{"id":1798239,"url":"https://alion.io/job/fixed-senior-cyber-security-rd-engineer","title":"Senior Cyber Security R&D Engineer","company":{"id":3882615,"name":"Fixed Solutions","domain":"solutions.fixed.global","url":"https://alion.io/company/fixed-3","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Zoho Recruit","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Cairo, Egypt"],"countries":["EG"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":74000,"max_usd":171000,"period":"year","method":"global_role_cell_scaled_by_country","sample_n":1567},"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agile","optional":false},{"name":"Anomaly Detection","optional":false},{"name":"Ansible","optional":false},{"name":"Apache Kafka","optional":false},{"name":"ArgoCD","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"C++","optional":false},{"name":"CI/CD","optional":false},{"name":"CIS Benchmarks","optional":false},{"name":"CWE","optional":false},{"name":"Dependabot","optional":false},{"name":"Docker","optional":false},{"name":"ElasticSearch","optional":false},{"name":"GCP","optional":false},{"name":"GDPR","optional":false},{"name":"GitHub Actions","optional":false},{"name":"GitLab CI","optional":false},{"name":"Go","optional":false},{"name":"ISO 27001","optional":false},{"name":"Istio","optional":false},{"name":"JavaScript","optional":false},{"name":"Jenkins","optional":false},{"name":"Kotlin","optional":false},{"name":"Kubernetes","optional":false},{"name":"Least Privilege","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"NIST 800-53","optional":false},{"name":"NIST CSF","optional":false},{"name":"OWASP","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"OWASP ZAP","optional":false},{"name":"PCI DSS","optional":false},{"name":"PowerShell","optional":false},{"name":"Python","optional":false},{"name":"Qualys Cloud Platform","optional":false},{"name":"Red Teaming","optional":false},{"name":"Rust","optional":false},{"name":"Scrum","optional":false},{"name":"Semgrep","optional":false},{"name":"Service Mesh","optional":false},{"name":"Shift-Left","optional":false},{"name":"Shift-Left Security","optional":false},{"name":"SIEM","optional":false},{"name":"Snyk","optional":false},{"name":"SOC 2","optional":false},{"name":"SonarQube","optional":false},{"name":"Splunk","optional":false},{"name":"STRIDE","optional":false},{"name":"Terraform","optional":false},{"name":"Threat Modeling","optional":false},{"name":"TypeScript","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-10-03T18:20:24Z","employer_posted_date":"2026-10-03","last_verified_at":"2026-10-10T21:47:37Z","board_verified":true,"closed_at":null,"days_open":7,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":7},"description":"ROLE OVERVIEW\nWe are seeking a high-caliber Research &\nDevelopment Engineer to join our Cybersecurity product team. This is a\nfull-lifecycle role - you will work side-by-side with the Product Manager from\nthe earliest ideation stage, translate business requirements into secure\narchitecture, prototype and build Minimum Viable Products (MVPs), and own\nsecurity engineering practices throughout the entire software development\nlifecycle (SDLC).You will operate at the\nintersection of applied security research, product engineering, and DevSecOps\nautomation, ensuring that every product we ship is built securely by design and\ndelivered with operational confidence.\nKEY RESPONSIBILITIES\n1. Product Ideation & Business Alignment\nCollaborate with the\nProduct Manager to translate market threats, customer pain points, and security\nintelligence into viable product ideas.\nParticipate in threat\nlandscape research and competitive analysis to validate product concepts and\ndefine differentiated value propositions.\nAuthor and review\nProduct Business Descriptions (PBDs), ensuring technical feasibility, security\nscope, and alignment with organizational strategy.\nDefine security use\ncases, acceptance criteria, and success metrics for proposed cybersecurity\nproducts.\nContribute to business\ncase development including effort estimation, risk assessment, and technology\nstack recommendations.\n2. MVP & Product Development\nDesign and develop\nMinimum Viable Products (MVPs) for cybersecurity solutions.\nLead the architecture\nand implementation of backend services, APIs, data pipelines, and analytics\ncomponents for security products.\nBuild proof-of-concepts\n(PoCs) and technical demonstrations to validate research hypotheses and product\nassumptions.\nMaintain product\nbacklogs with well-defined security stories, technical debt items, and research\ntasks in Agile/Scrum frameworks.\nDrive rapid iteration\ncycles, ensuring each sprint delivers measurable, shippable security value.\n3. Software Security Engineering\nApply Secure-by-Design\nprinciples across all phases of development including threat modeling (STRIDE /\nPASTA), secure code review, and security architecture review.\nConduct or commission\npenetration testing, fuzzing, and red team exercises on products prior to\nrelease.\nPerform vulnerability\nresearch and responsible disclosure coordination for internally developed\nproducts.\nEnsure compliance with\nsecurity standards such as OWASP Top 10, CWE/SANS Top 25, NIST 800-53, ISO\n27001, and relevant regulatory frameworks.\nDevelop and maintain\nsecurity reference architectures, coding standards, and secure development\nguidelines.\n4.DevSecOps Engineering & Automation\nDesign and implement\nend-to-end DevSecOps pipelines integrating SAST, DAST, SCA, secrets scanning,\ncontainer security, and IaC scanning.\nAutomate security gates\nwithin CI/CD workflows (GitHub Actions, GitLab CI, Jenkins) to enforce\npolicyas-code and prevent vulnerable code from reaching production.\nImplement infrastructure\nsecurity controls using Terraform, Ansible, or equivalent IaC tools, following\nleast-privilege and zero-trust principles.\nBuild security\nobservability into products from day one: structured logging, runtime\ndetection, anomaly alerting, and incident response hooks.\nManage container\nsecurity (Docker, Kubernetes) including image hardening, network policies, and\nruntime threat detection.\nEstablish and maintain\nvulnerability management programs covering dependency tracking, SBOMs, and\npatch management automation.\n5. Security Research & Innovation\nConduct applied research\ninto emerging attack techniques, adversarial AI/ML, malware analysis, protocol\nexploitation, and zero-day research.\nPublish internal\nresearch reports, technical whitepapers, and contribute to external security\nconferences and publications.\nEvaluate, integrate, and\nsometimes reverse-engineer third-party security tools, threat intelligence\nfeeds, and open-source frameworks.\nStay current with CVEs,\nthreat actor TTPs (MITRE ATT&CK), and evolving regulatory requirements\nimpacting product design.\nRequirements\nEducation\nBachelor's degree or\nhigher in Computer Science, Cybersecurity, Information Security, Software\nEngineering, or a related discipline.\nExperience\n4+ years of hands-on\npipeline management experience with at least 3 years focused on cybersecurity\nproduct development or security engineering.\nDemonstrated experience\nbuilding and shipping security products or tools from concept through\nproduction.\nTrack record of working\nwith Product Managers to define requirements, write business descriptions, and\ndeliver MVPs.\nExperience implementing\nDevSecOps pipelines and security automation in CI/CD environments.\nTECHNICAL SKILLS & COMPETENCIES\n1-Languages: Python,\nGo, Rust, Java/Kotlin, C/C++, Bash/PowerShell, JavaScript/TypeScript\n2-Security Engineering: Threat Modeling\n(STRIDE, PASTA), Penetration Testing, Reverse Engineering, Malware Analysis,\nExploit Development\n3-DevSecOps\n& CI/CD: GitHub Actions, GitLab CI, Jenkins, ArgoCD ·\nSAST (SonarQube, Semgrep) · DAST (OWASP ZAP, Burp Suite) · SCA (Snyk,\nDependabot)\n4-Cloud &\nInfrastructure: AWS / Azure / GCP security services · Terraform\n· Kubernetes · Docker · Service Mesh (Istio) · Zero-Trust Architecture\n5-Security\nPlatforms: SIEM (Splunk, Elastic/ELK) · SOAR · EDR/XDR ·\nVulnerability Management (Tenable, Qualys) · MITRE ATT&CK\n6-Data\n& Analytics: Security data engineering, Kafka,\nElasticsearch, threat intelligence pipelines, ML-based anomaly detection\n7-Standards\n& Frameworks: NIST CSF / 800-53 · ISO 27001 · OWASP ·\nSOC 2 · GDPR · PCI-DSS · CIS Benchmarks\n8-Methodologies: Agile / Scrum · Secure SDLC · Design Thinking · DevOps ·\nShift-Left Security · Risk-Based Prioritization\nPREFERRED CERTIFICATIONS\nOSCP - Offensive\nSecurity Certified Professional\nCISSP - Certified\nInformation Systems Security Professional\nCEH - Certified Ethical\nHacker\nCSSLP - Certified Secure\nSoftware Lifecycle Professional\nAWS / Azure / GCP\nSecurity Specialty Certifications\nCKS - Certified\nKubernetes Security Specialist\nGREM - GIAC Reverse\nEngineering Malware\nBEHAVIORAL COMPETENCIES\nProduct Thinking:\nConnects security engineering decisions to business outcomes and user value.\nResearch Rigor:\nApproaches problems with intellectual curiosity, forming and testing hypotheses\nsystematically.\nCommunication:\nTranslates complex security topics into clear business language for executive\nand nontechnical audiences.\nCollaboration: Works\neffectively in cross-functional teams spanning product, engineering, legal, and\noperations.\nOwnership: Takes\nend-to-end accountability for features and products, from design through\npostrelease monitoring.\nAdaptability: Thrives in\na fast-paced R&D environment where priorities evolve with the threat\nlandscape.\nSecurity Mindset:\nConsistently applies adversarial thinking to identify risk before it becomes\nexploitable","description_format":"text","description_chars":6868,"description_truncated":false,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security"],"lifecycle":[{"event":"open","at":"2026-10-03T18:20:24Z"}],"visa":[],"liveness":{"score":88,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.877,"p_room":1,"age_days":6,"expected_fill_days":22,"reasons":["conf:1","velocity","win:early"],"computed_at":"2026-10-10T05:45:15Z"},"pay":null,"html_url":"https://alion.io/job/fixed-senior-cyber-security-rd-engineer","json_url":"https://alion.io/job/fixed-senior-cyber-security-rd-engineer.json","meta":{"generated_at":"2026-10-11T01:09:22Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1667,"day_limit":5000,"remaining_today":3333,"minute_limit":60,"resets_at":"2026-10-12T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":3882615},"rest":"https://alion.io/mcp/rest/get_company?id=3882615"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Ffixed-senior-cyber-security-rd-engineer"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Ffixed-senior-cyber-security-rd-engineer"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Ffixed-senior-cyber-security-rd-engineer"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/fixed-senior-cyber-security-rd-engineer\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Ffixed-senior-cyber-security-rd-engineer"}]}