Senior Information Security Engineer
Posted 4hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Senior Security Engineer owning KPA’s enterprise security platforms, cloud, identity, and automation. Improving security across workplace-safety software, infrastructure, DevOps, and compliance environments.
Responsibilities:
- Own KPA's enterprise security platforms, including CrowdStrike, Rapid7, Cisco Umbrella, Cisco Duo, KnowBe4, and related technologies
- Lead vulnerability management and remediation, endpoint security, identity security, privileged access, penetration testing, and security hardening initiatives
- Lead security incident response, investigations, containment, remediation, and post-incident reviews
- Own the ongoing operation of SOC 2 controls, security audit requirements, and technical compliance initiatives
- Own Cisco Meraki security, VPN infrastructure, network security controls, and secure cloud connectivity
- Secure Azure, AWS, Microsoft 365, Entra ID, AWS Identity Center, Auth0, and cloud-native workloads
- Administer and improve identity governance across Entra ID, Cisco Duo, AWS Identity Center, Auth0, SSO, SCIM, Conditional Access, PIM, privileged accounts, service accounts, and authentication architecture
- Partner with DevOps to integrate security into CI/CD pipelines, Infrastructure as Code, containers, Kubernetes, and cloud workloads, including SAST, DAST, Snyk, and other application security technologies
- Improve cloud security posture management, workload protection, identity controls, logging, alerting, detection engineering, and remediation processes
- Own email security across Microsoft 365, SendGrid, Amazon SES, SPF, DKIM, DMARC, and phishing protection
- Build security automation using PowerShell, Python, Microsoft Graph, REST APIs, and AI-assisted development
- Lead security assessments for vendors, SaaS platforms, cloud services, and third-party integrations; administer third-party vendor management and support vendor risk management
- Administer and improve security awareness programs, policies, standards, and technical procedures
- Support AI security and governance initiatives, including ChatGPT Enterprise, Claude, MCP, and emerging AI technologies
- Support security architecture reviews for new cloud services, platforms, integrations, and technical initiatives
- Identify security gaps, technical debt, and opportunities to improve KPA's security posture through automation, AI, and modern engineering practices
- Serve as the senior technical counterpart to the Director of Security & Technology and senior escalation point for complex security incidents and technical security issues
- Partner with IT Operations and DevOps to embed security into workflows
Requirements:
- 5+ years of experience in security engineering, cloud security, infrastructure security, or a related senior technical role
- Strong knowledge of identity security, endpoint security, vulnerability management, network security, incident response, and zero trust principles
- Experience securing Azure, AWS, Microsoft 365, Entra ID, Windows, and Linux
- Familiarity with CI/CD pipelines, Kubernetes, container security, application security scanning, and DevSecOps practices
- Scripting and automation experience using PowerShell, Python, REST APIs, or similar technologies
- Experience supporting SOC 2 and NIST CSF or comparable security and compliance frameworks
- Relevant certifications such as CompTIA Security+, CISSP, CCSP, AWS Certified Security, or equivalent certifications are preferred
- Excellent communication, documentation, project leadership, and problem-solving skills
- Bachelor's degree in Computer Science, Information Technology or Cybersecurity or equivalent experience
- Full-time, exempt position
Benefits:
- Bonus potential of 10% annually
- Remote work arrangement
- Travel required seldom
- Reasonable accommodations may be made to enable individuals with disabilities to perform essential functions


















