Keyfactor logo
Keyfactor

Identity-first security for every machine.

Information Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 201-500Since 2014H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

1 day ago

Salary

0

Seniority

Senior

Job Description

Information Security Engineer

Keyfactor

• Experience conducting vulnerability assessments, system audits, and risk analysis using industry-standard scanning tools (e.g., Nessus, Azure security tools, Tenable, Burpsuite, etc…) to support a proactive security posture. • Manage and implement continuous monitoring processes to ensure the organization maintains compliance with a variety of information security frameworks, including ISO 27001:2022 and SOC 2 Type II. Experience with government compliance standards such as FedRAMP (NIST SP 800-53) and CMMC is preferred. This role focuses on ensuring robust security practices and adapting to evolving compliance requirements. • Collaborate closely with IT, DevOps, Engineering, and Compliance teams to enforce security policies, procedures, and best practices. • Actively monitor, analyze, and respond to security alerts and incidents, performing investigations, incident handling, and recommending corrective actions. • Provide expert guidance on security matters to support secure development and operations.

Job Requirements

  • 5+ years of experience in information security or a similar role
  • Proficiency in vulnerability scanning tools (Nessus, Burpsuite, Tenable, etc…) and interpreting scan results for remediation.
  • Strong knowledge of security standards
  • Demonstrated experience in continuous monitoring, network security, firewalls, VPNs, IDS/IPS, and endpoint protection.
  • Strong analytical skills and a meticulous approach to problem-solving.
  • Demonstrated capability to deliver results on-time and to a defined schedule.
  • Relevant certifications (e.g., CISSP, CompTIA Security+, CAP) are strongly preferred.
  • Familiarity with cloud security principles.
  • Experience with security automation and continuous monitoring tools.
  • PKI knowledge a plus.
  • Knowledge of scripting languages (Python, PowerShell) to automate security processes.
  • Experience in STIG configuration & implementation, and best practices for implementing these in various environments preferred.
  • Expertise in Government related InfoSec compliance frameworks such as NIST 800-53, NIST 800-171 preferred.
  • Experience with government-regulated environments (AWS GovCloud, Azure Government) preferred.

Benefits

  • Second Fridays (a company-wide day off on the second Friday of every month minus November and December due to the Holiday schedule). Please note that this benefit is subject to change.
  • Comprehensive benefit coverage globally.
  • Generous paid parental leave globally.
  • Competitive time off globally.
  • Dedicated employee-focused ambassadors via Key Contributors & Culture Committees.
  • DIVERSE Commitment, a call to action for a more inclusive and diverse future in business, society, and technology.
  • The Keyfactor Alliance Program to support DEIB efforts.
  • Wellbeing resources, wellness allowance, mindfulness app free membership, Wellness Wednesdays.
  • Global Volunteer Day, company non-profit matching, and 3 volunteer days off.
  • Monthly Talent development and Cross Functional meetings to support professional development.
  • Regular All Hands meetings – followed by group gatherings.

Related Categories

Related Job Pages

More Security Engineer Jobs

Relewant logo

Cybersecurity Architect

Relewant

Saremo il tuo Skill Integrator

Full TimeRemoteTeam 11-50Since 2001H1B No Sponsor

• Coinvolgimento in attività di design, integrazione e governance di soluzioni CyberSecurity in contesti enterprise complessi

Switzerland
KATBOTZ® logo

SAP Security & Authorization Consultant – SAP GROW, SAP S/4HANA Public Cloud

KATBOTZ®

Driving Customer Success Through Finance Transformation: Advanced Processes, Analytics, & AI.

ContractRemoteTeam 1-10Since 2021H1B No Sponsor

• Design and implement SAP security and authorization frameworks for SAP S/4HANA Public Cloud. • Define role-based access control (RBAC) models aligned with business processes. • Configure and maintain: Business Roles Business Catalogs Business Spaces Authorization Assignments Fiori Launchpad Access User Access Controls • Ensure secure access to SAP applications and business processes. • Support security design during Fit-to-Standard workshops. • Define authorization concepts aligned with SAP Best Practices. • Support SAP Central Business Configuration (CBC) security requirements. • Perform Segregation of Duties (SoD) assessments. • Identify and mitigate security and compliance risks. • Develop security documentation and access control procedures. • Manage user provisioning, deprovisioning, and access reviews. • Troubleshoot authorization and access-related issues. • Provide post-go-live support and hypercare.

United States
Full TimeRemoteTeam 51-200Since 2007H1B No Sponsor

• serves as a cybersecurity Subject Matter Expert (SME) with regards to Assessment and Authorization (A&A) of information systems and all associated cybersecurity policies and procedures. • performs a DOD cybersecurity process while either authorizing an information system or serving as a SME for an information system undergoing authorization. • possesses an understanding of how the security controls identified in the NIST 800-53 apply to the process of assessing and authorizing a large organization’s IT infrastructure such as DLA’s. • determines the applicable severity value for an identified vulnerability (e.g., non-compliant security control). • determines the possible ramifications on the system’s current or future authorization. • briefs senior management on the progress or results of an information system undergoing the Risk Management Framework (RMF) process.

Alabama
$115K - $140K / year
Full TimeRemoteTeam 10,001+Since 1933H1B No Sponsor

• Lead a team of risk, compliance, and privacy experts who partner with global technology teams and business leaders in the execution of Ryder’s Information Security Management System • Lead the development and ongoing management of common control and risk management frameworks for measuring the organizational security posture based on industry, regulatory, and customer needs • Serve as a trusted partner to educate and collaborate on information security and risk management best practices with stakeholders in Corporate Compliance, Enterprise Risk Management, Internal Audit, Physical Security and Safety, Legal, and IT • Lead the development and ongoing management of global information security policies and corporate standards throughout the organization that align with industry guidance and result in effective methods to reduce security risks • Lead the development and management of a global third-party risk management program to evaluate new and existing vendors on a regular basis based on their criticality to the business • Lead the development and management of a global information security customer compliance program which facilitates the processes for handling customer requests for information security attestations, audits, on-site reviews, and remediation of security findings • Lead the development and management of a modern, engaging, global information security training and awareness program to provide ongoing information security education to all levels of the organization • Lead the development and management of an IT enterprise risk register to properly catalog, manage, communicate, and assess global IT risks

Florida
$100K - $130K / year