
Information Security Engineer
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in United States, +1 more country.
• Oversee the company's SOC 2 compliance initiative, which encompasses preparedness, control execution, evidence gathering, continuous monitoring, remediation, and coordination with auditors.
• Manage vulnerability assessment across SaaS offerings, cloud infrastructure, containers, and endpoints.
• Utilize and optimize SAST, SCA, and dependency-scanning tools, collaborating with engineering teams on remediation efforts.
• Monitor runtime and infrastructure telemetry, investigate alerts, and lead containment strategies and follow-up actions.
• Track and present vulnerability SLAs, mean time to remediate, and security KPIs to executive leadership.
• Strengthen security within Microsoft Azure across identity management, networking, data protection, and workloads.
• Administer and enhance Microsoft Intune for endpoint configuration, compliance, and mobile device management.
• Fine-tune and manage Microsoft Defender for effective threat detection, response, and reporting.
• Draft, revise, and uphold information security policies, standards, and procedures.
• Lead efforts in responding to security questionnaires from customers and prospects, as well as RFPs and due-diligence inquiries.
• Assist in vendor risk assessments, third-party security reviews, audits, evidence collection, and remediation activities.
• Collaborate with Engineering on secure SDLC practices, threat modeling, and guidance for code reviews.
• Contribute to security awareness training and phishing simulation exercises.
• Develop incident response playbooks and participate in tabletop exercises and on-call rotations as required.
• 4–6 years of professional experience in information security, application security, cloud security, or a related field.
• Experience in preparing for SOC 2 Type 2 attestations for SaaS products.
• Practical experience in securing SaaS applications and workloads operating in Microsoft Azure.
• Familiarity with vulnerability management tools and processes, including triage, prioritization, and remediation through engineering teams.
• Proficient in several tools including Microsoft Intune, Microsoft Defender, Microsoft Purview, Datadog, GitHub Advanced Security/Dependabot/code scanning, and Snyk.
• Understanding of identity and access management, particularly with Microsoft Entra ID, conditional access, and least-privilege design principles.
• Experience in drafting or significantly contributing to security policies, standards, or procedures.
• Experience in responding to customer security inquiries and supporting compliance initiatives.
• Excellent written and verbal communication skills with the ability to convey technical risks to both technical and non-technical audiences.
• Preferred certifications include CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, and GSEC.
• Additional experience in container and Kubernetes security, threat modeling, secure code reviews, penetration testing, SaaS companies, or regulated industries is advantageous.
• Competitive salary and performance-based incentives.
• Comprehensive health, dental, and vision insurance.
• Retirement savings plan with company matching.
• Flexible working hours and remote work options.
• Opportunities for professional development and certifications.
• A collaborative and innovative work environment.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.