Staff InfoSec Engineer
Houghton Mifflin HarcourtMatch Score
Against your primary resumeLogin to See Your Match Score
Create a free account or log in to unlock your CV match score across:
Protocol Intelligence
Data-driven signals on your job's competitivenessNiche GovRAMP/application security requirements reduce candidate pool despite mid-level seniority.
Strong GovRAMP and compliance emphasis increases industry-specific sensitivity despite transferable cloud security skills.
Explicit 5–8 years and mandatory application/cloud security plus GovRAMP experience create strict screening filters.
Job Description
Structured overview of role & requirementsAbout This Role
Implement and monitor cloud and application security controls across AWS/Azure and on-prem environments, ensuring compliance with GovRAMP/NIST 800-53 requirements.
Manage application security assessments (SAST, DAST, SCA), vulnerability management, and remediation tracking throughout the SDLC and CI/CD pipelines.
Collaborate with Engineering, DevOps, Architecture, Risk, and Compliance teams to integrate security into development and cloud operations, supporting continuous monitoring and evidence collection.
Minimum Requirements
5+ years in Application Security, Product Security, or related security engineering roles.
Hands-on experience with AWS and/or comparable cloud environments and cloud security frameworks like NIST 800-53.
Proficiency in application security tools and practices: SAST, DAST, SCA, web & API security testing aligned with OWASP Top 10, secure code review, and vulnerability management.
Programming/scripting skills in Python, Java, JavaScript, PowerShell or similar for automation and security process integration.
Ideal Candidate Profile
Experienced in driving GovRAMP/NIST 800-53 initiatives, including control implementation, continuous monitoring, and compliance evidence management.
Skilled at collaborating across multi-disciplinary teams (Engineering, DevOps, Architecture, Risk, Compliance) to embed security in cloud-native and hybrid architectures.
Strong operator in DevSecOps with deep understanding of CI/CD pipeline integration, application security testing, and automation using scripting languages.
