Principal Cybersecurity Engineer/ Jr Cybersecurity Architect

Comspark groupBellevue, WA
Hybrid

About The Position

The Principal Cybersecurity Engineer will ensure that client’s software, systems, and infrastructure are designed and implemented to the highest security standards. This role involves performing technical security assessments, code reviews, and vulnerability testing to identify and remediate risks. The engineer will collaborate with client teams and partners to enhance security posture and drive vision and results across various technologies including mobile devices, IoT devices, enterprise applications, cloud, big data, and core/carrier network technologies. This position acts as a subject matter expert and a principal security advisor to cross-functional teams for the successful delivery of projects and services.

Requirements

  • Cyber Security: 10+ Years
  • Java, frameworks, python, Nodejs: 5+ Years
  • Threat Modelling like STRIDE, PASTA, TRIKE, ATTACK TREE, DREAD, KILL CHAIN, CAPEC: 5+ Years
  • SSL: 8+ Years
  • Firewall policy design: 5+ Years
  • Vulnerability analysis & mitigation: 5+ Years
  • Understanding load balancers (ex – A10, F5), firewalls (ex – CheckPoint), Venafi, MDM (ex - Mobile Iron), Cloud (ex - AWS, Azure), Malware Protection (ex -FireEye), Advanced Persistent Threats (ex - Damballa), Privileged Accounts (ex – CyberArk), SIEM (ex – ArcSight), Log & Event (ex – Splunk), Intrusion IDS/IPS (ex – Symantec): 5+ Years
  • Cloud Platform (ex – PCF, Docker), Scanning (ex – Qualys), AppSec (ex - Veracode): 5+ Years
  • Significant experience with the analysis of underlying technologies that form the solution necessary for the application of threat identification, analysis, and thread model design.
  • Significant experience with implementation of various threat modeling approaches pertaining to one or more of the following STRIDE, PASTA, TRIKE, ATTACK TREE, DREAD, KILL CHAIN, CAPEC.
  • Deep application security knowledge: Focus on expertise in secure coding practices, vulnerability management (SAST/DAST/IAST), and application security testing (OWASP Top 10) methodologies.
  • Mobile Application threat model, Cyber Threat Tree, and data flow diagram.
  • Subject matter expert in multiple facets of network & information security, including Firewall policy design, SSL Certificate management, vulnerability analysis & mitigation, and other topics as assigned.
  • Advanced understanding of IP/Security solutions & technologies applicable to the Wireless Network Architecture.
  • Subject matter expert in all facets of network & information security, including Firewall policy design, SSL Certificate management, vulnerability analysis & mitigation, and other topics as assigned.
  • Ability to create technical specification and requirements and work independently and with no direction/supervision.
  • Able to quickly adapt to new or evolving technologies related to new product & services requiring validation or research.
  • Strong verbal and communication skills with diverse cross functional groups.
  • Ability to present advanced concepts to leadership, peers, and others in subordinate roles.
  • Understanding load balancers (ex – A10, F5), firewalls (ex – CheckPoint), Venafi, MDM (ex - Mobile Iron), Cloud (ex - AWS, Azure), Malware Protection (ex -FireEye), Advanced Persistent Threats (ex - Damballa), Privileged Accounts (ex – CyberArk), SIEM (ex – ArcSight), Log & Event (ex – Splunk), Intrusion IDS/IPS (ex – Symantec), Cloud Platform (ex – PCF, Docker), Scanning (ex – Qualys), AppSec (ex - Veracode).
  • Advance knowledge of Scripting tools (Python/Perl/Shell/HTML/PHP).
  • Knowledge of federal & compliance regulations e.g. SOX, PCI & CPNI.
  • Working knowledge of web application development, RESTful APIs, and skills in Java, frameworks, python, Nodejs.
  • Experience with mobile applications, and handset security.

Responsibilities

  • Leads information security review of new technologies, designs, and remediation planning efforts.
  • Collaborates with Engineering & Operations Teams to address security vulnerabilities found via PSIRTs, scans, or breaches.
  • Investigates and/or leads identifying security needs & recommends plans/resolutions.
  • Implements, tests & monitors info security improvements.
  • Performs technical security assessments, code reviews, and vulnerability testing.
  • Works closely with other client Engineers to design and build proactive methods to enhance security posture.
  • Acts as a Principal security advisor to cross-functional teams for the successful delivery of projects or services.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service