
Information Security Engineer – Platform
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in United States.
• Manage security vulnerabilities by executing scans, interpreting the results, prioritizing findings based on actual exploitability, and facilitating remediation in collaboration with the code owners.
• Oversee the security of WordPress and its dependencies, including maintaining the update schedule for core, plugins, themes, and third-party libraries; identify risky or outdated dependencies and advocate for their replacement.
• Implement and uphold hardening standards for Linux servers, web server configurations, and application settings.
• Assist in the execution of security measures such as access reviews, secrets management, security logging and alerting, and maintaining TLS/certificate hygiene.
• Conduct security-focused code reviews on PHP and JavaScript modifications, as well as help prioritize findings from automated scans in the CI/CD pipeline.
• Engage in incident response activities—including monitoring, triage, evidence collection, documentation, and lessons learned—while collaborating with senior engineers who lead these efforts.
• Contribute to SOC 2 compliance through evidence gathering, control documentation, and policy assistance.
• Monitor vulnerabilities and threats pertinent to our technology stack, converting them into prioritized, actionable tickets.
• Write and review PHP and JavaScript for the WordPress platform, emphasizing security fixes, hardening, and remediation tasks.
• Troubleshoot and resolve WordPress, PHP, and MySQL issues in conjunction with the development and support teams.
• Assist with releases, deployments, and client site launches utilizing internal automation scripts.
• Manage Ubuntu/Debian Linux servers, covering tasks such as patching, monitoring, nginx configuration, log analysis, and routine maintenance.
• Work with DNS records, domain configurations, and SSL/TLS certificates across client site environments.
• Develop small automation scripts to decrease manual security and operations overhead.
• 1–3 years of professional experience in software development, systems administration, or IT, with a clear focus on security.
• Relevant experience from internships, labs, personal projects, or CTF work is also considered.
• Practical experience with WordPress and PHP is essential—you should be able to read plugin and theme code, trace bugs, and implement fixes. This is a mandatory requirement.
• Strong understanding of security principles, including the OWASP Top 10, authentication and authorization concepts, encryption, TLS basics, and common web attack vectors.
• Proficient in using the Linux command line for file system navigation, process management, and log analysis.
• Scripting capabilities in Bash and/or Python are required.
• Familiarity with web application architecture, including HTTP, DNS, TLS, APIs, and the request flow to your code.
• Practical knowledge of MySQL, including writing queries and debugging data-related issues.
• Excellent written communication skills are necessary, as security work involves extensive documentation and clear writing is crucial.
• A genuine curiosity and a systematic approach to problem-solving are essential. We prefer candidates who investigate thoroughly to understand root causes over those who are already familiar with every tool.
• Candidates must reside in the U.S. and have authorization to work without sponsorship.
• Remote work opportunity—operate from anywhere within the U.S.
• Unlimited paid time off (PTO) with performance-based flexibility.
• 401(k) plan with employer matching contributions.
• Comprehensive healthcare benefits, including medical, dental, and vision coverage.
• Financial support for professional development.
Agility Technologies Inc
American College of Education
First Due
Faire
Get handpicked remote jobs straight to your inbox weekly.