CorVel Corporation logo
CorVel Corporation

Raising the bar for care. Lowering risk for clients.

Info Security Engineer II

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000Since 1987H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

3 days ago

Salary

$87.2K - $134.6K / year

Seniority

Senior

Bachelor Degree3 yrs expEnglishCloud

Job Description

Info Security Engineer II

CorVel Corporation

• Foster information security practices and procedures across the organization • Research, analyze, and formulate recommendations for technologies, products, and solutions to enable business • Provide technical inputs, system security controls, evaluate and recommend new and emerging security products and technologies • Work with engineering teams to threat model technical designs and implementation of solutions • Act as a subject matter expert and partner with other engineers to select appropriate security controls • Further mature and maintain vulnerability management processes and metrics • Assist with a variety of risk assessments • Assist with vendor risk assessments, and provide customer assurance • Other duties as assigned

Job Requirements

  • 3 - 5 years of experience in information security
  • Specific experience with two or more of the following areas: Threat modeling, Secure system design and development, System security assessments, Vulnerability management, Security risk management
  • Experience with FIPS, NIST 800-53/CSF, or other relevant frameworks
  • Notable cloud security experience
  • Relevant security certification preferred (CC, CompTIA Security+, CISSP, SANS, etc.)
  • Outstanding written and spoken communication skills.

Benefits

  • Medical (HDHP) w/Pharmacy
  • Dental
  • Vision
  • Long Term Disability
  • Health Savings Account
  • Flexible Spending Account Options
  • Life Insurance
  • Accident Insurance
  • Critical Illness Insurance
  • Pre-paid Legal Insurance
  • Parking and Transit FSA accounts
  • 401K
  • ROTH 401K
  • Paid time off

Related Categories

Related Job Pages

More Security Engineer Jobs

Secfix logo

Senior Information Security Specialist, German-speaking

Secfix

The fastest way to get ISO 27001 compliant | Compliance & Security Automation

Full TimeRemoteTeam 11-50H1B No Sponsor

• Own and drive the compliance roadmap inside the Secfix platform across different compliance frameworks (ISO 27001, TISAX, SOC 2, GDPR, NIS 2, DORA, ISO 27017/27018, ISO 42001, C5, and more as we expand) • Implement ISO 27001 and adjacent frameworks end-to-end for customers • Mentor and upskill the compliance team: sharing expertise, reviewing work, and helping drive consistency in audits and customer deliverables • Conduct internal audits directly for strategic and complex customers, and review the internal audits performed by junior team members to drive quality and consistency • Act as a compliance partner to CSMs and sales reps: fast, reliable support for customer questions, and joining customer calls when deep expertise is needed • Own the quality of compliance content in the platform (including creating policies, evidence templates, Compliance enable playbooks for our CSMs, security awareness trainings and more) • Close framework gaps and incorporate auditor feedback into both team practice and platform improvements • Partner with product and engineering to translate compliance gaps into structured product work • Collaborate closely with CS, Product, and Founders to align compliance, customer, and roadmap priorities • Deepen relationships with our existing certification partners and train auditors on the Secfix platform so they can confidently use it during customer audits

Germany
GovCIO logo

Information Systems Security Officer

GovCIO

GovCIO is a service-disabled-veteran-owned small business (SDVOSB) that offers technology services to improve business performance for government organizations.

Role Description GovCIO is currently hiring for an Information Systems Security Officer (ISSO) to support our client’s contract needs. The ISSO ensures the confidentiality, integrity, and availability of HUD information systems by executing the NIST Risk Management Framework (RMF), supporting system authorization activities, conducting continuous monitoring, and coordinating remediation efforts with system owners and technical teams. Key responsibilities include: - Support and execute all phases of the NIST SP 800-37 RMF lifecycle including categorization, control selection, implementation, assessment, authorization, and continuous monitoring. - Develop, maintain, and update RMF documentation in JCAM including System Security Plans, Security Assessment Plans, Security Assessment Reports, POA&Ms, Configuration Management Plans, Contingency Plans, Incident Response Plans, Risk Assessment documentation, and interconnection documents. - Establish system impact levels following FIPS 199 for confidentiality, integrity, and availability. - Ensure systems comply with FISMA, NIST SP 800-53 Rev 5, OMB A-130, and applicable agency cybersecurity policies. - Prepare and maintain Body of Evidence materials and control traceability documentation in JCAM. - Support Authorization to Operate (ATO), Authority to Connect (ATC), and ongoing authorization activities; maintain associated documentation in JCAM. - Review and analyze vulnerability scan results using Tenable Security Center. - Validate asset inventories and correlate system information. - Validate secure configuration baselines and system hardening standards. - Track remediation activities and ensure POA&M items and milestones are created, updated, and closed on schedule. - Review endpoint security posture and support investigations by correlating endpoint findings with vulnerability, configuration, and CDM data. - Provide security reporting, dashboards, and status updates to system owners and leadership. - Support configuration management processes by reviewing and assessing change requests for security impact. - Ensure security controls are implemented correctly during system changes, upgrades, or new deployments. - Stay informed on emerging cybersecurity policies, standards, and threat landscapes; provide recommendations for improving security posture. - Collaborate with technical and non-technical personnel to review systems, gather evidence, and communicate security requirements. Qualifications - Bachelor’s degree in IT, Cybersecurity, Computer Science, or related field (or equivalent experience) with 5-8+ years or (commensurate experience). Requirements - 2–3 years in an ISSO or cybersecurity compliance role supporting RMF process. - Strong understanding of NIST 800-53 controls and assessment procedures. - Experience collecting, developing and maintaining RMF artifacts. - Experience managing POA&Ms and documenting remediation efforts. - Experience reviewing, interpreting, or validating vulnerability and configuration findings. - Clearance Required: Ability to obtain and maintain a HUD Public Trust clearance. Preferred Qualifications - CISSP, CISM, or similar advanced certification. - Experience supporting federal authorization packages. - Familiarity with CDM reporting and continuous monitoring processes. - Experience supporting secure development or cloud system reviews. Posted Salary Range USD $90,000.00 - USD $110,000.00 /Yr.

United States
$90K - $110K / year
Employment Hero logo

Security GRC Engineer

Employment Hero

Employment Hero is an HR-focused technology company on a mission to create a "better world at work" and change what people expect from employment. Beckoning qua

Role Description Employment Hero is seeking a Security GRC Engineer to join our Information Security department. In this build-centric and technical position, you will be responsible for engineering the integrations, tooling, and automation that power our GRC program. You will collaborate with our Audit Specialist to ensure our compliance is continuous, verifiable, and automated, reducing manual effort across the board. This role offers true ownership of our compliance automation from the start. You will transform control monitoring and evidence gathering into functional code while integrating the core systems that support our certifications. This is an ideal opportunity for an engineer with a compliance background, or a GRC expert who enjoys building, to scale automated security operations within a high-growth environment. As a GRC Analyst, you will be involved in: - Audit & Compliance Operations - Build and extend our in-house GRC automation platform (Python services on cloud infrastructure) that automates evidence collection, control checks, compliance letters and lost-device handling. - Build and run LLM-based tooling that reviews controls for evidence gaps and routes them to the right owners. - Own the day-to-day maintenance of Vanta: keep controls current, collect evidence from stakeholders, and manage control statuses across our certification portfolio. - Support audit preparation across our ISO and SOC 2 programs: prepare documentation, track auditor requests, and keep audit cycles on schedule. - Coordinate evidence collection and follow-ups with internal teams so that nothing is missed. - Maintain and report on compliance posture (control health, overdue evidence, vendor review status) to the security team. - Risk & Vendor Support - Assist with risk assessments: document, track, and follow up on identified risks in our GRC tooling. - Support third-party and vendor risk processes: coordinate vendor questionnaires, track review status, and maintain vendor registers. - Policy & BAU - Help maintain and review information security policies: flag outdated content, track review cycles, and support updates where needed. - Assist with broader GRC BAU tasks as the team’s needs evolve. Qualifications - A relevant degree or certification (e.g. CompTIA Security+, ISO 27001, ISO 27701, ISO 42001 Lead Auditor, Certified in Cybersecurity). - A background in constructing LLM-based solutions and the ability to execute end-to-end automation of manual workflows are highly valued assets. - 2 – 4 years in a GRC, compliance, or audit role (analyst, coordinator, or similar). - Experience working in a tech, SaaS, or scale-up environment. - Familiarity with Vanta or similar compliance automation tools (e.g. Drata, Tugboat Logic) is a strong plus. - A working understanding of frameworks like ISO 27001 or SOC 2. You do not need to be an expert, but you should know the basics. - Exposure to privacy or AI governance frameworks such as ISO 27701, 27018, or 42001. - Strong attention to detail and reliable follow-through. Organised and self-directed, able to manage multiple workstreams at once. - Clear communicator who is comfortable chasing stakeholders, asking questions, and keeping people accountable in a friendly but persistent way. - Eager to learn and open to feedback, with a genuine drive to grow in information security. The technical depth can be built, the mindset needs to be there. - A strong focus on continuous improvement, with a proven ability to challenge the status quo constructively. Benefits - You will work remotely, with the flexibility to own your time and impact. - You will access cutting-edge tools to amplify your work, knowledge and outputs. - You’ll surround yourself with ambitious, outcome-driven colleagues who challenge you to do the best work of your life. - You’ll own ESOP (employee share options) in one of the world’s fastest-growing tech companies. - You’ll also have access to a wide range of benefits that includes: - A very generous parental leave policy. - Subsidised egg freezing (so you can make the choice that’s right for you, on your terms). - A WFH office expense budget. - Outstanding learning & development opportunities.

Asia Pacific
Circle logo

Security Engineer II, Detection and Response

Circle

Circle helps businesses and developers harness the power of stablecoins for payments and internet commerce worldwide.

Full TimeRemoteTeam 501-1,000Since 2013H1B Sponsor

Circle (NYSE: CRCL) is one of the world's leading internet financial platform companies, building the foundation of a more open, global economy through digital assets, payment applications, and programmable blockchain infrastructure. Circle's platform includes the world's largest regulated stablecoin network anchored by USDC, Circle Payments Network for global money movement, and Arc, an enterprise-grade blockchain designed to become the Economic OS for the internet. Enterprises, financial institutions, and developers use Circle to power trusted, internet-scale financial innovation. Learn more at circle.com . What you'll be part of: Circle is committed to visibility and stability in everything we do. As we grow as an organization, we're expanding into some of the world's strongest jurisdictions. Speed and efficiency are motivators for our success and our employees live by our company values : High Integrity, Future Forward, Multistakeholder, Mindful, and Driven by Excellence. We have built a flexible work environment where new ideas are encouraged and everyone is a stakeholder. What you'll be responsible for: The Circle Security Team works to protect Circle; our customers, clients, and partners; and the financial markets upon which we rely. As a member of this team, you'll lead projects and be responsible for key deliverables of the security program while collaborating across Circle teams. You will continue to learn and stay current in a fun and rapidly changing environment. Also note that this position will require you to perform on-call duties mainly during working hours to support security operations, and you will assist the team with the occasional night time and weekend incident. We would also like someone with a strong response background and some exposure to insider risk. What you'll work on: - Proactively identify and respond to emerging security threats. - Advance deployment of AI to SOC function. - Help manage core tooling, such as SIEM and Orchestration platforms. - Identify gaps in our infrastructure, and work with business partners to gain visibility through logging and detection. - Respond to incidents and collaborate across teams to investigate and resolve. - Develop detection techniques to identify anomalous behaviors and attacks across the environment. - Support broader security team projects such as threat modeling, vulnerability scanning, audits, and custom tool building. - Take on-call shifts. What you'll bring to Circle: - Strong ability to work collaboratively across teams during high-stress situations, which sometimes involves after hours work. - Ability to manage multiple competing priorities and use good judgment to establish order of priorities on the fly. - Self-motivated and creative problem-solver able to work independently with minimal guidance. - Experience/familiarity with Slack, Apple MacOS, and GSuite. We're looking for strong, impactful work experience, which typically includes: - 2+ years of experience in detection, response, or security engineering. - Experience working security incidents, especially those involving engineering. - Experience working in an AWS + EKS environment required. - Hands-on experience using AI tooling both to accelerate work and to address threats, coupled with a strong understanding of the organizational risks AI introduces and strategies to defend against them. - Knowledge of operating systems, file systems, and memory on MacOS. - Programming experience in Python, Golang, or similar programming languages. - Professional or hobbyist blockchain exposure is preferred. You are the right person if you: - View Security Detection & Response as a data and engineering problem. - Exude positivity. - Aren't afraid to share your ideas. - Meet problems head-on and view them as opportunities. - Are self-reliant and motivated. - Communicate fearlessly. Circle is on a mission to create an inclusive financial future, with transparency at our core. We consider a wide variety of elements when crafting our compensation ranges and total compensation packages. Starting pay is determined by various factors, including but not limited to: relevant experience, skill set, qualifications, and other business and organizational needs. Please note that compensation ranges may differ for candidates in other locations. Base Pay Range: $122,500 - $165,000 We are an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status, or any other protected status required by the laws in the locations where we hire. Additionally, Circle participates in the E-Verify Program in certain locations, as required by law. Should you require accommodations or assistance in our interview process because of a disability, please reach out to accommodations@circle.com for support. We respect your privacy and will connect with you separately from our interview process to accommodate your needs. #LI-Remote

Texas + 5 moreAll locations: Texas | Arizona | Oregon | Washington | California | Canada