Job Category: Information TechnologyRequisition Number: CYBER(phone number removed)Description Position Summary You are the kind of engineer who stays curious when no one is watching. You read threat intelligence because understanding the adversary is how you stay ahead of them. When something is compromised, you run toward it. You care more about getting it right than getting credit for it. You have likely seen what happens when strong security talent gets trapped in slow, rigid organizations where good ideas stall, risk decisions lack context, and the work feels disconnected from the people it is supposed to protect. This is not that team. Delta Defense powers the USCCA , the nation's largest self-defense membership organization. We protect life, freedom, and the financial security of responsible American gun owners. The trust, data, products, and platforms behind that mission must be protected with discipline and precision. Our Information Security team exists to secure the perimeter, guard our crown jewels, and build the resilience that allows our people, business, and members to operate with confidence. As our Cybersecurity Engineer, you will help build and advance a modern security engineering program across product engineering, cloud infrastructure, and analytics teams. We believe great security is more JUDO than SUMO: skill over force, leverage over friction, precision over noise. That means we do not win by slowing teams down. We win by understanding the business, collaborating with teams early, reducing risk intelligently, and helping Delta Defense move faster with confidence. Your work will be visible. Your judgment will matter. And the members depending on us will be safer because you showed up. If that is the standard you already hold yourself to, we want to hear from you! Duties & ResponsibilitiesApplication Security & Secure SDLC: Lead application security across the software development lifecycle by partnering with Engineering and DevOps to integrate security into design, development, testing, and deployment. Perform threat modeling, secure design reviews, code reviews, and implement automated SAST, DAST, SCA, and secrets detection within CI/CD pipelines while enabling engineering teams to deliver secure software at scale.Web App & API Security: Design, implement, and continuously improve web application and API security controls across the enterprise. Develop and tune WAF policies, conduct API security assessments, identify business logic vulnerabilities, and establish secure-by-design standards that reduce risk without unnecessarily impacting developer velocity.Penetration Testing & Offensive Security: Plan and execute penetration testing activities against web applications, APIs, cloud environments, and supporting infrastructure. Validate vulnerabilities through manual testing, prioritize findings based on business risk, and partner with engineering teams to ensure timely remediation and measurable risk reduction.AI Security & Governance: Develop and enforce security controls governing enterprise AI platforms and internally developed AI capabilities. Establish policies for data classification, model usage, access controls, audit logging, and secure integration of AI technologies while ensuring responsible adoption across the organization.AI Threat Modeling & Security Engineering: Perform security assessments of Retrieval-Augmented Generation (RAG), agentic AI systems, MCP integrations, and large language model applications. Identify and mitigate risks including prompt injection, indirect prompt injection, insecure tool use, excessive agent permissions, model abuse, and data leakage using industry guidance such as the OWASP LLM Top 10 and MITRE ATLAS.IR & Detection Engineering: Contributes to technical investigation and response activities for security incidents including threat analysis, digital forensics, containment, eradication, and root cause analysis.Vulnerability Management: Operate a risk-based vulner
Not specified in the original listing.
Not specified in the original listing.