Job Closed

This listing is no longer active.

HSI logo
HSI

Making the Workplace Safer and Smarter

Product Development Security and Compliance Specialist

Security EngineerSecurity EngineerOtherRemoteMid LevelTeam 501-1,000H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

132 days ago

Salary

0

Seniority

Mid Level

Bachelor Degree2 yrs expEnglishAWSAzureGCPJenkinsPythonSDLC

Job Description

Product Development Security and Compliance Specialist

HSI

• Support HSI’s product and DevOps teams in building and operating secure, compliant SaaS products. • Coordinate and execute evidence collection for external audits (e.g., SOC 2, ISO 27001) and internal assessments. • Perform recurring control activities (e.g., access reviews, change reviews, configuration checks) according to documented procedures. • Assist with vendor and customer security questionnaires, RFP security sections, and due-diligence requests by gathering technical details and documentation. • Assist with risk assessments by documenting control gaps, tracking remediation tasks, and ensuring risks are recorded. • Assist with administration of security controls and tooling in SDLC process. • Triage and track security findings from automated tools, working with engineers to prioritize and validate remediation. • Help document configuration standards and runbooks for secure cloud services and application infrastructure. • Support vulnerability management and monitoring of existing security tooling. • Help maintain incident response documentation and capture incident timelines and evidence. • Participate in design discussions and contribute to security awareness materials for product development teams.

Job Requirements

  • Bachelor’s degree in computer science, Cybersecurity, Information Systems, or a related field; or equivalent combination of education and hands-on experience.
  • 2–4 years of experience in one or more of the following:
  • IT/security compliance or audit support
  • Security, DevSecOps, or application security roles
  • DevOps/Cloud engineering roles with significant security/compliance responsibilities
  • Experience working with or supporting at least one security or compliance framework (e.g., SOC 2, ISO 27001, NIST).
  • Experience creating or updating security/compliance documentation (e.g., policies, standards, procedures).
  • Experience supporting, or strong interest in supporting, audits or assessments (evidence gathering, walkthroughs, responding to questions)
  • Familiarity with concepts such as least privilege, change management, configuration management, and incident response.
  • Familiarity with CI/CD tools (e.g., Azure DevOps, GitHub Actions, GitLab CI, Jenkins) and how security checks can be integrated into pipelines.
  • Exposure to at least one major cloud platform (AWS, Azure, or GCP), including use of native security features and basic understanding of secure configuration concepts.
  • Hands-on experience with one or more of the following is strongly preferred:
  • Source code or dependency scanning (SAST/SCA)
  • Container security tools
  • Cloud security posture management or configuration scanning tools
  • Experience using ticketing and documentation systems (e.g., Jira, Confluence, SharePoint, or similar) to track work and maintain artifacts.
  • Experience with security/compliance automation platforms (e.g., Drata, Vanta, Secureframe) or GRC tools
  • Relevant industry certifications (e.g., Security+, CCSK, AWS/Azure foundational security certs) or coursework in information security or audit.
  • Basic scripting or automation skills (e.g., PowerShell, Bash, Python) for data extraction, evidence collection, or simple task automation.
  • Experience in a production SaaS or cloud-native product environment.

Related Categories

Related Job Pages

More Security Engineer Jobs

OtherRemoteTeam 1-10H1B No Sponsor

• Support a large, enterprise‑scale environment by driving security governance, policy development, and compliance execution across multiple services and cloud environments. • Partner closely with service owners, engineering teams, and security stakeholders to develop strong access controls, assess and remediate risk, implement monitoring, and automate routine security tasks. • Ensure compliance gaps are closed, privileged access is minimized, and security best practices are consistently applied across infrastructure and cloud platforms.

Washington
$115K - $125K / year
Job Closed

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Knight Division Tactical is seeking a disciplined and technically capable Hacker to support offensive and defensive cybersecurity operations. This role focuses on penetration testing, vulnerability assessment, network exploitation, and security research to protect KDT's systems and support mission-critical cyber operations. The Hacker works closely with operations, intelligence, and technical teams to identify vulnerabilities, simulate adversary tactics, and strengthen KDT's overall security posture. Key Responsibilities - Conduct penetration testing and red team assessments - Identify and exploit vulnerabilities in networks, systems, and applications - Perform security research and threat analysis - Develop and maintain offensive security tools and techniques - Document findings and provide remediation recommendations - Support incident response and threat hunting operations Qualifications - Strong understanding of network protocols, operating systems, and security concepts - Experience with penetration testing tools (Burp Suite, Metasploit, Nmap, etc.) - Knowledge of web application security (OWASP Top 10) - Ability to work under pressure in high-stakes environments - Strong written and verbal communication skills

United States + 171 moreAll locations: United States | Canada | Brazil | Colombia | Argentina | Chile | Venezuela | Bolivia | Ecuador | French Guiana | Guyana | Paraguay | Peru | Suriname | Uruguay | Mexico | Costa Rica | El Salvador | Guatemala | Honduras | Nicaragua | Panama | Dominican Republic | Puerto Rico | Bahamas | Guadeloupe | Haiti | Jamaica | Martinique | Montserrat | United Kingdom | Germany | France | Estonia | Portugal | Hungary | Poland | Ukraine | Romania | Bulgaria | Czechia | Slovakia | Belarus | Moldova | Sweden | Greece | Belgium | Italy | Ireland | Switzerland | Netherlands | Finland | Malta | Denmark | Lithuania | Croatia | Spain | Austria | Bosnia And Herzegovina | Iceland | Luxembourg | North Macedonia | Montenegro | Norway | Serbia | Slovenia | Albania | Cyprus | Latvia | Monaco | South Africa | Egypt | Algeria | Angola | Benin | Botswana | Burkina Faso | Burundi | Cameroon | Cabo Verde | Central African Republic | Chad | Congo | Côte D'ivoire | Democratic Republic of the Congo | Equatorial Guinea | Eritrea | Ethiopia | Gabon | Gambia | Ghana | Guinea | Guinea-bissau | Kenya | Lesotho | Liberia | Libya | Madagascar | Malawi | Mali | Mauritania | Mauritius | Mayotte | Morocco | Mozambique | Namibia | Niger | Nigeria | Réunion | Rwanda | Senegal | Seychelles | Sierra Leone | Somalia | Sudan | Eswatini | Tanzania | Togo | Tunisia | Uganda | Zambia | Zimbabwe | Georgia | Turkey | Israel | United Arab Emirates | Armenia | Azerbaijan | Bahrain | Iraq | Jordan | Kuwait | Lebanon | Oman | Qatar | Saudi Arabia | Palestine | Yemen | India | Japan | Philippines | Pakistan | Thailand | Singapore | Vietnam | Taiwan | Indonesia | Cambodia | Laos | Malaysia | Myanmar | South Korea | China | Afghanistan | Bangladesh | Bhutan | Kazakhstan | Kyrgyzstan | Maldives | Mongolia | Nepal | Sri Lanka | Tajikistan | Turkmenistan | Uzbekistan | Australia | Papua New Guinea | Kiribati | Palau | French Polynesia | Tuvalu | New Zealand
Job Closed
Coalfire logo

Consultant, Application Security

Coalfire

Cyber solutions that move you forward, faster.

Security Engineer132 days ago
OtherRemoteTeam 1,001-5,000Since 2001H1B Sponsor

• Working independently and collaboratively with a team to both lead and support • Perform penetration testing on applications with complex technology stacks from both a: Unauthenticated perspective and Authenticated perspective • Dynamically flex your skills when assessing emerging or custom technologies. • Lead complex engagements to provide a technical consistency approach across multiple tests. • Contextualize vulnerabilities and assess realistic impact to a client accounting for mitigating and aggravating factors. • Manage priorities and tasks to achieve utilization targets. • Operate with professionalism both internally and with clients. • Ensure quality reports and services are delivered efficiently and on time. • Support sales and business growth by scoping out potential opportunities. • Maintains strong depth of knowledge in the practice area. • Collaborate with project managers, quality management, sales and other delivery team members to drive customer satisfaction and meet project deliverables.

United States
$105K - $138K / year
Job Closed
Business Wire logo

Senior Manager, Cybersecurity Architecture

Business Wire

Global Leader in News Content Distribution

Security Engineer132 days ago
OtherRemoteTeam 501-1,000Since 1961H1B No Sponsor

• Develop and maintain BW’s enterprise cybersecurity strategy and long-term roadmap. • Lead architecture decisions across cloud, application, identity, data, vulnerability management, and email security domains. • Oversee the implementation and ongoing maintenance of approved security architectures, controls, and technologies. • Ensure security controls are properly deployed, configured, validated, and continuously monitored for effectiveness. • Promote the adoption of Zero Trust principles and secure-by-design engineering practices. • Offer security guidance for AI projects, automation systems, and other emerging technologies. • Work with IT and business teams to ensure the secure design and roll-out of new projects. • Act as BW’s main leader and primary contact for our external cyber defense partner. • Evaluate the delivery of security monitoring, threat detection, response recommendations, and threat insights. • Collaborate to enhance detection coverage, response workflows, communication methods, and tuning. • Evaluate service delivery performance and ensure alignment with BW’s cybersecurity priorities. • Provide strategic leadership during cybersecurity incidents, coordinating with IT, Legal, HR, Privacy, Communications, and other stakeholders. • Serve as the executive-facing cybersecurity representative during significant security events, and coordinate the execution of operational response activities. • Communicate incident severity, business impact, risks, and recommended remediation actions to executive leadership. • Lead post-incident reviews and ensure lessons learned are incorporated into long-term improvements. • Represent cybersecurity during internal audits, external audits, and cybersecurity assessments conducted by key enterprise stakeholders. • Maintain alignment with frameworks such as NIST CSF, ISO 27001, SOC2, and relevant privacy regulations. • Offer senior-level guidance in developing and improving cybersecurity governance programs, policies, standards, and secure architecture guidelines. • Lead enterprise cybersecurity risk assessments and ensure corrective actions are prioritized and implemented effectively. • Provide oversight and direction for cybersecurity elements of privacy and data protection initiatives. • Lead cloud security architecture across AWS and other platforms used by BW. • Guide secure software development practices and coordinate application security reviews. • Oversee identity and access management strategies, including modern authentication and privileged access controls. • Drive Zero Trust adoption across networks, identity, and application environments. • Establish governance and security frameworks for responsible AI usage and advanced automation technologies. • Lead team members focused on cybersecurity architecture, governance, privacy, and strategic initiatives. • Mentor and develop staff capabilities, fostering a culture of continuous learning and innovation. • Strengthen collaboration across IT, Legal, Privacy, Risk, and other business areas to advance cybersecurity maturity. • Act as a trusted advisor to senior leadership on cybersecurity risk, architecture decisions, and strategic initiatives.

United States
$220K - $230K / year
Job Closed