About this role
HMH is a learning technology company committed to delivering connected solutions that engage learners, empower educators and improve student outcomes. As a leading provider of K–12 core curriculum, supplemental and intervention solutions, and professional learning services, HMH partners with educators and school districts to uncover solutions that unlock students’ potential and extend teachers’ capabilities.
HMH serves more than 50 million students and 4 million educators in 150 countries. For more information, visit www.hmhco.com
Join our Information Security team as a Staff Security Engineer with approximately 5–8 years of hands-on experience in cloud security, application security, DevSecOps, vulnerability management, and security automation. This role will help protect our cloud and on-premises environments and support the organization’s GovRAMP security and compliance program.
Responsibilities include implementing and monitoring cloud security controls, managing vulnerabilities and security alerts, supporting GovRAMP/NIST 800-53 controls, SSP, POA&M, evidence collection, continuous monitoring, and assessments, and driving remediation activities. The role will partner with Engineering, DevOps, Architecture, Risk, and Compliance teams to integrate security into applications, CI/CD, cloud infrastructure, and data platforms.
The ideal candidate is a hands-on security professional experienced in cloud security, DevSecOps, automation, security monitoring, and compliance, with an ability to leverage modern cloud-native technologies and AI initiatives to strengthen security and enable business innovation.
Why Join Us:
At HMH, you will have the opportunity to strengthen cloud security and support GovRAMP initiatives while working with modern AWS and Azure technologies. You will collaborate with Engineering, DevOps, Architecture, Risk, and Compliance teams to protect critical applications and data, automate security processes, and drive meaningful improvements across the enterprise.
We foster a security-first, collaborative, and innovative environment that encourages continuous learning and professional growth. If you are passionate about cloud security, DevSecOps, automation, AI-driven security, and helping organizations securely scale in the cloud, we invite you to join us on our digital transformation journey.
Duties & Responsibilities include:
- Perform application security assessments using SAST, DAST, SCA, and manual testing.
- Identify, prioritize, track, and remediate application security vulnerabilities and findings.
- Conduct secure code reviews, threat modeling, and security design reviews for applications and new features.
- Perform web application and API security testing aligned with OWASP Top 10 and API Security practices.
- Integrate security controls and testing into CI/CD pipelines and the SDLC.
- Partner with engineering teams to implement secure coding practices and provide remediation guidance.
- Support vulnerability triage, risk assessment, remediation, exceptions, and penetration-test findings.
- Develop and maintain application security standards, guidelines, procedures, and documentation.
- Support GovRAMP/NIST 800-53 control implementation, evidence collection, continuous monitoring, remediation tracking, and assessment readiness.
- Provide security guidance and awareness to developers and engineering teams.
- Plan, implement, and track initiatives that strengthen application security across the SDLC and GovRAMP compliance requirements.
Required Skills:
- Hands-on experience with AWS and/or comparable cloud environments, including designing, implementing, and securing cloud and hybrid environments.
- Approximately 5 years of experience in Application Security, Product Security, or a related security engineering role.
- Strong understanding of OWASP Top 10, OWASP API Security, CWE, and common application vulnerabilities.
- Hands-on experience with SAST, DAST, SCA, vulnerability management, and application security testing tools.
- Experience testing web applications, REST APIs, and microservices, including authentication, authorization, session management, encryption, and secure API design.
- Experience with Burp Suite or similar security testing tools and secure code review practices.
- Knowledge of CI/CD and DevSecOps, including integrating security testing and controls into development pipelines.
- Working knowledge of cloud security and applicable security frameworks, such as NIST, ISO 27001, SOC 2, GDPR, HIPAA, or PCI DSS.
- Experience supporting GovRAMP/NIST 800-53 security controls, including control implementation, evidence collection, continuous monitoring, assessment support, and remediation tracking.
- Hands-on scripting/programming experience with Python, Java, JavaScript, PowerShell, or similar languages.
- Ability to analyze security findings, validate vulnerabilities, reduce false positives, prioritize risks, and communicate remediation recommendations effectively.
- Strong communication and collaboration skills with developers, architects, DevOps, security, risk, and compliance teams.
Preferred Qualifications:
- Hands-on experience securing AWS, Azure, or other enterprise cloud environments, including cloud-native services and hybrid architectures.
- Experience supporting GovRAMP/NIST 800-53 initiatives, including security assessments, control evidence, continuous monitoring, and remediation activities.
- Experience with threat modeling, security architecture reviews, and secure design practices for cloud applications and platforms.
- Knowledge of container and Kubernetes security, including image security, runtime controls, and workload protection.
- Experience with penetration testing, vulnerability assessments, or bug bounty programs.
- Experience automating security processes using Python, PowerShell, or similar scripting languages.
- Familiarity with DevSecOps and cloud security automation, including security controls integrated into CI/CD pipelines.
- Relevant security certifications such as Security+, CEH, OSCP, CSSLP, or equivalent is advantageous.
The Information Technology organization is transforming to realize our mission: Become a leader in HMH’s digital transformation, and as a strategic partner, innovate and deliver highest value, competitive advantage solutions across all corporate and business functions. Our ambition is to be a digital leader through innovation and develop and deliver leading edge technology such as robotic process automation and artificial intelligence to solve some of HMH’s greatest operational business challenges. Our professionals will have business relevant skills to connect our HMH partners to technologies that propel the businesses to deliver the greatest value for HMH and our customers.
We are building a team of IT professionals with an insatiable appetite to learn, a relentless focus on customer service, a technological curiosity toward future possibilities, and a creativity in solving business challenges with leading technologies. Our team will find ways to work together, create a sense of community where it’s safe to take risks and learn together, develop our careers, and all have an opportunity to work on new technologies. We will work together, learn together and have fun together. As a team, we will lead HMH’s digital transformation.