Skip to content
TwentyTwenty

IT Security Engineer

IT Security Engineer responsible for designing, implementing, and maintaining enterprise security infrastructure including firewalls, SIEM monitoring, vulnerability management, IAM, and compliance. Requires 5+ years IT security experience, strong networking and cloud knowledge.

About the job

Responsibilities

  • Design, implement, and maintain enterprise network security architecture, including firewalls, intrusion detection systems, VPNs, and DMZs.
  • Develop and enforce security policies, standards and procedures across the organization.
  • Conduct security assessments, vulnerability scans and penetration testing to identify and remediate security gaps.
  • Monitor systems and networks 24/7 using security information and event management (SIEM) tools; investigate and respond to security incidents.
  • Manage access controls, identity and access management (IAM), and multi-factor authentication (MFA) solutions.
  • Establish and manage data loss prevention (DLP) and encryption protocols for sensitive data at rest and in transit.
  • Perform security hardening of servers, workstations, and endpoints; manage patch management and system updates.
  • Provide security awareness training and education to employees to foster a security-conscious culture.
  • Conduct root cause analysis on security incidents and prepare incident response reports and recommendations.
  • Ensure compliance with relevant regulations (CMMC, SOC 2, GDPR, PCI-DSS, or industry-specific standards as applicable).

Requirements

  • Bachelor's degree in Computer Science, Information Security, or related field (or equivalent professional experience).
  • 5+ years of professional IT security experience, with demonstrated expertise in at least two of the following domains: network security, systems security, or cybersecurity.
  • Strong knowledge of TCP/IP, DNS, DHCP, and network protocols; experience with firewalls, proxies, and network segmentation.
  • Hands-on experience with security tools such as Splunk, ELK Stack, Snort, Suricata, or similar SIEM and IDS/IPS platforms.
  • Proficiency in systems security, including endpoint protection and vulnerability management.
  • Experience with cloud security (AWS, Azure, or GCP) and containerized environments (Docker, Kubernetes).
  • Understanding of common attack vectors and security frameworks (NIST, CIS Controls, OWASP Top 10).
  • Excellent problem-solving skills with the ability to work independently and as part of a team.
  • Strong communication skills to explain complex security concepts to non-technical stakeholders.

Nice-to-haves

  • Security certifications such as CISSP, CISM, CEH, CCNA Security, Security+, or similar.
  • Experience with security automation and Infrastructure as Code (Terraform, Ansible).
  • Knowledge of application security testing (SAST/DAST) and secure development practices.
  • Experience with incident response and forensics investigations.
  • Familiarity with compliance frameworks and audit processes.

Skills

Network Security, SIEM, Splunk, Ids/Ips, IAM, MFA, Dlp, Cloud Security, AWS, Azure, GCP, Docker, Kubernetes, Terraform, Ansible

Icarus

Icarus

El Segundo, CA

Network Engineer
$115k+/yrOn-site5+ YOESecurity Engineering

Own network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.

Plaid

Plaid

New York, NY
Security Analyst, Third-Party Ecosystem Risk Management
$119k+/yrHybrid4+ YOESecurity Engineering

Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.

DataVisor

DataVisor

Mountain View, CA

Security Engineer
$120k+/yrOn-site5+ YOESecurity Engineering

The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.

GameChanger

GameChanger

United States

Security Engineer, Application Security
$120k+/yrRemote3+ YOESecurity Engineering

The Security Engineer will lead application security across the SDLC, integrating DevSecOps controls, conducting threat modeling and secure code reviews, and managing application vulnerabilities. The role requires 3+ years of application security experience plus hands-on expertise with AWS, Kubernetes, IaC, CI/CD, and mobile or web security.

Pinterest

Pinterest

United States

Security GRC Analyst
$124k+/yrRemote4+ YOESecurity Engineering

The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.