Wolfe, LLC · Pittsburgh, PA

Salary
$110,000–$120,000
Posted
Jun 29, 2026
Location
Pittsburgh, PA
Last confirmed open
Jul 20, 2026

What this job asks for AI summary

A hands-on security engineering role focused on embedding security throughout the software development lifecycle at a FinTech company. Day-to-day work covers code review, SAST/DAST testing, penetration testing, and integrating automated security tooling into CI/CD pipelines, alongside managing a vulnerability management program and bug bounty program. Suited to developers transitioning into security or early-career application security engineers comfortable with secure coding principles and cloud/container environments.

Mid level · 2+ years · Pittsburgh, PA · Full-time

Pay in the description: $110,000–$120,000

Must have (6)
SAST or DASTCI/CDGitHub, GitLab, Jenkins or Aws CodepipelineOWASP Top 10penetration testingthreat modeling
Nice to have (8)
Snyk, Semgrep or CycodeWAFAPI securityvulnerability managementDSOMM or BsimmLLMsCISSP, Oscp, Gcsa or CsslpAWS

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

Roughly 35 people in the Pittsburgh, PA area plausibly meet what this posting asks for (information security analysts). range 15–55

Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.

What won't set you apart
CI/CD45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $103,630 (middle half $81,280–$130,050). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (9)

The JD explicitly accepts equivalent experience in lieu of a Bachelor's degree, so no formal degree is hard-gated.

SAST, DAST, and SCA are listed together as a single capability area throughout the posting; SAST is used as the primary name with DAST captured separately since both are called out individually in responsibilities.

Snyk, Semgrep, and Cycode appear under responsibilities as illustrative examples ('such as'), making them preferred rather than hard gates on any specific tool.

GitHub, GitLab, Jenkins, and AWS DevOps are listed as interchangeable CI/CD platform examples ('such as') in the requirements section; GitHub is used as the primary with the others as alternatives.

Certifications (CISSP, OSCP, GCSA, AWS Security Specialty, CSSLP) are explicitly called out as 'a plus, not a requirement' — listed as preferred accordingly.

DSOMM and BSIMM are framed as things the candidate is 'eager to learn' with 'deep prior experience' described as 'a plus, not a requirement' — listed as preferred.

The role is explicitly 5-days-per-week onsite in Pittsburgh, PA; remote is not available.

The posting is positioned as early-to-mid career ('2+ years', growth-oriented framing), supporting a Mid seniority classification despite the breadth of responsibilities.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Bot Management, secrets management.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗