWS Fargate","optional":false},{"name":"FedRAMP","optional":false},{"name":"React.js","optional":false},{"name":"Ruby","optional":false},{"name":"Ruby on Rails","optional":false},{"name":"JavaScript","optional":true},{"name":"Pulumi","optional":true},{"name":"Python","optional":true},{"name":"SQL","optional":true}],"status":"live","first_seen_at":"2026-10-08T23:22:56Z","employer_posted_date":"2026-10-08","last_verified_at":"2026-10-11T19:17:22Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"We are looking for a hands-on full-stack Software Engineer who will focus primarily on security remediation. Your first priority will be owning the remediation of vulnerabilities identified through penetration testing: not just reporting findings, but digging into the codebase, session traffic, and infrastructure to fix the underlying issues and prevent them from recurring. You will work closely with engineering and design teams to translate real-world security findings into concrete, testable requirements in our Technical Requirements Documents (TRDs), and you will personally implement or oversee the fixes.\nThis is an engineering role first. As the security backlog comes under control, you will have the flexibility to contribute to application development across our Ruby on Rails and React platform, bringing a security-minded perspective to the features you build.\nKey Responsibilities\nSecurity Remediation\nVulnerability Remediation: Own end-to-end remediation of vulnerabilities surfaced by penetration tests and other security assessments, from triage through verified fix.\nTraffic and Session Analysis: Use browser-based code inspection tools to examine session traffic between the front end and back end, identify cases where excessive or sensitive information is being exposed, and translate those findings into concrete design and engineering requirements.\nTRD Input: Feed vulnerability findings and remediation requirements directly into the Technical Requirements Document (TRD) process so fixes are captured as durable design requirements, not one-off patches.\nSession Management: Review and harden session management practices across the application stack.\nFull-Stack Remediation: Work within a Ruby on Rails and React codebase and across containerized services (AWS, Fargate) to implement fixes at both the application and infrastructure layers.\nAPI and Real-Time Systems: Assess and secure real-time and API-driven features, including those built on Pusher and AnyCable, and RESTful APIs generally.\nDocumentation: Produce clear, thorough documentation of vulnerabilities, root causes, remediation steps, and verification results.\nCompliance Support: Contribute security context and vocabulary to FedRAMP-related discussions and requirements, partnering with compliance and engineering stakeholders.\nApplication Development\nFeature Development: Design, build, and ship features across the Ruby on Rails back end and React front end alongside the broader engineering team.\nSecure by Design: Apply what you learn from remediation work to new development, helping the team avoid reintroducing known classes of vulnerabilities.\nCode Quality: Participate in code reviews, testing, and technical design discussions, with an eye toward both security and maintainability.\nRequirements\nEngineering Experience\n5+ years of hands-on software engineering experience, with broad full-stack work across multiple applications and technology layers.\nWorking proficiency in Ruby on Rails and React.\nExperience with containerized environments, AWS, and Fargate.\nSolid API experience, including RESTful API design and security considerations.\nHands-on experience with Pusher and AnyCable, or comparable real-time messaging technologies.\nKnowledge of Ruby data models and how schema and query design affect performance and scalability.\nSecurity Experience\n5+ years of experience in a security engineering or closely related role.\nProven experience remediating vulnerabilities identified through penetration testing.\nAWS Security certification(s) (e.g., AWS Certified Security - Specialty).\nGeneral familiarity with FedRAMP: enough understanding of the vocabulary and framework to contribute meaningfully to a FedRAMP-related project.\nAnalytical Skills\nComfortable using browser developer/code inspection tools to inspect network and session traffic.\nAble to identify when too much information is being exposed between backend and frontend, and to explain the risk clearly to engineering and design stakeholders.\nAble to translate security findings into actionable design requirements that feed directly into the TRD.\nCoding and Technical Skills\nWorking proficiency in Ruby on Rails.\nExperience with containerized environments, AWS, and Fargate.\nSolid API experience, including RESTful API design and security considerations.\nSolid understanding of session management principles and common pitfalls.\nHands-on experience with Pusher and AnyCable, or comparable real-time messaging technologies.\nBroad, full-stack experience across multiple applications and technology layers.\nKnowledge of Ruby data models and how schema and query design affect performance and scalability.\nDocumentation\nStrong written communication skills, with the ability to document vulnerabilities, remediations, and technical requirements clearly for both engineering and non-engineering audiences.\nNice to Have\nExperience with Pulumi for infrastructure as code.\nPython experience.\nSQL skills.\nActive or eligible for security clearance.","description_format":"text","description_chars":5010,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Telemedicine & Virtual Care"],"lifecycle":[{"event":"open","at":"2026-10-08T23:22:56Z"}],"visa":[],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":1,"expected_fill_days":40,"reasons":["conf:0","win:early"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/evisit-software-engineer-security-focus","json_url":"https://alion.io/job/evisit-software-engineer-security-focus.json","meta":{"generated_at":"2026-10-11T20:25:54Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler_verified","counted_by":"address","units_charged":1,"used_today":8408,"day_limit":null,"remaining_today":null,"minute_limit":300,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":8356},"rest":"https://alion.io/mcp/rest/get_company?id=8356"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fevisit-software-engineer-security-focus"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fevisit-software-engineer-security-focus"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fevisit-software-engineer-security-focus"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/evisit-software-engineer-security-focus\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fevisit-software-engineer-security-focus"}]}