
Security Engineer – Corporate Security
Posted Jul 31

Posted Jul 31
This is a fully remote position, open to applicants in New York.
• Design, implement, and oversee security controls and policies across corporate IT systems, emphasizing the confidentiality, integrity, and availability of employee, customer, and business data.
• Take ownership and enhance identity and access management (IAM/SSO/MFA), endpoint security (EDR, MDM), and email/network security (phishing defense, DLP, firewalls, VPN) throughout the organization.
• Conduct thorough security evaluations of corporate systems and vendors to identify vulnerabilities, assess risks, and propose actionable mitigation plans.
• Establish governance, guardrails, and monitoring for emerging employee tools, including the management of data handling, access, and third-party risks.
• Manage the vulnerability management lifecycle across the corporate fleet: scanning, risk-based prioritization, remediation and patch SLAs, and closure tracking for endpoints and internal systems.
• Spearhead security awareness and phishing simulation initiatives to cultivate a company-wide culture of security.
• Contribute to compliance and audit activities as required, providing security context to facilitate business agility.
• Evaluate and manage third-party/vendor security risks, including security questionnaires, contract assessments, and ongoing vendor monitoring.
• Assist in conducting and addressing findings from penetration tests, red team exercises, and internal audits, ensuring timely and effective remediation.
• Stay updated on the latest security threats, vulnerabilities, and compliance requirements impacting corporate environments; offer strategic guidance on technologies and best practices.
• Investigate security incidents and insider threat issues in collaboration with HR, Legal, and IT as necessary.
• Elevate the security standard across the organization by mentoring engineers and partners on secure practices, promoting a culture of security awareness and continuous improvement.
• Collaborate with stakeholders to effectively integrate security requirements into IT projects and broader business initiatives.
• Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent experience). Advanced degrees or certifications (e.g., CISSP, GIAC, Security+, CISM) are beneficial.
• At least 5 years of experience in information security, with significant exposure to corporate/IT security domains (identity, endpoint, network, GRC).
• In-depth knowledge of enterprise identity providers and SSO/MFA platforms, endpoint/EDR tools, MDM platforms, and email security tools.
• Familiarity with common compliance frameworks (e.g., SOC 2, ISO 27001).
• Awareness of government/public-sector security frameworks (FedRAMP, FISMA, NIST SP 800 series, CJIS) is a plus, considering Cape's government-facing customer base.
• Understanding of consumer privacy regulations (GDPR, CCPA, and other regional privacy laws) as they pertain to customer data handling.
• Exposure to secure software development lifecycle (SSDLC) practices and collaboration with engineering on secure design reviews.
• Proficient in scripting or automation (Python, shell scripting, or similar) to enhance security operations and reporting.
• Familiarity with vendor/third-party risk management processes and tools.
• Strong knowledge of network security, encryption technologies, and secure business-system configurations.
• Excellent analytical skills for identifying and mitigating complex security vulnerabilities and risks.
• Strong communication and leadership skills, capable of collaborating across teams and conveying technical information effectively to non-technical stakeholders.
• Highly organized with the ability to manage multiple priorities in a dynamic, fast-paced environment.
• 401(k) match
• 100% coverage of medical, dental, and vision premiums for you and your dependents
• 12 weeks paid parental leave (for all parents, no waiting period)
• Stipends for
• Family-forming needs
• Gender-affirming care
• Unlimited PTO
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.