Information Security Engineer
Core
Mid-level Information Security Engineer protecting SaaS products, hardening cloud/endpoint environments, and maturing the security program.
Role type
mid-level hands-on IC information security engineer
Builds
SaaS products, Microsoft Azure infrastructure, and security compliance posture
Domain
SaaS, Cloud Security, Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
vulnerability management, SOC 2 compliance, Microsoft Azure security, Microsoft Intune, Microsoft Defender, security policy drafting, security questionnaire response, SAST/SCA tooling, identity and access management
Preferred skills
container and Kubernetes security, threat modeling, secure code review, penetration testing
Technologies
Microsoft Azure, Microsoft Intune, Microsoft Defender, Microsoft Purview, Datadog, GitHub Advanced Security, Dependabot, Snyk
Responsibilities
Lead SOC 2 compliance program including readiness, control implementation, evidence collection, and auditor coordination. Manage vulnerability management across SaaS products, cloud infrastructure, containers, and endpoints. Operate and tune SAST, SCA, and dependency-scanning tooling. Monitor runtime and infrastructure telemetry for security signals. Draft and maintain corporate information security policies aligned to frameworks like SOC 2 and NIST CSF. Lead response to customer security questionnaires, RFPs, and due-diligence requests. Partner with Engineering on secure SDLC practices and threat modeling.
Seniority
Mid-level, hands-on IC