Security Engineer
Posted 18hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Security Engineer operating Firmable’s SOC 2 and ISO 27001 security controls. Managing AWS cloud security, vulnerabilities, access, monitoring, audits and incident response remotely.
Responsibilities:
- Implement and maintain SOC 2 and ISO 27001 controls across infrastructure, applications and internal systems
- Close control gaps as they are identified
- Enforce information security policies across engineering and business teams
- Manage access control, data classification, incident response, vendor risk and change management practices
- Perform continuous control monitoring, including recurring access reviews, log reviews, vulnerability scans and patch cadence checks
- Organize evidence ahead of audits
- Triage vulnerability scanner findings, coordinate remediation with engineering and verify closure
- Manage onboarding/offboarding, least-privilege access, MFA enforcement and periodic access recertification
- Monitor security alerts and logs, triage and escalate incidents according to the incident response plan
- Maintain the risk register and third-party risk assessments and track remediation to closure
- Prepare evidence for annual assessments and respond to customer security questionnaires
- Run employee security training and phishing simulations
- Partner with engineering on AWS secure cloud configuration, least-privilege IAM, encryption and secrets management
- Report into the Security & Compliance team
- Spend approximately 90% of time on hands-on execution and 10% on cross-functional work
Requirements:
- 2–5 years in security engineering, cloud security or infrastructure security
- Ideally direct SOC 2 or ISO 27001 exposure
- Working knowledge of the SOC 2 Trust Services Criteria and mapping technical controls to them
- Hands-on cloud security fundamentals, preferably AWS
- Experience with IAM, logging/monitoring and vulnerability scanning
- Comfortable executing security policy day to day, including access reviews, evidence collection and remediation tracking
- Clear written communication
- Comfortable working asynchronously across time zones with a distributed team
- Familiarity with GRC automation platforms such as Vanta or Drata is highly valued
- Relevant certification such as Security+, CySA+, ISO 27001 Lead Implementer, or progress toward CISA/CISSP is highly valued
Benefits:
- Competitive compensation
- Flexible hours
- Fully remote work
- Global, distributed team environment
- Real ownership over security controls
- Multi-framework exposure to SOC 2 and ISO 27001 programs
- Professional exposure to a fast-moving, AI-native product team

















