- Company Name
- Ben
- Job Title
- Security Engineer
- Job Description
-
**Job Title:** Security Engineer
**Role Summary:**
Design, deploy, and maintain security controls across infrastructure, product, and compliance domains. Drive secure-by-design practices, automate security tasks, conduct risk assessments, and ensure adherence to industry standards (OWASP Top 10, AWS Well‑Architected, ISO 27001, SOC 2). Own projects end‑to‑end in a fast‑paced, high‑impact environment.
**Expectations:**
- Hands‑on responsibility for security tooling management (EDR, MDM, ZTNA, vulnerability scanners).
- Proactive risk‑mitigation mindset with ownership of outcomes.
- Ability to work across multiple domains (infrastructure, product, compliance) and adapt to ambiguity.
- Comfortable fast‑paced delivery, challenging status quo, and driving self‑direction.
**Key Responsibilities:**
- Deploy, configure, and maintain security solutions (endpoint protection, MDM, identity & access controls).
- Embed secure coding, threat modeling, and design reviews into the development lifecycle.
- Monitor systems for anomalous activity; design detection and prevention mechanisms.
- Align infrastructure and applications with OWASP Top 10, AWS Well‑Architected, and other standards.
- Lead risk assessments, vendor reviews, and internal security evaluations.
- Document, update, and audit security policies, procedures, and controls under ISO 27001‑certified ISMS.
**Required Skills:**
- Experience with Microsoft security ecosystem: Entra ID (Azure AD), Intune, Defender.
- Proficiency in EDR, MDM, ZTNA, vulnerability scanners (Qualys, Rapid7, Tenable, etc.).
- Networking, operating systems, and cloud infra (AWS, Azure) fundamentals.
- Secure SDLC practices: threat modeling, secure code review, CI/CD hardening.
- Familiarity with compliance frameworks (ISO 27001, SOC 2) and policy documentation.
- Scripting/automation: Python, PowerShell, Bash; API integration for tool orchestration.
- Strong analytical, problem‑solving, and communication skills.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Certifications preferred: CISSP, CISM, CEH, or Microsoft Certified: Security, Compliance, and Identity Fundamentals.