Information Security Engineer
Posted 1hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Information Security Engineer securing Keyfactor’s cryptographic trust infrastructure. Managing monitoring, vulnerability assessments, incident response, and ISO 27001/SOC 2 compliance.
Responsibilities:
- Evaluate the security posture of systems, platforms, and cloud environments; establish security baselines and drive implementation and hardening to close identified gaps.
- Develop proficiency in SIEM, EDR, and other security platforms; configure, tune, and integrate tools with SaaS applications and diverse data sources.
- Evaluate and optimize security playbooks, runbooks, and processes based on lessons learned, tooling changes, and evolving threats.
- Conduct vulnerability assessments, system audits, and risk analysis using industry-standard scanning tools.
- Manage and implement continuous monitoring processes supporting compliance with ISO 27001:2022 and SOC 2 Type II.
- Monitor, analyze, and respond to security alerts and incidents; perform investigations, incident handling, and recommend corrective actions.
- Safeguard organizational data and infrastructure while driving adherence to evolving security best practices.
Requirements:
- 5+ years of experience in information security or a similar role
- Proficiency in vulnerability scanning tools (Nessus, Burpsuite, Tenable, etc…) and interpreting scan results for remediation.
- Strong knowledge of security standards
- Demonstrated experience in continuous monitoring, network security, firewalls, VPNs, IDS/IPS, and endpoint protection.
- Strong analytical skills and a meticulous approach to problem-solving
- Demonstrated capability to deliver results on-time and to a defined schedule.
- Familiarity with cloud security principles
- Experience with security automation and continuous monitoring tools
- Knowledge of scripting languages (Python, PowerShell) to automate security processes
- Relevant certifications (e.g., CISSP, CompTIA Security+, CAP) are strongly preferred
- PKI knowledge a plus
- Experience with government-regulated environments (AWS GovCloud, Azure Government) preferred
Benefits:
- Second Fridays (a company-wide day off on the second Friday of every month minus November and December due to the Holiday schedule). Please note that this benefit is subject to change.
- Comprehensive benefit coverage globally.
- Paid Parental Leave is available to new parents. Structure varies based on regional/government requirements. In regions where government-paid leave doesn’t exist, like in the U.S., the company offers generous paid parental leave, along with comprehensive adoption and fertility support.
- Competitive time off globally.
- Wellbeing resources, wellness allowance, mindfulness app free membership, Wellness Wednesdays.
- Global Volunteer Day, company non-profit matching, and 3 volunteer days off.
- Monthly Talent development and Cross Functional meetings to support professional development.
- Regular All Hands meetings followed by group gatherings.
- Opportunities to grow personally and professionally.
- Entrepreneurial environment balancing autonomy and structure.



















