
Information Security Engineer
Posted Aug 14

Posted Aug 14
This is a fully remote position, open to applicants in Spain, +1 more country.
• Oversee the company's SOC 2 compliance initiative, encompassing readiness, control implementation, evidence collection, continuous monitoring, remediation, and collaboration with auditors to ensure successful audit completion.
• Direct the vulnerability management program across SaaS products, cloud infrastructure, containers, and endpoints, including identification, triage, prioritization, remediation tracking, and reporting.
• Operate and optimize SAST, SCA, and dependency-scanning tools such as Snyk and GitHub Advanced Security/Dependabot.
• Monitor runtime and infrastructure telemetry, including Datadog for security signals; investigate alerts and lead containment and follow-up actions.
• Track and communicate vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership.
• Strengthen the security posture of the Microsoft Azure environment through configuration hardening, policy enforcement, and continuous monitoring.
• Manage and enhance Microsoft Intune for endpoint configuration, compliance, and mobile device management.
• Fine-tune and maintain Microsoft Defender for effective threat detection, response, and reporting.
• Draft, update, and sustain corporate information security policies, standards, and procedures in alignment with SOC 2, ISO 27001, and NIST CSF.
• Lead responses to customer and prospect security questionnaires, RFPs, and due-diligence requests; maintain a reusable response library.
• Support vendor risk assessments and third-party security reviews.
• Assist with internal and external audits, evidence collection, and remediation of findings.
• Collaborate with Engineering on secure SDLC practices, threat modeling, and code review guidance.
• Contribute to security awareness training, phishing simulations, and promoting a security-focused culture.
• Help refine incident response playbooks and participate in tabletop exercises and on-call rotations as necessary.
• 4 to 6 years of professional experience in information security, application security, cloud security, or a closely related field.
• Experience in preparing for SOC 2 Type 2 attestations for SaaS products.
• Hands-on experience securing SaaS applications and workloads deployed in Microsoft Azure.
• Proven experience with vulnerability management tools and processes, including triage, prioritization using CVSS/EPSS and exploitability context, and driving remediation with engineering teams.
• Proficient in several of the following: Microsoft Intune, Microsoft Defender Endpoint/Cloud, Microsoft Purview, Datadog, GitHub Advanced Security/Dependabot/code scanning, and Snyk.
• Strong understanding of identity and access management, particularly with Microsoft Entra ID (Azure AD), conditional access, and least-privilege principles.
• Experience in drafting or significantly contributing to security policies, standards, or procedures.
• Experience in responding to customer security questionnaires and supporting compliance initiatives.
• Excellent written and verbal communication skills, with the ability to convey technical risks to both engineers and non-technical stakeholders.
• Preferred certifications include CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent.
• Preferred experience with container and Kubernetes security, threat modeling, secure code review, penetration testing, SaaS companies, or regulated industries.
• Comprehensive benefits package including health, dental, and vision insurance.
• Opportunities for professional development and continued education.
• Flexible working hours and remote work options.
• Supportive and innovative work environment focused on employee well-being.
Cloudiax
Cisco
Cisco
Skylight
Get handpicked remote jobs straight to your inbox weekly.