InstantServe LLC logo
InstantServe LLC

Changing People, Processes & Perceptions.

Security Compliance Engineer

Security EngineerSecurity EngineerFull TimeRemoteMid LevelTeam 51-200H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

6 days ago

Salary

0

Seniority

Mid Level

Job Description

Security Compliance Engineer

InstantServe LLC

Role Description The Security Compliance Engineer is responsible for: - Vulnerability Management & Assessment: - Continuously monitor the analytics environment for vulnerabilities using approved scanning and assessment tools. - Coordinate with the central security team to prioritize findings, track remediation efforts, and ensure timely resolution in compliance with organizational policies. - Coordinate with product teams to provide vulnerability remediation and guidance. Research and present mitigation strategies. - Compliance Coordination & Documentation: - Maintain, update, and track the status of POA&Ms for all identified vulnerabilities within the analytics landscape. - Ensure timely and accurate reporting of compliance posture for internal and external audits. - Drive the implementation and continuous assessment of FedRAMP and NIST 800-53 controls across the analytics environment. - Prepare evidence and documentation for audit, and support all phases of the compliance lifecycle. Qualifications - Proficiency in Databricks configuring Private Link, Databricks cluster logging, Serverless egress controls, and using Customer Managed Keys. - AWS Guardrails with Bedrock, GuardDuty, Inspector, Config, Security Hub, Inspector, CloudTrail, and CloudWatch. - Strong awareness of IL4 compliance, risk management, and cloud-native security best practices. Company Description

Related Categories

Related Job Pages

More Security Engineer Jobs

PLACE logo

Security Engineer

PLACE

Everything Home - All in one PLACE

Full TimeRemoteTeam 201-500Since 2020H1B Sponsor

• Configure and operate security scanning tools to effectively identify and analyze vulnerabilities • Remediate infrastructure vulnerabilities as they appear and put in place process to preemptively avoid recurrence • Triage, investigate, and escalate security alerts with remediation recommendations • Document procedures, best practices, and technical security standards • Collaborate with internal and external engineering teams to optimize alert rules and monitoring coverage • Provide technical thought leadership regarding the security of networks and systems • Identify scanning and monitoring gaps as well as ensuring all our dependencies are being fully audited • Support debug/testing and remediation management to enhance infosec posture • Participate in an after-hours on-call rotation to investigate and triage security alerts • Develop a deep knowledge of organizational systems, environments, and security tools • Ensure that products and services meet established security standards set by the company • Monitor networks and systems for intrusions and implement protection and recovery methods • Identify and advise on security risks associated with new development or system changes • Assist in providing access to users and applications using our security standards and best practices

United States
$140K - $180K / year
Job Closed
Quisitive logo

Digital Security Coach

Quisitive

Quisitive is a technology company helping customers generate transformational impact with immense value through cloud and payment solutions. A global company, Q

• Lead recurring customer security coaching sessions, including tactical reviews, advisement sessions, and executive-level security discussions. • Review threats, incidents, posture trends, identity risks, compliance insights, and Microsoft security telemetry to identify meaningful areas for improvement. • Translate technical findings into clear, business-focused recommendations, roadmaps, and next steps. • Partner with MDR/SecOps, Customer Success Managers, consultants, and analysts to align customer priorities, risks, workstreams, and communication plans. • Help customers improve their understanding of their security environment and the effectiveness of their tools, processes, and controls. • Review and provide guidance across Microsoft security capabilities, including Microsoft Defender XDR, Microsoft Sentinel, Microsoft Entra ID, Microsoft Purview, Conditional Access, MFA, PIM, email security, insider risk, and cloud app governance. • Build and maintain customer-specific security roadmaps tied to licensing, budget, risk priorities, compliance drivers, and measurable outcomes. • Conduct security architecture and adoption planning to help customers optimize the value of their Microsoft tools and licenses. • Analyze security trends and make recommendations related to external and internal threats, including malware, identity-based risk, data leakage, and attack surface reduction. • Prepare advisement materials, tactical decks, quarterly executive summaries, and customer-facing recommendations using evidence from dashboards, analytics tools, KQL queries, reports, and telemetry trends. • Guide client conversations toward additional security enhancements, roadmap initiatives, and continuous improvement opportunities. • Monitor customer security issues, escalations, and requests, validating context and converting learnings into repeatable guidance. • Contribute to playbooks, best practices, and coaching materials while mentoring supporting consultants or analysts as needed.

United States
Full TimeRemoteTeam 1,001-5,000Since 2005H1B Sponsor

• Own US customer trust operations: Manage intake, triage, prioritization, and completion of customer security questionnaires, vendor risk assessments, and RFIs for US-based customers. • Respond to customer security inquiries with technical depth: Complete questionnaires accurately, respond to RFIs, and address customer security concerns with responses that demonstrate understanding of Smartsheet's architecture and security controls. • Manage questionnaire queue and ensure SLA compliance: Maintain visibility into pending assessments, track completion timelines, and escalate delays. Keep customers informed of progress and manage expectations. • Build customer relationships and provide security assurance: Become a trusted resource for customer security teams. Understand their compliance requirements, ask clarifying questions, and provide responses that build confidence in Smartsheet's controls. • Support US sales teams: Work with sales and customer success teams to remove security-related deal blockers, provide compliance assurance materials, and accelerate customer buying cycles. • Escalate and collaborate on complex assessments: Identify questions requiring specialized expertise (AI security, FedRAMP, HIPAA, specific control implementations) and escalate appropriately. Work cross-functionally to gather evidence and provide comprehensive responses. • Understand industry-specific compliance: Respond to questions about HIPAA, NIST, state privacy laws (CCPA, etc.), PCI DSS, and sector-specific requirements relevant to customer industries. • Drive process improvements: Identify opportunities to improve questionnaire completion efficiency, update response templates, and recommend changes that benefit the team and customer experience.

United States
$145K - $210K / year
Mollica IT logo

Senior SAP Security Consultant – GRC/AC

Mollica IT

Recrutando talentos de tecnologia & conectando histórias

Full TimeRemoteTeam 11-50Since 2013H1B No Sponsor

• Gather and analyze requirements together with business areas; • Convert functional requirements into technical requirements, preparing high- and low-level architecture documents; • Participate in alignment meetings and requirements-gathering sessions with business users; • Facilitate Fit-to-Standard workshops; • Validate requirements in the system and in the SAP Fiori application library, ensuring end-to-end coverage of functionalities in Solution & Architecture documents; • Execute exploratory testing to ensure consistency of functional design documents; • Update design documents during functional testing, defect remediation, integration testing, and UAT; • Create, review, and update SAP authorization concepts; • Contribute to the creation and review of training materials; • Provide support during Hypercare activities; • Perform other routine activities within the area.

Brazil