- Company Name
- GlobalSource IT
- Job Title
- Remote Security Engineer
- Job Description
-
**Job Title:** Remote Security Engineer
**Role Summary:**
A high‑growth technology company seeks its first dedicated Security Engineer to own and advance application, cloud, and compliance security. The role is hands‑on, embedding security throughout the software development lifecycle, automating controls with modern tooling (including AI‑assisted solutions), and maintaining a secure AWS environment while supporting SOC 2 operations.
**Expectations:**
- Minimum 5 years of experience in security engineering, application security, or cloud security.
- Proven ability to work closely with engineering teams and communicate security concepts clearly.
- Strong problem‑solving mindset with a focus on automation and continuous improvement.
**Key Responsibilities:**
- Partner with engineering to integrate security into the SDLC and CI/CD pipelines.
- Design, implement, and tune automated security gates (SAST, SCA, custom checks).
- Conduct secure code reviews and guide developers on remediation.
- Strengthen API security and detect logic‑based vulnerabilities.
- Own AWS security posture: configure WAF, GuardDuty, Shield, KMS, CloudTrail, IAM, and enforce guardrails.
- Deploy and manage CSPM tools (e.g., Wiz) to monitor cloud compliance.
- Build automation to reduce alert fatigue and explore AI‑driven log analysis and threat detection.
- Support incident response and coordinate with third‑party monitoring services.
- Secure employee identities and SaaS access using Microsoft Entra ID, Auth0, or similar IAM solutions.
- Manage day‑to‑day SOC 2 compliance, maintain evidence in Drata, and assist auditors.
- Perform vendor security assessments and maintain security policies and documentation.
**Required Skills:**
- Hands‑on AWS security (services, IAM, encryption, monitoring).
- Experience integrating security controls into CI/CD pipelines.
- Application security expertise: secure coding, OWASP Top 10, SAST, SCA.
- Proficiency with CSPM tools (Wiz, Prisma Cloud, Orca, Lacework, etc.).
- IAM platforms experience (Auth0, Microsoft Entra ID, Okta).
- Familiarity with SOC 2 compliance processes and evidence management.
- Ability to read and analyze code for vulnerabilities.
- Strong verbal and written communication; collaborative team player.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent practical experience).
- Preferred: AWS Security or AWS Solutions Architect certification.
- Preferred: Certifications in DevSecOps, container security, or related specialties.