Security Engineer

Posted 18hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security Engineer operating Firmable’s SOC 2 and ISO 27001 security controls. Managing AWS cloud security, vulnerabilities, access, monitoring, audits and incident response remotely.

Responsibilities:

  • Implement and maintain SOC 2 and ISO 27001 controls across infrastructure, applications and internal systems
  • Close control gaps as they are identified
  • Enforce information security policies across engineering and business teams
  • Manage access control, data classification, incident response, vendor risk and change management practices
  • Perform continuous control monitoring, including recurring access reviews, log reviews, vulnerability scans and patch cadence checks
  • Organize evidence ahead of audits
  • Triage vulnerability scanner findings, coordinate remediation with engineering and verify closure
  • Manage onboarding/offboarding, least-privilege access, MFA enforcement and periodic access recertification
  • Monitor security alerts and logs, triage and escalate incidents according to the incident response plan
  • Maintain the risk register and third-party risk assessments and track remediation to closure
  • Prepare evidence for annual assessments and respond to customer security questionnaires
  • Run employee security training and phishing simulations
  • Partner with engineering on AWS secure cloud configuration, least-privilege IAM, encryption and secrets management
  • Report into the Security & Compliance team
  • Spend approximately 90% of time on hands-on execution and 10% on cross-functional work

Requirements:

  • 2–5 years in security engineering, cloud security or infrastructure security
  • Ideally direct SOC 2 or ISO 27001 exposure
  • Working knowledge of the SOC 2 Trust Services Criteria and mapping technical controls to them
  • Hands-on cloud security fundamentals, preferably AWS
  • Experience with IAM, logging/monitoring and vulnerability scanning
  • Comfortable executing security policy day to day, including access reviews, evidence collection and remediation tracking
  • Clear written communication
  • Comfortable working asynchronously across time zones with a distributed team
  • Familiarity with GRC automation platforms such as Vanta or Drata is highly valued
  • Relevant certification such as Security+, CySA+, ISO 27001 Lead Implementer, or progress toward CISA/CISSP is highly valued

Benefits:

  • Competitive compensation
  • Flexible hours
  • Fully remote work
  • Global, distributed team environment
  • Real ownership over security controls
  • Multi-framework exposure to SOC 2 and ISO 27001 programs
  • Professional exposure to a fast-moving, AI-native product team