• Skip to primary navigation
  • Skip to main content
  • Skip to footer

Side Hustles

Side Hustles

Side Hustles For All

  • Best Side Hustles
    • Woman sitting on a pile of coins and working on a laptop surrounded by icons representing different side hustle ideas

      31 Best Side Hustles to Earn Extra Money in 2026

    • Bicycle courier delivering food for their side hustle.

      What Is a Side Hustle?

    • Remote worker sitting at his desk making money from home

      18 Ways to Make Money from Home (Online and Offline Jobs)

    • By Category
      • Arts & Crafts
      • Business Services
      • Caregiving
      • Creative Services
      • Digital Freelance Services
      • View All
    • By Lifestyle
      • I’m introverted
      • I’m a man
      • I’m a woman
      • I’m a stay-at-home mom
      • I’m unique
      • View All
    • By Profession
      • Artists & Creatives
      • Musicians
      • Nurses
      • Physicians
      • Teachers
      • View All
    • By Age Group
      • College Students
      • Teens
      • Age 50+
      • Seniors
      • View All
    • By Skills & Interests
      • Get Paid to Lose Weight
      • Get Paid to Play Games
      • Get Paid to Read
      • Get Paid to Sleep
      • Get Paid to Travel
      • View All
  • Best Gig Apps
    • Freelance worker popping out of a phone screen and considering gig apps on the App Store and Google Play

      Top 6 Gig Apps to Make Real Cash in 2026

    • Smartphone surrounded by the icons of different money-making apps

      Top 10 Best Money-Making Apps to Try in 2026

    • two teenagers using job apps on a phone and laptop

      19 Job Apps for Teens to Find Jobs and Make Money

    • By Gig Type
      • Cashback
      • Data Entry
      • Delivery
      • Games
      • Product Testing
      • View All
    • By Payment Method
      • Bingo Games that Pay to Cash App
      • Games that Pay Real Money
      • Games that Pay to Cash App
      • Games that Pay via PayPal
      • Surveys that Pay to Cash App
      • View All
    • By Benefits
      • $20 Signup Bonuses
      • $25 Signup Bonuses
      • $50 Signup Bonuses
      • Best Signup Bonuses
      • Instant Signup Bonuses
      • View All
    • By Skills & Interests
      • Driving
      • Losing Weight
      • Playing Games
      • Product Testing
      • Watching Ads
      • View All
  • Job Hunting
    • Freelance worker browsing a job post on a freelance job board.

      23 Job Boards You Can Use to Find Remote Work

    • Freelance writer sitting at her laptop working on a project

      15 Best Remote Jobs That Require No Paid Work Experience

    • Teenager sitting at laptop working an online job

      14 Online Jobs for Teens (With No Experience)

    • Freelancing
      • Freelance Writing Sites
      • Freelance Writing Job Boards
      • Freelance Writing Platforms
      • View More
    • Gig & Shift Work
      • Gig Work Apps
      • On-Demand Work Apps
      • Shift Work Apps
      • View More
    • GPT (Get Paid To)
      • Microtasking
      • Product Testing
      • Survey Taking
      • View More
    • Remote Working
      • Best Remote Job Boards
      • Top 15 Remote Jobs
      • View More
  • Job Board
    • Work Schedule
      • Part-Time Jobs
      • Per-Diem Jobs
      • Go Search
    • Work Environment
      • Hybrid Jobs
      • Remote Jobs
      • Go Search
    • Employment Type
      • Contractor Jobs
      • Internship Jobs
      • Temporary Jobs
      • Go Search
    • Job Title
      • Accounting Jobs
      • Data Entry Jobs
      • Nursing Jobs
      • Online Teaching Jobs
      • Software Engineer Jobs
      • Go Search
    • State
      • California Jobs
      • Florida Jobs
      • New York Jobs
      • Pennsylvania Jobs
      • Texas Jobs
      • Go Search
    • City
      • Chicago, IL
      • Houston, TX
      • Los Angeles, CA
      • New York City, NY
      • Phoenix, AZ
      • Go Search

Home Flexible Job Board Senior Security Engineer

Salary Unstated 72d ago

Senior Security Engineer

Boost your chances before you apply.

  • ✨ Apply 10x Faster Free

    It takes 30+ tailored applications to land jobs like this one. We'll help you get that done in 1 hour.

    No Credit Card Required

  • Proceed to Application Go directly to the company's job page to apply.
Logo

Mach7 Technologies

Burlington, VT, US

Full-time Permanent Remote

✨ Apply 10x Faster

Analyze your resume for missing keywords, then one-click optimize it. Don't be anything less than a 100% match candidate.

Free

No Credit Card Required

Summary

Lead application security efforts across the product portfolio by integrating security into every phase of the software development lifecycle. This includes conducting threat modeling, managing software supply chain risks, and driving vulnerability remediation across web, mobile, and embedded software.

Job Description

Title: Senior Security Engineer

Team: Engineering

Location:
Remote-Friendly

About the Role:

We're looking for a Senior Security Engineer to
lead application security efforts across our product portfolio, spanning web
applications, APIs, mobile, embedded software, and shipped product
deliverables. You'll be embedded in the engineering organization,
partnering with product and platform teams to bake security into every phase
of the software development lifecycle, not bolt it on at the end.

A critical part of this role is developing
and maintaining a deep understanding of
our product attack surface, how components interact, what's
exposed, and where real risk lives. That understanding is what transforms
security tooling output into prioritized, meaningful action across threat
modeling, vulnerability management, and supply chain risk.

This is a high-impact role for someone who is equally
comfortable reading source code, threat modeling a new
microservice, and coaching a developer through a secure code review.

What You'll Do

Application Security & Secure SDLC 

  • Own
    and evolve the AppSec program across the entire SDLC — from design reviews
    to post-deployment monitoring — for web, API, mobile, and shipped product
    deliverables 
  • Build
    and maintain a living model of the product attack surface —
    mapping trust boundaries, data flows, exposed interfaces, and high-value
    targets — and use it to drive prioritization across all security
    workstreams 
  • Conduct
    threat modeling and architecture security reviews for new features,
    services, and product releases across all delivery channels 
  • Perform
    manual and automated secure code reviews across multiple languages
    (e.g. Python, Go, TypeScript, C/C++) 
  • Integrate
    and tune SAST, DAST, and SCA tooling within CI/CD pipelines (GitHub
    Actions, Jenkins, or equivalent) 
  • Triage
    and drive remediation of vulnerabilities surfaced through scanning, bug
    bounty, and pen tests 
  • Develop
    and maintain a library of security standards, patterns, and
    guardrails applicable across product types 

Third-Party & Supply Chain Security 

  • Own
    the Software Bill of Materials (SBOM) program — define generation,
    storage, and consumption processes across all product lines 
  • Establish
    and maintain policies for evaluating, onboarding, and
    continuously monitoring third-party dependencies and open-source
    components 
  • Triage
    and prioritize CVEs and license risks surfaced through SCA tooling,
    driving timely remediation with engineering teams 
  • Define
    processes for responding to upstream supply chain incidents
    (e.g. compromised packages, malicious dependencies) 
  • Collaborate
    with procurement and legal to assess security risk of third-party vendors
    and integrations 
  • Contribute
    to industry frameworks and internal standards around software supply chain
    security (SLSA, NIST SSDF, or equivalent) 
  • Act
    as a trusted security advisor embedded within product engineering
    squads 
  • Lead
    security training, lunch-and-learns, and developer education
    initiatives 
  • Collaborate
    with the Platform team on secrets management, identity, and access
    controls 
  • Work
    with the GRC function to translate compliance requirements (SOC 2, ISO
    27001) into engineering controls 

Incident & Vulnerability Management 

  • Participate
    in the security on-call rotation and lead security incident response
    investigations 
  • Drive
    root cause analysis and communicate findings clearly to engineering
    leadership 
  • Build
    and maintain metrics and dashboards to track the health of the
    AppSec program 
  • Participate
    as a member of the
    Cybersecurity council, representing development in the
    organization. Report weekly on new threat intelligence as it relates
    to product security, and any actions that are being taken to remediate new
    findings.  

What
We're Looking For
Required

·         5+ years of experience in security engineering,
with a strong AppSec focus 

·         Hands-on experience with threat modeling
frameworks (STRIDE, PASTA, or similar) 

·         Proficiency with common AppSec
tooling: Semgrep, Snyk, Burp Suite, OWASP ZAP, or equivalents 

·         Deep understanding of web application
vulnerabilities (OWASP Top 10, API security, auth/authz flaws) 

·         Ability to read and reason about code in at
least two languages; prior development experience a plus 

·         Experience with software supply chain security —
SBOM generation and analysis (CycloneDX, SPDX), SCA tooling, and dependency
risk management 

·         Strong written and verbal communication skills —
you can explain risk to both engineers and executives 

      Preferred 

·         Experience with cloud-native
environments (AWS, GCP, or Azure) and container/Kubernetes security 

·         Familiarity with software supply chain
frameworks such as SLSA, NIST SSDF, or OpenSSF Scorecards 

·         Contributions to open-source security
tooling or security research 

·         Relevant certifications: OSCP, CSSLP,
GWEB, or similar 

We recognize
that candidates bring diverse experiences and backgrounds. If you don’t meet
every requirement, we still encourage you to apply! Many strong candidates
don’t check every box. We value potential, growth, and impact as much as experience.

 

Who You Are

·         Experienced security professional with
a strong background in application security and secure software development.

·         Skilled at threat modeling, secure code
reviews, and identifying real-world risks across complex systems.

·         Knowledgeable in web, API, mobile, and
software supply chain security best practices.

·         Comfortable working with developers to
embed security throughout the SDLC.

·         Proficient with security testing and
vulnerability management tools, including SAST, DAST, and SCA solutions.

·         Strong communicator who can translate
technical risks into actionable recommendations.

·         Collaborative, proactive, and driven to
improve both product security and engineering security culture.

·         Passionate about continuous learning,
emerging threats, and helping teams build secure products at scale.

About Mach7:

Mach7
Technologies helps healthcare organizations bring all their medical images
together in one place so they can be easily accessed, shared, and used to
support patient care. Our enterprise imaging solutions, including a
vendor-neutral archive (VNA), enterprise PACS, the eUnity enterprise
diagnostic viewer, and teleradiology workflows, consolidate imaging from
across the enterprise into a single, accessible source of truth. Built on
open standards, including DICOM and a configurable HL7 engine, and free from
proprietary data lock-in, our technology lets providers store, view, and
share images on their own terms. The result is a simpler, more connected
imaging environment that puts data ownership back where it belongs: with the
people delivering care. Your data, your infrastructure, your choice.

AI Expectations

·         Integrate AI
into daily work
— leverage AI tools to enhance
efficiency, elevate quality, and support smarter, faster decision-making.

·         Apply
critical human judgment to AI output
— review,
validate, and take full accountability for AI-assisted work, ensuring accuracy
and reliability.

·         Continuously
improve through AI
— proactively identify
opportunities to optimize processes, rethink workflows, and challenge existing
approaches rather than maintaining the status quo.

·         Use AI
responsibly and ethically
— safeguard
sensitive information, adhere to company guidelines, and actively identify
risks such as bias, inaccuracies, or misuse.

CLIMBS Culture Code

At Mach7, our culture is rooted in CLIMBS, a mindset
that guides how we show up, collaborate, and grow each day. More than just a
set of values, CLIMBS represents the standard we hold ourselves to and the way
we approach our work, our teams, and our impact.

C — Customer First
Every decision starts with the customer’s perspective. Success = customer
outcomes and satisfaction.

L — Learn & Grow
Curiosity keeps us climbing. We embrace continuous learning, share knowledge
freely, and invest in each other’s development.

I — Innovate for Impact
We value meaningful, outcome-driven innovation over activity. We challenge the
status quo and align behind real customer benefit.

M —
Minimize Complexity & Move
As complex as needed but no more. Agility beats bureaucracy. We move
fast and stay focused on what matters.

B —
Build Good Sh*t
(Yes, intentionally memorable.) Extreme ownership, craftsmanship, and pride in
high-quality work.

S — Everyone Sells
Not just Sales—Engineering, Product, Support, Finance, IT. We align behind
commercial success to enable company success

About the company

Mach7 Technologies

At Mach7, our purpose is simple: to deliver to healthcare professionals the tools they need to help their patients achieve better health outcomes. Every day, medical practitioners face the challenge of bringing together an immense amount of patient data from multiple disparate sources while also finding a way to make sense of it. They must contend with issues like non-consolidated image storage, labor-intensive and inefficient workflows, and multiple viewers for different specialties and image types. With these obstacles in mind, Mach7 has built innovative solutions from the ground up that can integrate multiple systems, enable clinical collaboration, deliver vendor neutral archiving, provide enterprise-wide universal viewing, modernize legacy PACS, and more. Mach7 is focused on removing the technology limitations that inhibit the free flow of patient information and access to the complete patient medical record.

We differ from many other companies in the industry by building an integrated imaging ecosystem where all technologies work together in harmony. Because we are built as an integration platform first, we give you the freedom to use the technologies that are important to your physicians and patients, even if they are from another vendor. This also means we offer the independence and flexibility to deploy these as individual components or a comprehensive end-to-end enterprise imaging platform. Through this, we help organizations increase their efficiency, achieve profound operational cost savings, leverage their existing IT investments, improve the experience for patients and medical professionals, and, ultimately, support healthier outcomes.

Company size

51-200 employees

Industry

Medical Equipment Manufacturing

Org type

Public Company

Headquarters

Burlington, Vermont

Apply Now

About the company

Mach7 Technologies

At Mach7, our purpose is simple: to deliver to healthcare professionals the tools they need to help their patients achieve better health outcomes. Every day, medical practitioners face the challenge of bringing together an immense amount of patient data from multiple disparate sources while also finding a way to make sense of it. They must contend with issues like non-consolidated image storage, labor-intensive and inefficient workflows, and multiple viewers for different specialties and image types. With these obstacles in mind, Mach7 has built innovative solutions from the ground up that can integrate multiple systems, enable clinical collaboration, deliver vendor neutral archiving, provide enterprise-wide universal viewing, modernize legacy PACS, and more. Mach7 is focused on removing the technology limitations that inhibit the free flow of patient information and access to the complete patient medical record.

We differ from many other companies in the industry by building an integrated imaging ecosystem where all technologies work together in harmony. Because we are built as an integration platform first, we give you the freedom to use the technologies that are important to your physicians and patients, even if they are from another vendor. This also means we offer the independence and flexibility to deploy these as individual components or a comprehensive end-to-end enterprise imaging platform. Through this, we help organizations increase their efficiency, achieve profound operational cost savings, leverage their existing IT investments, improve the experience for patients and medical professionals, and, ultimately, support healthier outcomes.

Company size

51-200 employees

Industry

Medical Equipment Manufacturing

Org type

Public Company

Headquarters

Burlington, Vermont

Footer

sidehustles.com
Facebook Twitter Instagram LinkedIn Reddit TikTok YouTube

Show Me The Money

  • Side Hustle Basics
  • Side Hustle Job Board (Remote & Part-Time Jobs)
  • Gig App Reviews
  • Job Hunting
  • Manage Your Money
  • The Gig Apple: News & Events

Company

  • About Us
  • Contact Us
  • Become a Contributor
  • Advertising & Sponsorships
  • Partner With Us
  • Editorial Guidelines

Side Hustles © All rights reserved

  • Privacy Policy
  • Terms of Service

Thanks for using our free job board

Your review would mean a lot to us.

If you love that we're just giving away remote jobs for free with no paywall, please spread the word. (You will need to create an account on Trustpilot, for which we'll be eternally grateful.) Good luck out there!

Leave a Review Not yet. Send me to the job post.