Skip to content

Security Engineer resume example

See how a complete Security Engineer resume organizes experience, projects, education, and skills.

OpenAIPosting location: Seattle · United StatesIndependent fictional example, not company material.

Fictional resume example. Names, employment histories and results are illustrative, not an actual employee record.

Claire Morgan

Security Engineer · Seattle · United States

Security Engineer with experience in risk reduction, detection, response, and secure systems. Practical work includes Threat modeling, Detection engineering, Incident response, Cloud security.

Experience

OpenAI

Seattle · United States

Security Engineer

Mar 2022 - now

  • Performed threat modeling for account recovery and session renewal, tracing trust boundaries and abuse paths. Turned the findings into application security controls and negative authorization tests before release.
  • Used Python to reproduce authorization vulnerabilities during scoped penetration testing in an approved test environment. Paired each finding with a failing request, a code fix, and a regression test that confirmed the bypass was closed.
  • Correlated an application finding with the affected endpoint and authorization path, reproduced the exploit in a test environment, and retested both the fix and adjacent access controls.
  • Owned an application-security review using threat modeling and authorized penetration testing, resolving an authorization bypass before the affected endpoint was released.
  • Built Python regression checks for the patched access path and verified encryption settings, enabling reviewers to reproduce both the blocked attack and legitimate request.

Cisco

San Jose · United States

Security Engineer

Jan 2019 - Feb 2022

  • Ran two incident simulations with engineering, legal, and support. Kept turnaround time within the agreed operating window.
  • Reviewed remediation evidence against the original finding, retested the affected access path, and kept residual exposure visible when the mitigation could not remove the entire risk.
  • Reconstructed an access incident from authentication logs and the affected account’s permissions, distinguished authorized service activity from unexpected access, and verified containment with the service owner before revoking temporary restrictions.

Selected project

Security Engineer — independent case study

Project owner

Feb 2024 - Jun 2024

  • Automated evidence collection for 12 access-control checks
  • Built a lab assessment using synthetic accounts and a published control framework; mapped each finding to the affected access path and kept evidence of both the vulnerable and remediated state.
  • Retested the proposed control with an authorized negative case and wrote a residual-risk note; distinguished a passed laboratory check from assurance about an organization’s entire environment.
  • Owned the authorized lab retest using synthetic accounts, resolved an access-control gap and completed a report showing both the blocked request and the permitted path.

Education

University of Washington

Seattle, Washington · United States

B.S. Computer Science

Sep 2013 - Jun 2017

Relevant coursework: Algorithms, operating systems, databases, computer networks

Skills

Role expertise

Threat modeling · Detection engineering · Incident response · Cloud security · Python · IAM

Certifications

CompTIA Security+

CompTIA

Jun 2024

Publications

  • Published an independent security note using redacted lab evidence, distinguishing a verified control from residual risk and explaining why a passed test is not whole-system assurance.

How this Security Engineer resume addresses the posting

See which posting requirements are supported by specific work.

OpenAI

Security Engineer, Application Security

Seattle · United StatesMid-level

View original job posting

This resume is a fictional example. Check the original posting for current details.

  • In the posting
      • threat modeling
      • application security
      Term in work evidence

    Threat Modeling and Risk Assessment: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.

    As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.

    In this resume
    Performed threat modeling for account recovery and session renewal, tracing trust boundaries and abuse paths. Turned the findings into application security controls and negative authorization tests before release.
    Security Engineer · OpenAI
  • In the posting
      • Python
      • vulnerabilities
      Term in work evidence

    Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.

    Perform Security Assessments: Conduct regular security assessments, code reviews, and penetration testing to identify vulnerabilities in applications and software.

    In this resume
    Used Python to reproduce authorization vulnerabilities during scoped penetration testing in an approved test environment. Paired each finding with a failing request, a code fix, and a regression test that confirmed the bypass was closed.
    Security Engineer · OpenAI
  • In the posting
      • penetration testing
      • security
      Term in work evidence

    As a Security Engineer, Application Security you will be responsible for identifying and mitigating security vulnerabilities within software applications through building security tools, code reviews, penetration testing, and security assessments.

    We’re looking for people who will work closely with development teams to ensure secure coding practices are integrated throughout the software development lifecycle, preventing security risks before they emerge.

    In this resume
    Owned an application-security review using threat modeling and authorized penetration testing, resolving an authorization bypass before the affected endpoint was released.
    Security Engineer · OpenAI
  • In the posting
      • Incident response
      • risk assessment
      Evidence not found

    Incident Response Support: Assist in investigating, analyzing, and responding to security incidents related to applications, ensuring timely resolution and documentation of incidents.

    Threat Modeling and Risk Assessment: Conduct threat modeling and risk assessments to proactively identify potential risks and develop mitigation strategies.

    In this resume

    No supporting experience found. Do not add this keyword unless your own work supports it.

View 1 more matched requirement
  • In the posting
      • encryption
      Term in work evidence

    Proficiency in programming languages (such as Python, Java, C++, etc.), knowledge of security tools (e.g., Burp Suite, OWASP ZAP), and familiarity with security protocols and encryption methods.

    In this resume
    Built Python regression checks for the patched access path and verified encryption settings, enabling reviewers to reproduce both the blocked attack and legitimate request.
    Security Engineer · OpenAI
References2 sourcesReviewed

Start with this example. Finish with your experience.

Open it in the editor and replace every role, project, and result with your real experience.