Lehi, UTremote

Salary
Posted
Jul 15, 2026
Location
Lehi, UT
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A mid-level cybersecurity engineering role focused on owning vulnerability management, application security, and secure development practices within a SaaS event-management platform. Day-to-day work spans running and interpreting vulnerability scans, replicating and validating findings, managing a bug bounty program, embedding security into developer workflows, and overseeing incident tracking and endpoint security tooling across AWS environments. Suits someone with 3–5 years of hands-on technical security experience who can operate independently across engineering and IT teams.

Mid level · 3+ years · Remote · Full-time

Must have (2)
OWASP Top 10AWS
Nice to have (16)
Burp SuiteKali LinuxBugCrowdSonarqubeTenableBitsightOneTrustJiraSophosJAMFPDQBetterCloudPython, PowerShell or Shell ScriptingPCI-DSSISO 27001SOC 2

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 13,000 people nationally plausibly meet what this posting asks for (information security analysts). range 5,500–19,500

Applicant volume Heavy — This req sits in a large pool with little in its requirements to thin it, and auto-apply tools fire at everything in the occupation. Applying early and leading with the rare skills below is what gets read.

What the occupation pays Median $132,021 (middle half $99,961–$167,095).

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The posting explicitly describes this as a 'mid-level, autonomous role (not entry-level)' in the body text, but the title 'Cybersecurity Engineer' carries no level word — advertised seniority is therefore Unspecified. The stated 3–5 years of experience and scope (owning programs end-to-end within a single team) support a Mid classification.

US citizenship is a hard gate stated in the Required Skills section ('All candidates must be a US citizen').

All specific tools (Burp Suite, Kali Linux, BugCrowd, Sonarqube, Tenable, Bitsight, OneTrust, Jira, Sophos, JAMF, PDQ, BetterCloud) appear under the 'Preferred Experience & Tool Stack' heading and are explicitly framed as 'a massive plus', so they are preferred rather than required.

Scripting (Python, PowerShell, or Bash) is listed under Preferred as 'basic scripting skills' for automation — treated as preferred with the three options as interchangeable alternatives.

Security framework experience (PCI-DSS, ISO 27001, SOC 2) and certifications (Security+, CEH, GIAC, CISSP) are listed under Preferred; certifications are not emitted as named technology skills.

No compensation figures are provided in the posting.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗