3Pillar Global logo
3Pillar Global

Building digital businesses, together.

Senior Information Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000H1B SponsorCompany SiteLinkedIn

Location

Romania

Posted

3 days ago

Salary

0

Seniority

Senior

4 yrs expEnglishAzureCloudSDLC

Job Description

Senior Information Security Engineer

3Pillar Global

• Own the end-to-end vulnerability management program across our SaaS products, cloud infrastructure, containers, and endpoints including identification, triage, prioritization, remediation tracking, and reporting • Operate and tune SAST, SCA, and dependency-scanning tooling (e.g., Snyk, GitHub Advanced Security/Dependabot) and partner with engineering teams to drive timely remediation • Monitor runtime and infrastructure telemetry (e.g., Datadog) for security signals; investigate alerts and lead containment and follow-up actions • Track and report on vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership • Enhance the security posture of our Microsoft Azure environment including identity, networking, data, and workloads through configuration hardening, policy enforcement, and continuous monitoring • Administer and improve Microsoft Intune for endpoint configuration, compliance, and mobile device management • Tune and maintain Microsoft Defender (Endpoint, Cloud, and related products) for threat detection, response, and reporting • Implement and operate Microsoft Purview controls for data classification, DLP, and information protection • Draft, update, and maintain corporate information security policies, standards, and procedures aligned to recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF) • Lead the response to customer and prospect security questionnaires, RFPs, and due-diligence requests, and maintain a reusable response library • Support vendor risk assessments and third-party security reviews • Assist with internal and external audits, evidence collection, and remediation of findings • Partner with Engineering on secure SDLC practices, threat modeling, and code review guidance • Contribute to security awareness training, phishing simulations, and a strong security culture across the company • Help mature incident response playbooks and participate in tabletop exercises and on-call rotations as needed

Job Requirements

  • 4–6 years of professional experience in information security, application security, cloud security, or a closely related role
  • Hands-on experience securing SaaS applications and workloads running in Microsoft Azure
  • Demonstrated experience with vulnerability management tooling and process including triage, prioritization (e.g., CVSS, EPSS, exploitability context), and driving remediation through engineering teams
  • Working proficiency with several of the following: Microsoft Intune, Microsoft Defender (Endpoint/Cloud), Microsoft Purview, Datadog, GitHub (Advanced Security, Dependabot, code scanning), and Snyk
  • Solid understanding of identity and access management concepts, particularly Microsoft Entra ID (Azure AD), conditional access, and least-privilege design
  • Experience writing or substantially contributing to security policies, standards, or procedures
  • Experience responding to customer security questionnaires and supporting compliance efforts (SOC 2, ISO 27001, or similar)
  • Strong written and verbal communication skills and able to translate technical risk for both engineers and non-technical stakeholders.

Benefits

  • flexible work environment
  • focus on wellbeing with fitness offerings and mental health plans (country-dependent)
  • generous time off
  • career growth and development opportunities

Related Categories

Related Job Pages

More Security Engineer Jobs

10x.Team logo

Security Architect – AI Trainer, Freelance

10x.Team

Built for Humans. Powered by AI. The AI Recruiter that takes over first interviews — fast, fair, and compliant.

ContractRemoteTeam 11-50Since 2023H1B No Sponsor

• Review and refine AI-generated outputs related to security architecture, cyber risk assessments, mitigation strategies, and practical aspects of security design • Evaluate AI responses for accuracy, practicality, and compliance with real-world security requirements • Draft realistic security architecture scenarios based on your direct professional experience • Create scenario variations from different perspectives (e.g. security architect, client, IT leader, or regulator) • Identify gaps, oversights, or weak reasoning in AI-generated security content

Spain
€103 - €159 / hour
1Password logo

Security Engineer Intern, Application Security

1Password

Productive businesses use 1Password to secure employees at scale.

InternshipRemoteTeam 501-1,000Since 2009H1B Sponsor

• Validate incoming security findings from the broader research community using code analysis tooling or other industry standard pentesting tooling e.g. burpsuite. • Work with engineering teams to remediate valid findings in our codebase (product). Respond to security researchers, help with public disclosure. • Build or improve upon new automated workflows and tooling, leveraging LLMs for vulnerability triage, validation, remediation in any of rust, golang, python, etc.

California + 1 moreAll locations: California | Texas
Devoted Studios logo

Infrastructure & Endpoint Security Engineer

Devoted Studios

Creating equal opportunity for talent to work on games of their dreams

Full TimeRemoteTeam 51-200H1B No Sponsor

• Design and maintain secure network and infrastructure architecture; • Configure and manage firewalls, VPNs, access controls, and network segmentation; • Secure servers, cloud resources, containers, and virtual machines; • Secure employee workstations and enforce security baselines; • Monitor endpoints and infrastructure for suspicious activity; • Collect, analyze, and correlate security logs; • Detect, investigate, and respond to security incidents; • Perform vulnerability analysis, risk assessment, and remediation; • Conduct system and network hardening; • Develop and deliver internal security trainings and awareness sessions; • Manage and maintain security training platforms and learning content; • Organize phishing simulations and awareness campaigns; • Collaborate with IT, DevOps, Infrastructure, and HR teams; • Complete and review clients security questionnaires and security assessment forms to demonstrate the company’s security posture; • Participate in security and compliance calls with client information security specialists and stakeholders. **Monitoring & Incident Response:** - Set up and maintain security monitoring and alerting; - Investigate anomalies and security incidents; - Perform root-cause analysis and post-incident reviews; - Improve detection, response, and prevention processes. **Security Awareness & Training:** - Plan and deliver security awareness programs; - Manage training platforms and user enrollment; - Track training completion and effectiveness; - Continuously improve training materials based on incidents and risks.

Ukraine
Full TimeRemoteTeam 10,001+Since 1931H1B Sponsor

• Define, drive, and execute product strategy and roadmap for cybersecurity and control platforms • Translate enterprise risk priorities, threat scenarios, and regulatory requirements into product capabilities and control solutions • Ensure alignment between product outcomes, risk reduction, and business resilience objectives • Act as the voice of the customer, representing the needs of control owners, engineers, risk partners, and business stakeholders • Engage in continuous discovery, test-and-learn, and feedback loops to validate assumptions and refine product direction • Build strong partnerships across Product Security, Cyber Operations, Technology Risk, and engineering teams • Decompose complex problems into manageable work items and maintain a prioritized product backlog • Lead iterative, outcome-based delivery using agile and test-and-learn methodologies • Provide clear direction, timely feedback, and alignment across cross-functional teams • Ensure controls are designed with clear linkage to risk scenarios, exposure conditions, and business outcomes • Enable standardized control onboarding, lifecycle management, and adoption across domains • Define and manage KPIs to measure control effectiveness, risk reduction, and product adoption

United States
$120K - $193.7K / year
Job Closed