
Security & Infrastructure Engineer
Posted 3 days ago

Posted 3 days ago
This is a fully remote position, open to applicants in United States.
• Oversee Microsoft 365 identity and access management, which includes user lifecycle, conditional access policies, multi-factor authentication (MFA), and role-based permissions.
• Create and automate the processes for provisioning and deprovisioning user accounts and service accounts across cloud and SaaS platforms.
• Collaborate with development teams to enhance coverage of application-layer vulnerabilities, ensuring findings are identified and tracked.
• Manage external security and penetration testing initiatives from start to finish, encompassing scoping, vendor coordination, remediation tracking, and validation of fixes through retesting.
• Develop, document, and implement necessary security processes, policies, and controls to achieve and sustain SOC 2 compliance and other relevant control frameworks.
• Continuously evaluate and strengthen AWS security posture, focusing on IAM, network security, and configuration hardening.
• Construct ongoing security reports and dashboards to monitor risk and compliance status.
• Collaborate with DevOps on infrastructure security and secure provisioning for cloud resources and CI/CD pipelines.
• Monitor vulnerabilities and emerging threats within the environment.
• Maintain comprehensive documentation of security policies, procedures, and audit evidence.
• Work closely with engineering, DevOps, and leadership teams.
• 3-5 years of experience in information security, IT security, or a related field.
• Hands-on experience managing Microsoft 365 identity and access management, including Entra ID (Azure AD), conditional access, and MFA.
• Proficient in configuring and managing SSO/SAML/OIDC integrations with third-party SaaS applications.
• Familiarity with security frameworks and controls such as NIST, CIS Controls, and SOC 2.
• Experience in developing or documenting repeatable security processes and procedures.
• Highly motivated self-starter with a strong focus on teamwork.
• Excellent verbal and written communication skills.
• Adaptability and comfort in a dynamic, constantly evolving startup environment.
• Dedication to fostering a positive, collaborative workplace culture.
• Must reside in the United States; sponsorship is currently not available.
• Preferred: Experience securing AWS environments, including IAM, GuardDuty, Security Hub, CloudTrail, and VPC security.
• Preferred: Knowledge of DevOps practices and infrastructure-as-code.
• Preferred: Understanding of networking fundamentals, including DNS, VPNs, firewalls, and basic routing.
• Preferred: Experience with SIEM or observability platforms, such as Datadog or Splunk.
• Preferred: Security certifications such as CISSP, CISM, AWS Security Specialty, or CompTIA Security+.
• Occasional domestic travel with flexibility and advance notice when scheduling travel.
• Professional remote or in-office working environment.
• Reasonable accommodations for qualified applicants or employees with disabilities.
Tailscale
Tailscale
Just Eat Takeaway.com
Yunex Traffic
Get handpicked remote jobs straight to your inbox weekly.