Information Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of HSP Group

HSP Group

51 - 200 employees

🤝 B2B

💼 Consulting

📋 Compliance

B2B • Consulting • Compliance

HSP Group helps companies manage their international operations and expand globally. We provide HQ-based finance, tax, legal and HR personnel with a simplified, turnkey approach to ensure efficient operations, full compliance with local regulations, and needed consistency across each geography.

📋 Description

• Lead the company’s SOC 2 compliance program, including readiness, control implementation, evidence collection, ongoing monitoring, remediation, and coordination with auditors through successful completion of the audit. • Lead the vulnerability management program across SaaS products, cloud infrastructure, containers, and endpoints, including identification, triage, prioritization, remediation tracking, and reporting. • Operate and tune SAST, SCA, and dependency-scanning tooling such as Snyk and GitHub Advanced Security/Dependabot. • Monitor runtime and infrastructure telemetry such as Datadog for security signals; investigate alerts and lead containment and follow-up actions. • Track and report vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership. • Enhance the security posture of the Microsoft Azure environment through configuration hardening, policy enforcement, and continuous monitoring. • Administer and improve Microsoft Intune for endpoint configuration, compliance, and mobile device management. • Tune and maintain Microsoft Defender for threat detection, response, and reporting. • Draft, update, and maintain corporate information security policies, standards, and procedures aligned with SOC 2, ISO 27001, and NIST CSF. • Lead responses to customer and prospect security questionnaires, RFPs, and due-diligence requests; maintain a reusable response library. • Support vendor risk assessments and third-party security reviews. • Assist with internal and external audits, evidence collection, and remediation of findings. • Partner with Engineering on secure SDLC practices, threat modeling, and code review guidance. • Contribute to security awareness training, phishing simulations, and security culture. • Help mature incident response playbooks and participate in tabletop exercises and on-call rotations as needed.

🎯 Requirements

• 4–6 years of professional experience in information security, application security, cloud security, or a closely related role. • Experience preparing for SOC 2 Type 2 attestations for SaaS products. • Hands-on experience securing SaaS applications and workloads running in Microsoft Azure. • Demonstrated experience with vulnerability management tooling and processes, including triage, prioritization using CVSS/EPSS and exploitability context, and driving remediation through engineering teams. • Working proficiency with several of Microsoft Intune, Microsoft Defender Endpoint/Cloud, Microsoft Purview, Datadog, GitHub Advanced Security/Dependabot/code scanning, and Snyk. • Solid understanding of identity and access management, particularly Microsoft Entra ID (Azure AD), conditional access, and least-privilege design. • Experience writing or substantially contributing to security policies, standards, or procedures. • Experience responding to customer security questionnaires and supporting compliance efforts. • Strong written and verbal communication skills, with the ability to translate technical risk for engineers and non-technical stakeholders. • Nice-to-have certifications include CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent. • Nice-to-have experience with container and Kubernetes security, threat modeling, secure code review, penetration testing, SaaS companies, or regulated industries.

Apply Now

Similar Jobs

🕒 Yesterday

TD SYNNEX

10,000+ employees

💼 Consulting

📦 Logistics

📣 Marketing

Cybersecurity IAM and Zero Trust Architect shaping TD SYNNEX’s global identity security strategy. Designing secure access, governance, and cloud identity capabilities across international operations.

AWS

Azure

Cloud

Cyber Security

🕒 July 29

EverAI

51 - 200

🤖 Artificial Intelligence

🎮 Gaming

Security Engineer managing application security for fast-growing AI companionship platform. Working across application security, risk & compliance, and security awareness.

🕒 July 27

SCI Serviclients

51 - 200

💼 Consulting

🔒 Cybersecurity

🎯 Recruiter

Senior Cybersecurity Consultant influencing architecture and risk management at SCI Serviclients. Leading vulnerability management and participating in key technical decisions.

🗣️🇪🇸 Spanish Required

Cloud

🕒 July 15

BlueLeaders

1 - 10

💼 Consulting

🎯 Recruiter

👥 HR Tech

Formador/a para elaboración de contenidos jurídicos y clases online en OpositaTest. Trabaja 100% remoto en un equipo apasionado por la formación y la tecnología.

🗣️🇪🇸 Spanish Required