Why This Role Stands Out
You will lead the design and implementation of critical enterprise security controls, significantly enhancing the organization's security posture and ensuring compliance with diverse industry frameworks. This role is ideal for a security professional eager to drive innovation in cloud, infrastructure, and identity security within a reputable company. Apply now to make a substantial impact and advance your career in a dynamic environment.
Quick Overview
Job Description
This is a permanent opportunity that will require someone to be on site 5 days a week initially. The Senior Information Security Engineer is responsible for designing, implementing, and managing enterprise security controls that support regulatory compliance and strengthen the organization''s overall security posture. This role leads the implementation of security technologies across cloud, infrastructure, identity, and endpoint environments while supporting compliance with SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001, CSA STAR Level 2, Cyber Essentials+, HIPAA, and other industry frameworks.
Key Responsibilities
Design, implement, and maintain enterprise security controls aligned with industry standards and compliance requirements.
Lead Identity and Access Management (IAM), including RBAC, privileged access management (PAM), access governance, and identity lifecycle management.
Manage secure authentication solutions, including MFA, SSO, federation, and certificate-based authentication.
Administer endpoint and cloud security technologies, including antivirus, EDR/XDR, malware protection, and threat detection.
Develop and maintain Data Loss Prevention (DLP) strategies across endpoints, email, networks, and cloud environments.
Oversee vulnerability management, including scanning, risk prioritization, remediation tracking, patch management, and penetration test coordination.
Establish secure configuration management processes, including security baselines, change control, compliance monitoring, and Infrastructure as Code (IaC) validation.
Partner with Infrastructure leadership and the CISO to design and implement security controls for Azure and Google Cloud Platform (Google Cloud Platform).
Support physical security technologies and integrate physical and logical access controls.
Assist with security assessments, audits, certifications, and remediation activities while working with internal stakeholders and external auditors.
Provide technical leadership and mentor security team members on security best practices and continuous improvement initiatives.
Technical Expertise
Enterprise IAM, RBAC, ABAC, PAM, and identity governance
MFA, SSO, SAML, OAuth 2.0, OpenID Connect (OIDC), PKI, and certificate management
Endpoint security, EDR/XDR, threat intelligence, malware protection, and incident response
Data Loss Prevention (DLP), encryption, tokenization, and data classification
Configuration management, security baselines, compliance automation, and IaC security
Vulnerability management, patch management, penetration testing, and remediation
Physical access control systems (PACS) and integrated security monitoring
Compliance & Security Frameworks
Experience supporting security programs aligned with:
SOC 2 Type II
ISO/IEC 27001
ISO/IEC 42001
CSA STAR Level 2
Cyber Essentials+
HIPAA
NIST Cybersecurity Framework (CSF)
CIS Controls
MITRE ATT&CK
Qualifications
Bachelor''s degree in Computer Science, Information Security, or a related field (or equivalent experience).
5–7 years of information security, including hands-on implementation of enterprise security controls plus 3 years of leadership experience.
Experience securing cloud environments (Azure and Google Cloud Platform) and enterprise infrastructure.
Knowledge of Zero Trust architecture, DevSecOps, AI/ML security, and security automation.
Proficiency with scripting and automation tools such as Python, PowerShell, Bash, or Terraform.
Similar jobs
- RF
EDR Engineer / Senior EDR Engineer
NewRecorded Future
Remote - USA🇺🇸Remote5 hours agoGCPAWSSplunk+8Engineering - PO
Security Operations Specialist
NewPoint72
New York🇺🇸5 hours agoSplunkAgileArticulateOperations & Project Management - GT
Asset Protection Specialist (Full Time)
NewGreen Thumb
Dracut🇺🇸3 hours agoBackground ChecksComplianceHIPAA+4 - VE
IAM Architect
NewVeridianTech
United States🇺🇸Hybrid19 hours agoSAFeMFAOAuth+13 - IT
IAM Engineer
NewIntellisoft Technologies
New York, NY🇺🇸On-site19 hours agoOAuthTechnology - SH
Physical Security/Information Assurance Specialist with Security Clearance
NewSystem High Corporation
Andrews AFB, MD🇺🇸Hybrid19 hours agoAdministrative