> Markdown version of [/jobs/ext/1449718-information-security-specialist](https://www.wearedevelopers.com/jobs/ext/1449718-information-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Specialist - **Company:** Marmon Foodservice Technologies, Inc. - **Location:** Carol Stream, IL, United States - **Experience:** Experienced - **Salary:** $80,000.0 - $120,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cyber Security, Identity and Access Management, Information Technology Operations, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Workflow Management Systems, Data Logging, Scripting, Delivery Pipeline, Large Language Models, Software Security, Network Server, Security Orchestration, Automation & Response - **Published:** July 26, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e27568a56e72f7b3 ## About the Role * 3-6 years of experience in information security, IT operations, or risk-related roles * Exposure across multiple security areas (security operations, access management, governance, or risk) * Basic understanding of application security concepts and how software is built and deployed * Strong organizational, documentation, and follow-up skills * Ability to work effectively with distributed teams across regions, * Experience with endpoint security, vulnerability management, or SIEM tooling * Familiarity with security frameworks or control-based programs (SOC 2, ISO, NIST, CIS) * Experience working alongside software engineers or platform teams * Exposure to security automation, scripting, or workflow tools * Exposure and understanding of AI and LLM * Curiosity and initiative to identify improvements beyond assigned tasks Core Competencies * Operational Excellence: Executes security tasks consistently and accurately * Collaboration: Works effectively with IT, engineering, and security stakeholders * Risk Awareness: Understands tradeoffs and supports risk-based decisions * Problem Solving: Identifies gaps and contributes to practical solutions * Continuous Improvement: Seeks ways to improve processes, tooling, and coverage ## Description The Information Security Specialist supports the organization's security program by helping operate, maintain, and mature security controls across infrastructure, cloud environments, identities, applications, and governance processes. This role works closely with global IT, security, and software engineering teams to ensure security requirements are consistently implemented, monitored, and improved. The ideal candidate has broad security exposure, strong operational discipline, and an interest in improving how security is embedded into day-to-day technology operations and new product development., Security Operations & Control Execution * Support day-to-day execution of security controls across endpoints, servers, identities, applications, and cloud platforms * Track adherence to security requirements and follow up on gaps with regional teams * Maintain accurate records, evidence, and reporting related to security control coverage * Ensure security tasks and remediation actions are progressing and documented Cloud & Infrastructure Security * Support security operations within Azure and AWS environments, including visibility into workloads and configurations * Assist with monitoring security tooling and baseline controls for cloud-hosted systems * Help validate security requirements for new cloud resources and services * Identify configuration or control gaps and escalate or coordinate remediation Vulnerability Management & Risk Handling * Assist with vulnerability tracking, triage, and remediation coordination * Help ensure systems that cannot meet security standards have documented and approved risk exceptions * Maintain inventories of vulnerabilities, exceptions, and associated remediation or compensating controls * Support periodic reviews to ensure risk records remain accurate and current Identity & Access Support * Participate in access reviews, entitlement validations, and privilege attestations * Track review outcomes and remediation activities * Support documentation and evidence related to access management controls * Promote least-privilege and appropriate access practices through consistent execution Application & Product Security Collaboration * Work with software engineers and product teams during design and implementation of new systems * Assist with security reviews for applications, SaaS tools, and internal services * Help validate security considerations such as authentication, authorization, data protection, and logging * Support integration of security requirements into development and deployment workflows Security Tools, Automation & Process Improvement * Assist in operationalizing security tools that are newly implemented or not yet fully adopted * Help define and document workflows, procedures, and ownership for security technologies * Identify opportunities to improve existing automations or reduce manual effort * Contribute ideas and support efforts to modernize and scale security operations Security Program & Gap Identification * Identify gaps, inefficiencies, or inconsistencies across security processes and controls * Assist with developing practical, risk-based plans to address identified gaps * Track progress and support implementation of improvement initiatives * Help establish metrics and reporting to measure control effectiveness, * Security requirements are consistently tracked and followed up across environments * Cloud and application security needs are addressed early and clearly * Vulnerabilities and exceptions are well-maintained and audit-ready * Access reviews and security attestations are completed on time * Security tools and processes continue to mature and scale ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Kubernetes Security - Challenge and Opportunity](https://www.wearedevelopers.com/videos/412-kubernetes-security-challenge-and-opportunity) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Stephan Gillich - Bringing AI Everywhere](https://www.wearedevelopers.com/magazine/489-stephan-gillich-bringing-ai-everywhere)