Information Security & Platform Engineer

Kirin Consulting LLC
  • NY
  • $80,000–$105,000 Per Year
3 days ago

Job Description

<

\/head>

This is a remote position.<\/p>

<\/p>

<\/colgroup>

A note on applications - please read before applying<\/span><\/span><\/b><\/span><\/span>

<\/p>

We use AI tools heavily in our day-to-day engineering, and we expect you to as well. A rÃsumà is different. It is the one artifact where we want your actual voice, your real judgment, and specifics only you can supply.<\/span><\/span><\/span><\/span>

<\/p>

We do not review AI-generated rÃsumà summaries or profiles. They are generic, interchangeable, and tell us nothing about the person behind them. Applications with an obviously AI-written summary will be rejected outright, without further review. Write it yourself.<\/span><\/span><\/span><\/span>

<\/p><\/td> <\/tr> <\/tbody> <\/table> <\/div>

<\/div>

Overview<\/span><\/span><\/b><\/span><\/span>

<\/p>

Dealer Alchemist builds the digital advertising platform that powers automotive dealer websites across the country. We run a mature production WordPress platform serving our live dealer sites, alongside a growing cloud-based platform.<\/span><\/span><\/span><\/span>

<\/p>

We are looking for an early-career engineer who wants to build a career in application and infrastructure security, and who already has real hands-on WordPress and PHP experience. That combination matters here: the most valuable security work on our platform is understanding plugin and theme code well enough to know what is actually exploitable, keeping a large fleet of sites patched and hardened, and closing the gap between a scan finding and a working fix.<\/span><\/span><\/span><\/span>

<\/p>

This is a growth role with genuine responsibility, not a shadowing role. You will run day-to-day security operations and contribute directly to the platform. You will work under engineering leadership and alongside senior engineers who own risk decisions and lead incident response - you set the pace on the work, they backstop the judgment calls, and your scope expands as you demonstrate it.<\/span><\/span><\/span><\/span>

<\/p>

How the role splits<\/span><\/span><\/i><\/b><\/span><\/span>

<\/p>

Roughly 60% security and 40% platform engineering. The platform work is not filler - it keeps you fluent in the codebase you are securing, and it is where a lot of remediation actually lands. Your security objectives are committed and tracked alongside platform work each sprint, so proactive security does not get crowded out by day-to-day requests.<\/span><\/span><\/span><\/span>

<\/p>

What You'll Do<\/span><\/span><\/b><\/span><\/span>

<\/p>

Security<\/span><\/span><\/i><\/b><\/span><\/span>

<\/p>

  • Vulnerability management<\/span><\/span><\/b><\/span><\/span> - run scans, interpret results, triage findings by real-world exploitability, and drive remediation to closure with the engineers who own the code.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • WordPress and dependency security<\/span><\/span><\/b><\/span><\/span> - own the patch cadence for core, plugins, themes, and third-party libraries; identify risky or abandoned dependencies and make the case for replacing them.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Apply and maintain hardening baselines across Linux servers, web server configuration, and application settings.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Help implement security controls: access reviews, secrets management, security logging and alerting, and TLS / certificate hygiene.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Perform security-focused code review on PHP and JavaScript changes, and help triage findings from automated scanning in the pipeline.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Participate in incident response<\/span><\/span><\/b><\/span><\/span> - monitoring, triage, evidence gathering, documentation, and the lessons-learned process, working alongside the senior engineers who lead it.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Support SOC 2 compliance<\/span><\/span><\/b><\/span><\/span> - evidence collection, control documentation, and policy support.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Track vulnerabilities and threats relevant to our stack, and translate them into prioritized, actionable tickets.<\/span><\/span><\/span><\/span>

<\/p><\/li> <\/ul>

Platform Engineering & Operations<\/span><\/span><\/i><\/b><\/span><\/span>

<\/p>

  • Write and review PHP and JavaScript for the WordPress platform, with a focus on security fixes, hardening, and remediation work.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Diagnose and resolve WordPress, PHP, and MySQL issues alongside the development and support teams.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Assist with releases, deployments, and client site launches using internal automation scripts.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Administer Ubuntu / Debian Linux servers: patching, monitoring, nginx configuration, log analysis, and routine maintenance.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Work with DNS records, domain configuration, and SSL / TLS certificates across client site environments.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Build small automations and scripts that reduce manual security and operations overhead.<\/span><\/span><\/span><\/span>

<\/p><\/li> <\/ul>

<\/div><\/span>

Requirements<\/h3> 1-3 years of professional experience in software development, systems administration, or IT with a demonstrated security focus. Strong internship, lab, home-lab, or CTF work counts toward this.<\/span><\/span><\/span><\/span>

<\/p><\/li> Hands-on WordPress and PHP experience<\/span><\/span><\/b> - you can read plugin and theme code, trace a bug through it, and write a fix. This is a hard requirement, not a nice-to-have.<\/span><\/span><\/span><\/span>

<\/p><\/li> Solid security fundamentals: OWASP Top 10, authentication and authorization concepts, encryption and TLS basics, and common web attack vectors.<\/span><\/span><\/span><\/span>

<\/p><\/li> Comfortable on the Linux command line: file system, process management, and log analysis.<\/span><\/span><\/span><\/span>

<\/p><\/li> Scripting ability in Bash and / or Python.<\/span><\/span><\/span><\/span>

<\/p><\/li> A working understanding of web application architecture - HTTP, DNS, TLS, APIs, and how a request actually reaches your code.<\/span><\/span><\/span><\/span>

<\/p><\/li> Working knowledge of MySQL: writing queries and debugging data issues.<\/span><\/span><\/span><\/span>

<\/p><\/li> Strong written communication - security work is documentation-heavy, and clear writing is a core part of the job.<\/span><\/span><\/span><\/span>

<\/p><\/li> Genuine curiosity and a methodical approach. We would rather hire someone who digs until they understand the root cause than someone who already knows every tool.<\/span><\/span><\/span><\/span>

<\/p><\/li> Must reside in the U.S. and be authorized to work without sponsorship.<\/span><\/span><\/span><\/span>

<\/p><\/li> <\/ul> Nice to Have<\/span><\/span><\/b><\/span><\/span>

<\/p> Security certifications (e.g., CompTIA Security+, eJPT) or active pursuit of one.<\/span><\/span><\/span><\/span>

<\/p><\/li> Hands-on experience with vulnerability scanners (e.g., Nessus, OpenVAS, Trivy, WPScan) or centralized logging / SIEM concepts.<\/span><\/span><\/span><\/span>

<\/p><\/li> Exposure to SOC 2 or another compliance framework.<\/span><\/span><\/span><\/span>

<\/p><\/li> Experience managing nginx: server blocks, proxy configs, rewrites, and SSL.<\/span><\/span><\/span><\/span>

<\/p><\/li> Familiarity with a major cloud platform (e.g., GCP or AWS) and cloud IAM basics.<\/span><\/span><\/span><\/span>

<\/p><\/li> Exposure to containers and container security.<\/span><\/span><\/span><\/span>

<\/p><\/li> CI/CD familiarity (e.g., GitHub Actions) and pipeline security tooling - dependency scanning, SAST, DAST.<\/span><\/span><\/span><\/span>

<\/p><\/li> Any exposure to modern TypeScript-based backend or frontend frameworks.<\/span><\/span><\/span><\/span>

<\/p><\/li> Proficiency using AI-assisted tools in engineering and security workflows, with sound judgment on privacy and data handling.<\/span><\/span><\/span><\/span>

<\/p><\/li> <\/ul> What Success Looks Like (First 90 Days)<\/span><\/span><\/b><\/span><\/span>

<\/p> A documented inventory of our production surfaces and the known security gaps on each, ranked by actual exposure rather than raw scanner severity.<\/span><\/span><\/span><\/span>

<\/p><\/li> A running vulnerability management cycle - scan, triage, remediate, verify - on a predictable cadence.<\/span><\/span><\/span><\/span>

<\/p><\/li> A consistent patch cadence for WordPress core, plugins, and dependencies across the fleet, with the riskiest gaps closed first.<\/span><\/span><\/span><\/span>

<\/p><\/li> Several security fixes shipped by you, end to end, from finding to verified remediation.<\/span><\/span><\/span><\/span>

<\/p><\/li> Clear documentation of what we run, what protects it, and what still needs attention.<\/span><\/span><\/span><\/span>

<\/p><\/li> <\/ul> Growth Path<\/span><\/span><\/b><\/span><\/span>

<\/p> This role is designed to grow. As you build depth, the scope expands toward owning the vulnerability management program outright, leading incident response, and taking on security architecture input for new work. We will support relevant training and certification along the way.<\/span><\/span><\/span><\/span>

<\/p> <\/div><\/span>

Benefits<\/h3>

Compensation & Benefits<\/span><\/span><\/b><\/span><\/span>

<\/p>

  • Remote - work from anywhere in the U.S.<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Unlimited PTO - performance-based flexibility<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • 401(k) with employer matching<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Comprehensive healthcare - medical, dental, and vision<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Paid professional development<\/span><\/span><\/span><\/span>

<\/p><\/li>

  • Salary - $80,000 - $105,000<\/span><\/span><\/span><\/span>

<\/p><\/li> <\/ul>

About Dealer Alchemist<\/span><\/span><\/b><\/span><\/span>

<\/p>

Dealer Alchemist is a digital advertising agency specializing in the automotive industry. We build and operate the platforms that power dealer websites and advertising campaigns at scale, combining deep domain expertise with modern engineering practices.<\/span><\/span><\/span><\/span>

<\/p>

<\/div><\/span>

<\/body> <\/html>

Numbers & Facts

LocationNY
Salary$80,000–$105,000 Per Year

Skills

  • Access Controlunmatched
  • Advertising Agenciesunmatched
  • Amazon Web Services (AWS)unmatched
  • Analysis Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Artificial Intelligence (AI)unmatched
  • Automotive Industryunmatched
  • Bash Scriptingunmatched
  • Cadenceunmatched
  • Cloud Computingunmatched
  • Code Reviewsunmatched
  • Command Lineunmatched
  • Communications Security (COMSEC)unmatched
  • CompTIA Security+unmatched
  • Computer Securityunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Integrationunmatched
  • DNS (Domain Name System)unmatched
  • Debian Linuxunmatched
  • Debugging Skillsunmatched
  • Digital Certificatesunmatched
  • Documentationunmatched
  • Editingunmatched
  • File Systemsunmatched
  • GCP (Good Clinical Practices)unmatched
  • GitHubunmatched
  • HTTP (HyperText Transport Protocol)unmatched
  • Healthcareunmatched
  • Identify Issuesunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Applicationunmatched
  • JavaScriptunmatched
  • Leadershipunmatched
  • Linux Operating Systemunmatched
  • Machine Toolunmatched
  • MySQLunmatched
  • Nessusunmatched
  • Online Advertisingunmatched
  • PHP Scripting Language (PHP Hypertext Preprocessor)unmatched
  • Process Managementunmatched
  • Python Programming/Scripting Languageunmatched
  • Riskunmatched
  • SSL-TLS (Secure Socket Layer - Transport Layer Security)unmatched
  • Scripting (Scripting Languages)unmatched
  • Security Architectureunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Infrastructureunmatched
  • Software Administrationunmatched
  • Software Developmentunmatched
  • Software Patchesunmatched
  • Systems Administration/Managementunmatched
  • Ubuntuunmatched
  • User Interface/Experience (UI/UX)unmatched
  • Vehicle Fleetsunmatched
  • Vulnerability Scannersunmatched
  • Web Client Plug-insunmatched
  • Wordpressunmatched
  • Writing Skillsunmatched
  • nginx Web Serverunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder