IT Security Engineer Jobs in Colorado
IT Security Engineer jobs in Colorado are in strong demand, concentrated in aerospace and defense contractors, federal civilian agencies, financial services, and the state's growing technology sector, with openings at every level from analyst-track associates to senior architects and team leads. Denver, Colorado Springs, and Boulder account for the largest share of hiring, with established employers like Lockheed Martin, CSAA Insurance, and Raytheon Technologies maintaining deep and recurring security engineering headcount in the region. The most sought-after specialties are cloud security, penetration testing, and identity and access management. Find a role that fits below and apply directly.
Find IT Security Engineer JobsOverview
Showing 5 of 10+ IT Security Engineer jobs







TG IT Application Security Manager
Date: Sep 16, 2026
Location: Lakewood, US
Company: Terumo BCT, Inc.
Requisition ID: 35487
At Terumo Blood and Cell Technologies, our 8,000+ global associates proud to come to work each day, knowing that what we do impacts the lives of patients around the world. For Terumo, for Everyone, Everywhere.
We make medical devices and related products that are used to collect, separate, manufacture and process various components of blood and cells. With our innovative technologies and service offerings, we touch a patient’s life every second of every day and are committed to continuing to increase the number of patients we serve. Advancing healthcare with heart.
With some of the best and brightest minds in the industry, an unmatched global footprint, comprehensive benefits and a distinct culture, Terumo Blood and Cell Technologies is a great place to work, grow and be part of a team that is focused on making a difference. Join us and help shape wherever we go next. You create your future and ours.
Application Security Manager
JOB SUMMARY
Employment Type: Full-time
Department: Global Cybersecurity
Role Reports to: Security Operations Leader
Location: Americas
Work Arrangement: Hybrid
Scope: Regional
ESSENTIAL DUTIES (or key responsibilities)
Application Security Leadership
- Collaborate with other global and regional leaders within to develop the enterprise Application Security strategy.
- Lead, mentor, and develop Application Security Analysts.
- Define AppSec metrics, KPIs, and maturity goals in collaboration with regional and global security leaders.
Secure Software Lifecycle
- Integrate security into all phases of the enterprise application portfolio.
- Ensure security requirements are incorporated during design and architecture reviews.
- Promote security-by-design principles across application teams.
Security Testing
Manage and oversee:
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- Interactive Application Security Testing (IAST)
- API Security Testing
- Container Security
- Infrastructure as Code (IaC) Security
- Mobile Application Security Testing
- Secrets Detection
- Review findings, prioritize remediation, and validate fixes.
- Assist in Supply Chain Security
Threat Modeling
- Facilitate threat modeling sessions with development teams.
- Identify abuse cases and attack paths.
- Recommend architectural improvements.
- Ensure high-risk applications undergo formal security architecture reviews.
Vulnerability Management
- Establish application vulnerability management processes
- Prioritize remediation using risk-based methodologies
- Track remediation SLAs
- Report vulnerability metrics to executive leadership
- Coordinate penetration testing remediation activities
- Threat Intelligence
Cloud Application Security
Support secure development within cloud platforms including:
- AWS
- Microsoft Azure
- Google Cloud Platform
Secure Code Reviews
- Conduct manual secure code reviews
- Review high-risk applications
- Provide secure coding guidance
- Coach development teams on remediation
API Security
- Establish and set-up safe rules
- Find weak spots through testing
- Monitor logs to spot shadow APIs and strange traffic patterns
Security Awareness
Collaboration on training programs covering:
- OWASP Top 10
- Secure Coding
- API Security
- Cloud Security
- Common software vulnerabilities
- Secure design principles
Application Risk Management
- Perform application security risk assessments.
- Support enterprise application risk management initiatives.
Incident Response
Support cyber incident response by:
- Investigating application security incidents.
- Supporting forensic analysis.
- Identifying root causes.
- Leading post-incident reviews.
- Developing preventive controls.
Compliance
Support compliance initiatives including:
- NIST CSF 2.0
- NIST SP 800-218 (SSDF)
- NIST SP 800-53
- OWASP ASVS
- PCI DSS
- HIPAA
- SOX
- ISO/IEC 27001
- SOC 2
OTHER DUTIES AND RESPONSIBILITIES
MINIMUM QUALIFICATION REQUIREMENTS
Education
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or related field.
- Master's degree preferred.
- 8–10+ years of cybersecurity experience.
- 5+ years in Application Security.
- 3+ years leading security teams.
- Experience implementing enterprise DevSecOps programs.
- Experience working with Agile and CI/CD environments.
- Experience with cloud-native application security.
Certificates, Licenses, Registrations
- CISSP
- CSSLP
- GIAC Web Application Penetration Tester (GWAPT)
- GIAC Secure Software Programmer (GSSP)
- Certified Cloud Security Professional (CCSP)
- Certified Information Security Manager (CISM)
- Microsoft Certified: Cybersecurity Architect Expert
- Microsoft Certified: Azure Security Engineer Associate
Korn Ferry Competencies
- Strong people leadership
- Strategic planning
- Executive communication
- Stakeholder management
- Cross-functional collaboration
- Risk-based decision making
- Program management
- Coaching and mentoring
- Conflict resolution
- Continuous improvement mindset
Key Performance Indicators (KPIs)
- Critical vulnerability remediation SLA compliance
- Mean time to remediate (MTTR)
- Percentage of applications covered by SAST, DAST, and SCA
- Security defects identified pre-production
- Reduction in high-risk application vulnerabilities
- CI/CD pipeline security coverage
- Secure code review completion rate
- Threat model completion rate
- Developer secure coding training completion
- Penetration test remediation completion
- Application security maturity score
- Audit and compliance findings related to application security
PHYSICAL REQUIREMENTS (for US only)
Typical Office Environment requirements include: reading, speaking, hearing, close vision, traverse, bending, sitting, and occasional lifting up to 20 pounds.
Target Pay Range: $121,400.00 to $151,800.00 - Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data
Target Bonus on Base: 15.0
We anticipate this requisition will be open for a minimum of five days, from 09/16/2026. We encourage your prompt application.
At Terumo Blood and Cell Technologies, we provide competitive total reward offerings that consist of compensation, benefits, recognition, along with a wealth of other well-being, work-life and recognition programs which support in unlocking the potential for you and your family. Included in our expansive list of benefits offerings are multiple group medical, dental and vision plans, a robust wellness program, life insurance and disability coverages, also a variety of voluntary programs such as group accident, hospital indemnity, critical illness, pet insurance and much more. To help you save for retirement, we offer a 401(k) plan with a matching contribution and for work-life balance we have vacation and sick time programs for associates. For us, it’s about protecting the personal welfare of our associates and their families, helping to achieve personal goals and offering those extra touches for convenience, security and overall peace of mind.
We are proud to be an Equal Opportunity Affirmative Action Employer. All applicants will be afforded equal opportunity without discrimination because of race, color, religion, sex, gender identity or expression, sexual orientation, marital status, order of protection status, national origin or ancestry, citizenship status, age, physical or mental disability unrelated to ability, military status or an unfavorable discharge from military service.
Job Segment: Testing, Cloud, Developer, Military Intelligence, Manager, Technology, Government, Management
See All 10 IT Security Engineer Jobs in Colorado
Find roles in Colorado that match your experience and apply in just a few clicks.
Find IT Security Engineer JobsIT Security Engineer Jobs by City in Colorado
Where Colorado roles are concentrated, by current openings.
IT Security Engineer Job Market in Colorado
A snapshot from current Colorado openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Food & Beverage
What Colorado Employers Look For
The qualifications that appear most often in IT security engineer jobs across Colorado.
- Active security certification such as CISSP, CEH, or Security+ recognized by Colorado employers
- Three or more years of hands-on experience in network security, vulnerability management, or incident response
- Proficiency with SIEM platforms, endpoint detection tools, and firewall configuration and monitoring
- Experience in regulated environments including defense, government contracting, or financial services
- Ability to obtain or maintain a federal security clearance, often required for Colorado Springs and Denver roles
- Bachelor's degree in cybersecurity, computer science, information systems, or a related technical field
IT Security Engineer Jobs in Colorado: Frequently Asked Questions
How do you become a it security engineer in Colorado?
Colorado does not require a state-issued license to work as an it security engineer, so entry centers on education and vendor-neutral certifications. Most employers in Colorado expect a bachelor's degree in cybersecurity, computer science, or information systems paired with at least one certification such as CompTIA Security+, CISSP, or CEH. Defense and government contractors in Colorado Springs and the Denver metro frequently require candidates to be eligible for a federal security clearance, which becomes the practical credential that shapes hiring in those sectors.
How much do IT security engineers make in Colorado?
IT security engineers in Colorado earn a median of about $135,220 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $87,560 for the lowest 10% to over $208,650 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire it security engineers in Colorado?
Employers hiring it security engineers in Colorado right now include Albedo, Terumo, and AgentSync, based on current listings on Migrate Mate as of September 2026. Colorado's concentration of aerospace, defense, and federal agency work means security-cleared roles represent a consistent and large share of the state's total openings.
Which Colorado cities have the most it security engineer jobs?
Denver, Golden, and Aurora hold the most it security engineer openings in Colorado. Denver leads because of its dense technology and financial services sector, Colorado Springs follows as the home of multiple military installations and their contractor ecosystems, and Boulder draws openings from its high concentration of software and cybersecurity firms headquartered along the Front Range.
Are there remote it security engineer jobs in Colorado?
Yes, and more than most technical roles. About 67% of it security engineer openings tied to Colorado are remote or hybrid as of September 2026, reflecting how much of the work involves cloud platforms, SIEM dashboards, and code review rather than on-site hardware. Cloud security, threat intelligence analysis, and application security roles tend to be the most remote-accessible, while positions requiring cleared facility access or hands-on network infrastructure work remain on-site.
How can I get hired as a it security engineer in Colorado with little or no experience?
The most realistic entry path is a help desk or IT support role at a Colorado employer followed by a targeted move into a junior security analyst position. Large Colorado employers in the defense and financial services space, including federal contractors in the Colorado Springs corridor, regularly hire associate-level analysts who hold CompTIA Security+ and are willing to pursue a clearance. Community College of Denver and Front Range Community College offer cybersecurity certificate programs that Colorado employers recognize as practical preparation, and completing a home lab project or a public capture-the-flag competition portfolio strengthens applications considerably.
Where can I find and apply to it security engineer jobs in Colorado?
You can find and apply to it security engineer jobs in Colorado on Migrate Mate, which lists current Colorado openings updated regularly. Search the listings for roles that match your experience level and specialization, then apply directly to the ones that fit.
See All 10 IT Security Engineer Jobs in Colorado
Find roles in Colorado that match your experience and apply in just a few clicks.
Find IT Security Engineer Jobs