Information Security Engineer

Posted Aug 14

This is a fully remote position, open to applicants in Spain, +1 more country.

📋 Description

• Oversee the company's SOC 2 compliance initiative, encompassing readiness, control implementation, evidence collection, continuous monitoring, remediation, and collaboration with auditors to ensure successful audit completion.

• Direct the vulnerability management program across SaaS products, cloud infrastructure, containers, and endpoints, including identification, triage, prioritization, remediation tracking, and reporting.

• Operate and optimize SAST, SCA, and dependency-scanning tools such as Snyk and GitHub Advanced Security/Dependabot.

• Monitor runtime and infrastructure telemetry, including Datadog for security signals; investigate alerts and lead containment and follow-up actions.

• Track and communicate vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership.

• Strengthen the security posture of the Microsoft Azure environment through configuration hardening, policy enforcement, and continuous monitoring.

• Manage and enhance Microsoft Intune for endpoint configuration, compliance, and mobile device management.

• Fine-tune and maintain Microsoft Defender for effective threat detection, response, and reporting.

• Draft, update, and sustain corporate information security policies, standards, and procedures in alignment with SOC 2, ISO 27001, and NIST CSF.

• Lead responses to customer and prospect security questionnaires, RFPs, and due-diligence requests; maintain a reusable response library.

• Support vendor risk assessments and third-party security reviews.

• Assist with internal and external audits, evidence collection, and remediation of findings.

• Collaborate with Engineering on secure SDLC practices, threat modeling, and code review guidance.

• Contribute to security awareness training, phishing simulations, and promoting a security-focused culture.

• Help refine incident response playbooks and participate in tabletop exercises and on-call rotations as necessary.


⛳️ Requirements

• 4 to 6 years of professional experience in information security, application security, cloud security, or a closely related field.

• Experience in preparing for SOC 2 Type 2 attestations for SaaS products.

• Hands-on experience securing SaaS applications and workloads deployed in Microsoft Azure.

• Proven experience with vulnerability management tools and processes, including triage, prioritization using CVSS/EPSS and exploitability context, and driving remediation with engineering teams.

• Proficient in several of the following: Microsoft Intune, Microsoft Defender Endpoint/Cloud, Microsoft Purview, Datadog, GitHub Advanced Security/Dependabot/code scanning, and Snyk.

• Strong understanding of identity and access management, particularly with Microsoft Entra ID (Azure AD), conditional access, and least-privilege principles.

• Experience in drafting or significantly contributing to security policies, standards, or procedures.

• Experience in responding to customer security questionnaires and supporting compliance initiatives.

• Excellent written and verbal communication skills, with the ability to convey technical risks to both engineers and non-technical stakeholders.

• Preferred certifications include CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent.

• Preferred experience with container and Kubernetes security, threat modeling, secure code review, penetration testing, SaaS companies, or regulated industries.


🏝️ Benefits

• Comprehensive benefits package including health, dental, and vision insurance.

• Opportunities for professional development and continued education.

• Flexible working hours and remote work options.

• Supportive and innovative work environment focused on employee well-being.

People also viewed

Cloudiax18 hours ago

Information Security, Compliance & IKS Manager – ISO 27001

DE flagGermany OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Cisco20 hours ago

Senior Manager, Security Channel – Market Growth, Splunk

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$169.3k – $237.2k/year
ApplyView job
Cisco1 day ago

Senior Manager, Security Channel – Market Growth, Splunk

US flagArizona, +10 more statesFull-timeCybersecurity / Security Engineer$169.3k – $237.2k/year
ApplyView job
Skylight1 day ago

Senior Product Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$200k – $250k/year
ApplyView job
Sony Interactive Entertainment1 day ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads1 day ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers