
Information Security Engineer
Posted Aug 19

Posted Aug 19
This is a fully remote position, open to applicants in United States.
• Implement, configure, and manage security controls to protect networks, infrastructure, cloud environments, applications, and integration services.
• Design, deploy, and sustain secure-default controls across network, infrastructure, hybrid cloud, application delivery, and integration services.
• Apply zero trust access frameworks based on identity, device state, and request context during the onboarding of new and acquired environments.
• Develop and maintain policies, infrastructure modules, and automation scripts utilizing PowerShell, Python, Terraform, or similar tools.
• Configure and manage telemetry for asset and configuration visibility, access monitoring, and exposure management.
• Ensure that newly integrated environments attain security visibility and facilitate detection and remediation efforts.
• Implement compensating controls and address security findings.
• Handle high volumes of findings using fleet-wide tools and transition legacy and acquired systems to standardized builds.
• Provide evidence for the validation and closure of findings.
• Supply Governance, Risk, and Compliance (GRC) with data regarding environment attributes, including asset criticality, data classification, exposure state, and dependency mapping.
• Automate risk scoring processes to ensure up-to-date and consistent risk information.
• Execute repeatable processes for onboarding, migration, and decommissioning acquired firms.
• Report directly to the VP of Security Engineering & Architecture.
• Collaborate effectively with senior engineers, infrastructure teams, and Governance, Risk & Compliance.
• Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.
• 4–8 years of hands-on experience in security engineering, systems/network engineering with a security focus, or a related technical field.
• Experience in implementing and operating security controls within hybrid cloud environments, including AWS and/or Azure.
• Proficient in identity and access management, including tools such as Okta, Entra ID, MFA, and privileged access management.
• Expertise in PowerShell, Python, Terraform, or other automation and scripting tools.
• Familiarity with CI/CD, infrastructure-as-code, or policy-as-code toolchains.
• Working knowledge of NIST Cybersecurity Framework (CSF), CIS Controls, and defense-in-depth strategies.
• Experience in vulnerability management and remediation, including CVSS, EPSS, and CISA KEV.
• Ability to prioritize findings and implement fixes or compensating controls effectively.
• Strong collaboration skills across engineering, infrastructure, and Governance, Risk & Compliance.
• Security certifications are preferred, such as Security+, SSCP, AWS Security Specialty, Microsoft SC-200/AZ-500, or progress towards CISSP.
• Experience in regulated industries and audit/examination is preferred; familiarity with the financial industry and Reg S-P is a plus.
• Experience in supporting high-volume acquisition integration is preferred.
• Exposure to securing AI or agentic systems is preferred.
• Demonstrated ability to deliver security capabilities through automation rather than manual processes is preferred.
• Eligibility for bonus/incentive programs.
• Additional compensation and/or benefits may be available.
• Opportunities for progressive career advancement.
• Support for professional growth.
• Opportunities to contribute to community initiatives.
• A diverse and supportive workplace culture.
• Emphasis on work-life balance.
• Flexible remote work arrangements.
Agile Defense
Stripe
Guild Mortgage
Cambiar Education
Get handpicked remote jobs straight to your inbox weekly.