About The Position

The Cybersecurity Engineer II in our Application Security Program plays a key role in enhancing the security program for a company and national brand that has been listed on the Fortune 100 Best Places to Work. We work in a collaborative environment where your ideas can help shape the direction and development of critical security capabilities. You will work with a team of talented professionals that are keenly focused on solving complex security challenges and supporting product innovation with technology. Our team is not afraid to fail fast, learn and are motivated to find ways to make things better. This role requires you to be flexible, adaptable to change, and willing to ask questions that lead to security posture improvements for CarMax.

Requirements

  • Strong fundamentals in general Cybersecurity concepts with an interest in learning more about and contributing to Application Security
  • Functional understanding with at least one coding or scripting language: e.g. PowerShell, Python, .Net, Javascript, C#
  • Excellent analytical, troubleshooting, and problem-solving skills and performs well in high pressure or stressful situations
  • Excellent organization and time management skills
  • Excellent communication skills to include, but not limited to, verbal and written communication; delivering organized presentations; able to tailor message to the audience; and facilitate group discussions with diplomacy and seek diverse opinions
  • Ability to effectively estimate the efforts of others and the impact required to accomplish requested tasks/projects

Nice To Haves

  • Functional proficiency with at least one coding or scripting language
  • Experience performing dynamic application security testing (DAST) using open source and commercial tools.
  • Experience performing static security code analysis (SAST) and providing relevant recommendations to stakeholders.
  • Experience integrating security into the container lifecycle, including image assurance, Kubernetes posture management, secrets management, and runtime threat detection
  • Knowledge of developer tools like GitHub, Azure DevOps, and TeamCity.
  • Experience with Public Cloud: e.g. Azure, AWS, GCP.
  • Understanding of development and product teams and DevSecOps best practices.
  • CISSP certification preferred but not required.

Responsibilities

  • Implement, develop, operate, and improve Cybersecurity solutions utilized for to progress Application Security at CarMax including static and dynamic analysis, API Sec, and Container Sec.
  • Provide functional and technical expertise on projects that have application security implications for our Company.
  • Learn and understand the full portfolio of Cybersecurity capabilities at CarMax and how they work together to secure or enterprise.
  • Independently drive tasks and projects to successful completion through effective time and schedule management, customer interaction, and cross functional team interaction
  • Effectively triage support problems and respond with the appropriate level of urgency
  • Participate in a 24x7 on-call weekly rotation as scheduled, and the ability to perform after hours support as needed. Current rotation is about 3 weeks per year.

Benefits

  • Paid sick time
  • Vacation time
  • Holiday time
  • Holiday Premium Pay
  • Paid time away with no specified limit as needed for sick, bereavement, jury duty, holidays, floating holiday, etc. subject to manager approval.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service