openqareer

Is/IT Security Engineer

Economic Impact Catalyst · Удалённо · Remote

# Is/IT Security Engineer **Economic Impact Catalyst** · Remote · `Remote` 🕒 **Статус:** *Опубликовано: сегодня* · *Источник: Get on Board (LATAM)* --- ### About the Role How You Work Skills and certifications matter, but what determines success here is how you approach the work, especially when the path isn't clearly defined. We're looking for someone who: - Investigates without being pointed. You notice gaps and keep digging until you understand a problem, whether or not anyone assigned it. This shows up daily in threat identification, vulnerability review, and incident response. - Builds to last. You fix the immediate issue, then document it, automate what repeats, and hand off work so it runs without you. Runbooks and roadmaps are part of doing the job well, not overhead. - Moves without waiting. In a remote team, you set your own priorities and make progress without constant direction. In your first 90 days, you'll orient yourself, ask good questions, and get to work. - Translates risk for the room. You explain risk clearly to engineers, business owners, and leadership, adjusting to your audience without creating unnecessary alarm. - Shares what you know. You cross-train teammates, write documentation others can use, and treat security as a shared responsibility, not a gate you control. Experience and Technical Skills - 3+ years of mid-level cybersecurity experience as a security analyst, security engineer, systems engineer, or similar technical security role. - Bachelor's degree or equivalent experience in Cybersecurity, Computer Science, IT, or a related field. - An advanced, professional, or expert-level security certification is preferred. - Hands-on experience administering or managing at least one enterprise security application or platform. - Experience leading security projects from planning through implementation, handoff, and continuous improvement. - Strong grasp of information security principles and incident investigation techniques, with a practical understanding of threats and risk. - Working knowledge of network, application, endpoint, cloud, identity, and systems security architecture. - Experience designing and implementing security controls across servers, networks, databases, cloud, and applications. - Strong troubleshooting, automation, project management, and written communication skills. Security Platforms and Domain Knowledge - Experience securing multi-tenant SaaS platforms: tenant isolation, role-based access control, secure configuration, data protection, threat detection, vulnerability remediation, and incident response. - Hands-on experience with tools such as SIEM, EDR/XDR, DLP, IDS/IPS, email security, identity security, and vulnerability management platforms. - Experience with SOAR, CSPM, and CNAPP, ideally in an AWS-based multi-tenant SaaS environment. - Working knowledge of NIST and SOC 2, including supporting audits, evidence collection, and remediation. Our Values in Action Our values describe how the work actually gets done here. - Curiosity: You follow security developments because the space interests you. When you meet an unfamiliar threat or system, you investigate before you conclude, and you share what you learn. - Ownership: You see security controls through from design to ongoing monitoring, including the documentation and handoff that make your work last. When an incident happens, you stay calm, drive toward resolution, and make sure the root cause is fixed, not just contained. - Empathy: You build security processes people will actually follow, and you explain risk in terms that help others make better decisions. You mentor teammates in a way that builds capability, not dependence. - Identify threats and vulnerabilities, conduct complex security investigations, and lead incident response, containment, recovery, and follow-up activities. - Architect, design, and implement security technologies and processes in partnership with engineering, infrastructure, application, and business owners. - Manage, administer, monitor, and support multiple security applications; troubleshoot issues and automate operational workflows to reduce risk and improve response time. - Measure and report on enterprise security capabilities using automated and manual tools, with clear metrics for risk, coverage, and remediation progress. - Develop and maintain security policies, standards, procedures, runbooks, roadmaps, and business cases, and communicate them clearly to technical and business partners. - Review new and existing systems before and after implementation to confirm security requirements and complete risk, architecture, and impact assessments. - Develop, maintain, audit, and enhance security controls across endpoints, servers, networks, databases, cloud services, applications, identities, and data. - Support security awareness, audits, assessments, compliance requests, and remediation activities aligned with EIC's security and governance requirements. - Deliver security projects, mentor and cross-train team members, maintain technical documentation, and strengthen tenant isolation and secure-by-default controls across the multi-tenant SaaS platform. Skills that will make your application stand out: While we value how you approach the work as much as what you already know, candidates with hands-on experience in AWS Security, Incident Response, Vulnerability Management, SIEM, and SOC 2 will be especially well positioned for this role. These skills map directly to what you'll be doing from day one: securing our AWS-based multi-tenant platform, leading investigations when something goes wrong, finding and fixing risk before it becomes a problem, monitoring for threats, and supporting our SOC 2 compliance efforts. If you've worked in any of these areas, tell us about it in your application — specific examples of projects, tools, or incidents you've handled will help us understand your experience.

Наблюдалась 2026-09-29, впервые 2026-09-29, источник — Get on Board (LATAM).

Открыть у работодателя