
Senior Information Security Engineer
Posted Jul 14

Posted Jul 14
This is a fully remote position, open to applicants in Romania.
• Take ownership of the complete vulnerability management program for our SaaS products, cloud infrastructure, containers, and endpoints, encompassing identification, triage, prioritization, remediation tracking, and reporting.
• Operate and optimize SAST, SCA, and dependency-scanning tools (such as Snyk and GitHub Advanced Security/Dependabot) while collaborating with engineering teams to ensure prompt remediation.
• Monitor runtime and infrastructure telemetry (e.g., Datadog) for security signals; investigate alerts and lead containment and follow-up actions.
• Monitor and report on vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership.
• Strengthen the security posture of our Microsoft Azure environment, including identity, networking, data, and workloads, through configuration hardening, policy enforcement, and ongoing monitoring.
• Manage and enhance Microsoft Intune for endpoint configuration, compliance, and mobile device management.
• Fine-tune and maintain Microsoft Defender (Endpoint, Cloud, and related products) for effective threat detection, response, and reporting.
• Implement and manage Microsoft Purview controls for data classification, DLP, and information protection.
• Draft, revise, and maintain corporate information security policies, standards, and procedures in alignment with recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF).
• Lead the response to security questionnaires from customers and prospects, RFPs, and due diligence requests, while maintaining a reusable response library.
• Assist with vendor risk assessments and third-party security reviews.
• Support internal and external audits, including evidence collection and remediation of findings.
• Collaborate with Engineering on secure SDLC practices, threat modeling, and code review guidance.
• Contribute to security awareness training, phishing simulations, and fostering a robust security culture throughout the organization.
• Help advance incident response playbooks and participate in tabletop exercises and on-call rotations as required.
• 4–6 years of professional experience in information security, application security, cloud security, or a closely related field.
• Practical experience in securing SaaS applications and workloads operating in Microsoft Azure.
• Proven experience with vulnerability management tools and processes, including triage, prioritization (e.g., CVSS, EPSS, exploitability context), and driving remediation efforts with engineering teams.
• Working knowledge of several of the following tools: Microsoft Intune, Microsoft Defender (Endpoint/Cloud), Microsoft Purview, Datadog, GitHub (Advanced Security, Dependabot, code scanning), and Snyk.
• Strong understanding of identity and access management concepts, especially Microsoft Entra ID (Azure AD), conditional access, and least-privilege design.
• Experience in writing or significantly contributing to security policies, standards, or procedures.
• Experience in responding to customer security questionnaires and supporting compliance initiatives (SOC 2, ISO 27001, or similar).
• Excellent written and verbal communication skills, with the ability to convey technical risks to both technical and non-technical stakeholders.
• Flexible work environment.
• Emphasis on wellbeing through fitness offerings and mental health plans (country-dependent).
• Generous time off.
• Opportunities for career growth and development.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.