Information Security Engineer
The Information Security Engineer manages security compliance programs, audit readiness, client due diligence, and security questionnaires. The role requires 2+ years of experience with SOC 2, ISO 27001, data privacy frameworks, and compliance tooling.
About the job
Responsibilities
- Respond to client security questionnaires and due diligence requests.
- Update security policies and documentation.
- Manage and optimize ISO 27001, SOC 2, and DPIA compliance frameworks.
- Partner with internal audit teams, external certification bodies, and penetration testing providers.
- Translate technical security constraints, data, and compliance requirements into actionable strategies and audit evidence.
- Drive continuous operational excellence and maintain audit readiness.
Requirements
- 2–5 years of professional experience in information security compliance.
- Proven experience navigating multiple audit programs, particularly SOC 2.
- Strong knowledge of ISO 27001, SOC 2, and data privacy frameworks, including GDPR and DPIA.
- 2–5 years of experience managing compliance programs, leading internal audits, and responding to customer security questionnaires.
- Advanced experience with vulnerability management tracking tools, penetration testing remediation systems, and compliance management platforms.
- Exceptional communication skills, including the ability to explain security controls, ROI, and compliance documentation to clients, enterprise stakeholders, and auditors.
Nice to Have
- ISO 27001 Lead Auditor or Lead Implementer certification.
- Experience with automated compliance tools such as Vanta, Drata, or Secureframe.
Skills
Information Security, ISO 27001, SOC 2, GDPR, Dpia, Vulnerability Management, Penetration Testing, Security Compliance, Internal Audits, Vanta, Drata, Secureframe
Similar jobs
Security Engineering jobsBuild production security automation, CI/CD guardrails, and AI-assisted workflows for Starburst’s Application Security program. The role requires a strong information security foundation, software engineering ability, and 2–4 years of relevant experience.
Secures Supabase’s cloud platform, Kubernetes environments, containers, and infrastructure by conducting risk assessments, strengthening controls, and building scalable security guardrails. Requires senior-level platform or cloud security experience with deep AWS, Kubernetes, container, and Linux expertise.
Leads a global Security Operations team, setting detection, response, and security strategy while driving incident response and risk remediation. The role requires strong SaaS and cloud security experience, leadership ability, familiarity with major security standards, and responsible use of AI.
Secures Glean's software supply chain by managing vulnerabilities, hardening images, protecting open-source dependencies, and embedding trusted release controls in CI/CD. Requires 3+ years in application security or vulnerability management, strong cloud-native and container security knowledge, and experience with FedRAMP audits.
Owns frontline security alert triage, incident response, detection coverage, and automation across cloud, SaaS, container, and Web3 environments. Requires at least three years of hands-on security operations experience and proficiency with scripting, SIEM platforms, and threat intelligence tooling.