- Company Name
- Tails.com | B Corp
- Job Title
- Security Engineer
- Job Description
-
**Job Title**
Security Engineer
**Role Summary**
The Security Engineer strengthens the organization’s cyber security posture by defining, embedding, and assuring security standards, guardrails, and governance across engineering, infrastructure, data, and business teams. The role balances operational pragmatism with strong governance, leveraging the partner Nestlé Cyber team’s resources for SOC intelligence, tooling, and incident response support.
**Expectations**
- Develop and maintain clear, pragmatic security standards aligned with ISO 27001, NIST CSF, CIS, PCI‑DSS, and GDPR frameworks.
- Ensure consistent application of controls, promote secure‑by‑design throughout delivery lifecycles, and oversee effectiveness of governance processes.
- Lead risk assessment, issue remediation tracking, and audit evidence collection.
- Deliver targeted communication and training to improve security awareness.
- Continuously evolve standards and best practices, automate governance activities, and monitor emerging threats and technologies.
**Key Responsibilities**
- Define, document, and enforce security standards, guardrails, and controls across the organization.
- Embed security requirements into engineering, infrastructure, and data projects through guidance and enablement.
- Collaborate with Nestlé Cyber on SOC intelligence, tooling, and incident response, while providing hands‑on validation when required.
- Conduct risk assessments, identify gaps, and manage remediation to closure.
- Lead assurance activities, support audits, and provide clear, accurate evidence of control effectiveness.
- Translate central cyber insights into actionable local actions with accountable ownership.
- Support incident response with structured analysis and technical validation.
- Deliver communications and training to elevate security awareness.
- Monitor and improve security maturity, automating governance, and ensuring practices remain business‑aligned.
**Required Skills**
- Experience in security engineering, governance, or related cyber security roles.
- Strong knowledge of ISO 27001, NIST CSF, CIS, PCI‑DSS, GDPR, and secure design principles.
- Understanding of cloud and infrastructure security patterns.
- Ability to define, assess, and assure security controls and standards.
- Familiarity with SOC operations, threat intelligence, and incident response.
- Ability to translate technical risk into actionable requirements.
- Basic scripting/automation skills (Python, Bash, PowerShell).
- Excellent written and verbal communication across technical and non‑technical audiences.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field preferred.
- Relevant certifications (ISO 27001 Lead Implementer/Assessor, CISSP, CISM, GRC, or equivalent) are beneficial but not mandatory.