Job Closed

This listing is no longer active.

mpathic logo
mpathic

Conversation Intelligence to Enhance Outcomes

IT Security & Compliance Lead

Security EngineerSecurity EngineerOtherRemoteSeniorTeam 11-50Since 2021H1B No SponsorCompany SiteLinkedIn

Location

Colorado

Posted

173 days ago

Salary

$120K - $160K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishAWSAzureGCP

Job Description

IT Security & Compliance Lead

mpathic

• Own internal IT systems including identity management, device management, endpoint security, and SaaS tooling. • Lead SOC 2 and other compliance programs, including audit readiness, evidence collection, auditor coordination, and remediation. • Design, implement, and maintain security controls such as access controls, encryption, logging, and vulnerability management. • Develop and maintain security policies, procedures, and documentation aligned with frameworks such as SOC 2, NIST, and ISO 27001. • Manage identity lifecycle processes, including onboarding, offboarding, and access reviews using least-privilege principles. • Evaluate, select, and implement IT and security tools (MDM, EDR, SSO/IdP, DLP, logging). • Oversee vendor security reviews and third-party risk management. • Partner with engineering and operations to ensure secure configurations across cloud infrastructure and SaaS applications. • Participate in incident response activities and drive continuous improvement from security events. • Automate IT and security workflows where possible to improve efficiency and reliability.

Job Requirements

  • 5+ years of experience across IT, security engineering, or compliance-focused roles
  • Hands-on experience leading SOC 2 audits (Type I or II) or comparable compliance efforts
  • Strong understanding of identity and access management, endpoint security, and SaaS security configuration
  • Experience working in cloud-first environments (AWS, GCP, or Azure)
  • Comfortable owning ambiguous, cross-functional problems and prioritizing pragmatically
  • Strong communication skills and the ability to work effectively with both technical and non-technical stakeholders
  • Experience with scripting or automation for IT/security workflows is a plus.

Benefits

  • 100% employer-funded healthcare
  • Flexible managed PTO
  • Training and education funding
  • Regular in-person retreats

Related Categories

Related Job Pages

More Security Engineer Jobs

OtherRemoteTeam 1,001-5,000Since 1973H1B No Sponsor

• Lead the review and analysis of vulnerability data to identify trends, patterns, and key risks across Deckers’ global environment • Facilitate vulnerability management meetings and drive risk-based discussions to prioritize and accelerate remediation efforts • Advise and support remediation teams in developing actionable plans to address vulnerabilities and strengthen our security posture • Perform risk-based assessments for both on-premise and cloud-based services, ensuring robust protection for critical assets • Integrate advanced security technologies and automation tools to enhance threat detection and response capabilities • Build and present business cases for adopting new security solutions to mitigate emerging risks • Develop, consolidate, and maintain security metrics to measure the effectiveness of our cybersecurity program • Apply industry-leading frameworks (NIST, ISO27001/2, CIS Top 20 Controls) to establish and maintain best-in-class security measures • Foster strong relationships with technical teams, serving as a trusted advisor and championing a culture of security awareness • Contribute to the strategic direction of the Technical Security team by designing and implementing tools that enhance customer trust and detect suspicious activity

Arizona + 4 moreAll locations: Arizona | California | Texas | Utah | Washington
$120K - $130K / year
Job Closed
Cobalt AI logo

Senior Security Engineer

Cobalt AI

DETECT MORE. RESPOND FASTER. SAVE MONEY.

Security Engineer174 days ago
Full TimeRemoteTeam 51-200Since 2016H1B No Sponsor

• Run Cobalt's endpoint and cloud asset security stack across managed laptops, desktops, and cloud infrastructure — including EDR, vulnerability management, and continuous compliance monitoring tooling • Administer Cobalt's compliance automation platform as the system of record for controls and evidence — manage personnel records, reconcile against HRIS and identity provider data, and handle edge cases outside the primary HRIS • Own end-to-end onboarding and offboarding security across employees, contractors, and external partners — verify new hires complete security gating before access is provisioned, apply the right requirements for each personnel tier, and close out access promptly when people leave • Triage alerts from EDR, SIEM, and the vulnerability scanner; recommend patches, file risk acceptances, and gather evidence to close out remediations • Co-own Cobalt's SOC 2 program — coordinate with auditors, gather evidence from internal teams, and run control testing (SSO, IAM, change management, access reviews) ahead of fieldwork • Maintain Cobalt's security policies (vulnerability management, logging and monitoring, incident response, access control), keep them current as the business evolves, and draft new policies when we identify gaps • Own the customer security questionnaire pipeline — partner with Sales, GTM, and product leads to turn around SIG, CAIQ, and bespoke vendor assessments quickly and accurately • Run vendor security reviews for new software and services Cobalt adopts, with clear turnaround expectations and a process the rest of the company can rely on • Triage suspected phishing reports and serve as incident manager when something happens — scope, contain, document, and run the postmortem • Own annual security awareness training rollout and tracking across the company • Partner with Engineering to secure the Cobalt Monitoring Intelligence platform at the edge and bring security perspective into design and code review • Support pen test engagements end-to-end: scoping, remediation tracking, and re-test follow-up

California
$160K - $190K / year
DuckDuckGo logo

Senior Web Security Engineer, Browser Platform

DuckDuckGo

Independent internet privacy company. Download our browser with privacy built-in, unlike Chrome, on mobile & desktop.

Security Engineer174 days ago
OtherRemoteTeam 51-200Since 2008H1B No Sponsor

• Conduct browser security audits (special pages, DuckAI integrations, password manager, etc.) • Execute on SERP security mitigations (XSS prevention, tooling development to help engineers write safer code) • Manage application security scanning infrastructure setup (aka SAST/DAST integrations in GitHub) • Deliver on Internal red-team operations (simulated attack scenarios) • Support security triage

United States
$178.5K / year
Full TimeRemoteTeam 5,001-10,000H1B No Sponsor

• Diseñar e implementar prácticas de Seguridad en la Nube y DevSecOps • Asegurar la seguridad de los datos en entornos de nube • Desarrollar flujos de trabajo automatizados de detección y respuesta

Spain