Job Closed

This listing is no longer active.

ezCater logo
ezCater

ezCater is the world’s largest online marketplace for business catering.

Security Engineer

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 501-1,000Since 2007H1B No SponsorCompany SiteLinkedIn

Location

Massachusetts

Posted

171 days ago

Salary

$113K - $137K / year

Seniority

Senior

Bachelor DegreeEnglishPythonRuby

Job Description

Security Engineer

ezCater

• Collaborate with Technology and Product teams to conduct security assessments, ensuring code and infrastructure changes align with SOC 2, PCI-DSS, and internal policies. • Automate compliance and control activities such as risk assessments, vulnerability scanning, third party risk management, and control validation. • Create monitoring and detective alerts for security operations, non-compliance, and incident response. • Responsible for maintaining a healthy posture of our security tools and automations. • Provide support for third-party assessments from customers and audit evidence collection and review. • Expand beyond purely identifying gaps and risks, and own the design and implementation of monitoring and remediating them. • Span across multiple security domains, you’ll be able to flex into technical and non-technical roles to drive risk detective and mitigative projects.

Job Requirements

  • Experience with development and scripting languages (Ruby, Go, Python) and leveraging API’s to automate workflows.
  • Articulate about risk management and compliance controls relating to industry best practices and frameworks.
  • Experience performing and remediating risk and control gap assessments.
  • Knowledge of Governance, Risk & Compliance (GRC) frameworks, Security Operations Center (SOC) processes, IT Security protocols, and privacy practices.
  • Someone who is willing to challenge the existing norms and “Aim Higher, Make it Better” than the way it currently is.
  • A continuous learning mindset to stay current with the latest security trends, threats, and technologies.

Benefits

  • Market competitive salary
  • Stock options
  • 12 paid holidays
  • Flexible PTO
  • 401K with ezCater match
  • Health/dental/FSA
  • Long-term disability insurance
  • Mental health and family planning resources
  • Remote-hybrid work from our awesome Boston office OR your home OR a mixture of both home and office
  • A tremendous amount of responsibility and autonomy
  • Wicked awesome co-workers
  • Relish (and many more goodies) when you’re in our office

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 5,001-10,000H1B Sponsor

• Owning, shaping, and running proof-of-concepts, beta programs, and pre-sales activities with customers and partner teams on the French market • Diving into enterprise architecture discovery and hands-on software configuration • Strategizing with and assisting customers as they move to more agile, secure, identity centric security models • Taking a consultative approach to solutions and solving challenges around next generation security transformation • Educating and enabling internal teams and partners regarding our Enterprise solution portfolios to motivate effective sales strategies • Influencing product roadmaps and ensuring the inclusion of business priorities and requirements of customers

United Kingdom
Job Closed
OtherRemoteTeam 201-500H1B No Sponsor

• Deliver engaging, interactive live training sessions • Build and lead hands-on labs and exercises • Provide clear explanations of complex security concepts • Support students’ learning with feedback and Q&A • Align lessons to certification goals and industry expectations • Participate in pre-class planning and post-session debrief • Collaborate with curriculum developers on updates

United States
eSimplicity logo

Information Security Officer

eSimplicity

An engineering firm that delivers high-quality Healthcare IT, Cybersecurity, and Telecommunication solutions.

Security Engineer172 days ago
OtherRemoteTeam 51-200Since 2016H1B No Sponsor

• Work closely with the Product Owners, ISSOs, engineering and infrastructure staff to provide guidance on implementation if security policies, standards, and procedures • Analyze new or updated security requirements, collaborate with stakeholders, and develop responses that are clear and accurate • Support the review and update of ATO artifacts such as System Security Plans, Information System Contingency Plans, Configuration and Change Management Plans, Incident Response Plans, Privacy Impact Analysis, and more. • Interpret security risk assessment, review security scan results, assess security vulnerabilities and support the development and remediation of vulnerability and compliance issues via Plan of Action and Milestones (POA&Ms) • Support the development of implementation and design documentation relating to security feature implementation • Work with engineering and infrastructure personnel to document remediation for vulnerabilities and non-compliance issues • Analyze and interpret agency security requirements and provide governance communication to non-security personnel • Collaborate with product teams, ISSOs and other stakeholders in support of continuous monitoring and ATO efforts • Conducts vulnerability assessments and monitors systems, networks, databases and Web-based assets for potential system breaches. • Recommends and takes the lead on implementing changes to enhance security systems, prevent unauthorized access, and help mitigate security vulnerabilities. • Responds to alerts from information security tools. • Reports, investigates, and resolves higher level security incidents. • Responds to security tool outages, degradations in service, tune security rules and alerts, and setup/maintain security tool dashboards and reporting. • Research security trends, new methods, and techniques used in unauthorized access of data to preemptively eliminate the possibility of system breach. • Ensures compliance with regulations and privacy laws. • Conducts research to identify new attack vectors. • Educates and communicates security requirements and procedures to all users and new employees. • Recommend process improvements to the information system for risk mitigation. • Applies iterative security automation to all program aspects increasing overall security posture iteratively and never accepts the status quo. • Provide audit log review in Splunk, present any findings to ISSO, and plan for any investigation or remediation activities. • Periodic user and privileged access reviews.

United States
$112.8K - $140K / year
Job Closed
Model N logo

Information Security Engineer – IAM Lead

Model N

Model N enables our life sciences and high-tech customers deliver life-changing products to the world.

Security Engineer172 days ago
OtherRemoteTeam 501-1,000Since 2000H1B Sponsor

• Define the IAM roadmap and ensure alignment with security, compliance, and business needs. • Design and maintain enterprise IAM architectures for workforce, partners, and customers. • Lead initiatives related to authentication, authorization, identity governance, and privileged access. • Contribute to enterprise security architecture standards beyond IAM, with identity as a foundational control. • Set standards for identity lifecycle management, directory services, federation, and access controls. • Drive implementation of modern IAM capabilities such as SSO, MFA, password less authentication, SCIM, role-based access, and just-in-time access. • Oversee integration of cloud and on-prem applications using SAML, OIDC, and OAuth. • Evaluate tools, guide vendor selection, and manage technical relationships. • Develop reusable patterns, reference architectures, and security guidance for development teams. • Partner with engineering to embed IAM and security controls into CI/CD pipelines and cloud platforms. • Design and govern enterprise identity architecture across AWS, Okta, Entra ID, Active Directory, and hybrid environments. • Enforce least-privilege access using federation, roles, conditional access, and zero trust principles. • Architect secure access for cloud workloads, eliminating long-lived credentials and unmanaged identities. • Secure non-human identities, service accounts, APIs, and automation using scoped roles, ownership models, and rotation policies. • Design and operate centralized secrets and key management solutions using KMS, Vault, and PAM platforms. • Centralize identity logging, monitoring, and response for authentication and authorization events. • Support security operations by improving access-focused detection, alerting, and incident response workflows. • Establish access policies, role models, and attestation processes. • Ensure IAM and access controls meet regulatory, audit, and internal security expectations. • Provide oversight for provisioning, deprovisioning, and access escalation processes. • Guide monitoring and tuning of identity and security services to meet availability and performance targets. • Mentor IAM and security engineers and influence cross-functional teams. • Work closely with security, infrastructure, application owners, risk, and compliance partners. • Communicate technical and security concepts clearly to both technical and non-technical audiences. • Support incident response activities when identity or access systems are involved.

United States
Job Closed