openqareer

Security Engineer

MXS Solutions · Удалённо · Remote

# Security Engineer **MXS Solutions** · Remote · `Remote` 🕒 **Статус:** *Опубликовано: вчера* · *Источник: Indeed* --- ### About the Role About the Role We're looking for a detail-oriented Security Engineer to own the day-to-day work of keeping our infrastructure and codebase patched, secure, and compliant. This role is central to our security posture: you'll be responsible for identifying vulnerabilities, applying patches across servers and source code repositories, and ensuring our compliance automation platform (Vanta) accurately reflects the current state of our environment at all times. This is a hands-on, execution-focused role suited for someone who takes ownership of recurring security hygiene tasks and treats compliance tooling as a living system rather than a one-time checkbox. What You'll Do Server Patching: Regularly assess, schedule, and apply OS-level and application-level patches across production, staging, and development servers (Linux/Windows), minimizing downtime and following change-management procedures. Source Code Remediation: Monitor dependency and vulnerability scanning tools (e.g., Dependabot, AWS Inspector, npm audit, pip-audit) and apply patches or version bumps to remediate known CVEs in application code and third-party libraries. Vanta Compliance Maintenance: Serve as the primary owner of our Vanta instance — resolving failing checks, connecting/maintaining integrations, uploading required evidence, and ensuring monitored controls stay in a passing state ahead of audits (SOC 2). Vulnerability Management: Triage vulnerability scan results, prioritize based on severity and exploitability, and track remediation through to closure. Patch Cadence & Documentation: Establish and maintain a routine patching schedule, and document patch history, exceptions, and risk acceptances for audit purposes. Cross-Team Coordination: Work with engineering and IT teams to schedule patch windows, test changes in non-production environments, and roll out fixes with minimal disruption. Alerting & Monitoring: Configure and respond to alerts related to outdated packages, expiring certificates, misconfigurations, and other Vanta-flagged issues. Reporting: Provide regular status updates to leadership on patch compliance rates, open vulnerabilities, and audit readiness. What We're Looking For 2+ years of experience in a security engineering, systems administration, or DevOps role with a security focus. Hands-on experience patching and maintaining Linux servers in a production environment. Familiarity with dependency/vulnerability scanning tools and patching source code dependencies (npm, pip, apt, yum, etc.). Direct experience with Vanta or a similar compliance automation platform (Drata, Secureframe, Tugboat Logic) strongly preferred. Working knowledge of common compliance frameworks (SOC 2, ISO 27001, HIPAA, or similar). Scripting ability (Bash, Python, or similar) to automate patch checks and reporting. Experience with cloud infrastructure (AWS) and infrastructure-as-code concepts. Strong organizational skills — this role requires consistent follow-through on recurring tasks, not just one-off fixes. Clear written communication for documenting remediation steps and audit evidence. Nice to Have Experience with CI/CD pipelines and integrating security checks into build processes. Prior experience preparing for or supporting a SOC 2 audit. Relevant certifications (Security+, GCIH, AWS Security Specialty, etc.). Why Join Us Direct, visible impact on the company's security and audit readiness. Ownership of a critical, high-trust function rather than a narrow ticket queue. Collaborative environment working closely with engineering and leadership. Pay: $90,000.00 - $120,000.00 per year Benefits: 401(k) Dental insurance Health insurance Paid time off Vision insurance Work Location: Remote

Наблюдалась 2026-09-16, впервые 2026-09-14, источник — Indeed.

Открыть у работодателя