
Infosec, Compliance Specialist
Posted Sep 3

Posted Sep 3
This is a fully remote position, open to applicants in Lebanon.
• Design and implement enterprise Single Sign-On (SSO) solutions utilizing Keycloak, SAML 2.0, and OpenID Connect (OIDC).
• Set up Microsoft Entra ID (Azure AD) and Google Cloud Identity as identity brokers.
• Create centralized Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), and Zero Trust security policies across all platform boundaries.
• Oversee GitHub Advanced Security (GHAS) initiatives, including the enforcement of Dependabot alerts, secret scanning, static code analysis (CodeQL/SAST), and branch protection rules.
• Implement portable secrets management and supervise service-to-service security mechanisms such as mutual TLS (mTLS) across Kubernetes clusters.
• Guide audit readiness activities, vulnerability scanning programs, and compliance enforcement initiatives for standards such as SOC 2 and ISO 27001.
• Collaborate with engineering, platform, and operations teams to ensure that security controls are integrated throughout the software development lifecycle.
• Facilitate the ongoing enhancement of the organizational security posture through governance, risk management, and compliance best practices.
• Bachelor’s degree in Computer Science, Software Engineering, or a related discipline.
• At least 5 years of experience in Information Security, Identity and Access Management (IAM), Compliance, DevSecOps, or a related area.
• Extensive experience with Keycloak administration, realm configuration, user federation, and Identity Provider (IdP) mapping.
• Solid understanding of Microsoft Entra ID enterprise applications and Google Identity Platform.
• Experience in enforcing security policies across multi-tenant Kubernetes clusters and cloud boundaries.
• Familiarity with GitHub Advanced Security and DevSecOps automated tools.
• Strong grasp of SAML 2.0, OpenID Connect (OIDC), identity federation, and authentication protocols.
• Experience in implementing RBAC, MFA, Zero Trust architectures, and cloud security best practices.
• Knowledge of vulnerability management, audit readiness processes, and compliance frameworks such as SOC 2 and ISO 27001.
• Outstanding analytical, problem-solving, and risk assessment abilities.
• Excellent communication skills in English.
• Ability to work collaboratively with cross-functional and globally distributed teams.
• Availability to work from 11:00 AM to 8:00 PM.
• Remote work arrangement.
Freudenberg Group
Secfix
Mercor
Lifelancer
Get handpicked remote jobs straight to your inbox weekly.