Cybersecurity Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
We are seeking a Cybersecurity & Compliance Specialist to strengthen our security posture across internal systems and customer environments while overseeing compliance efforts for both Vector Choice and our clients. This role is responsible for monitoring security threats, reviewing penetration testing results, maintaining compliance with security best practices and regulatory frameworks, supporting CyberGuard compliance initiatives, developing and maintaining Written Information Security Programs (WISPs), and ensuring clients meet requirements such as FTC Safeguards, CMMC, and other applicable standards.The ideal candidate has hands-on security experience, strong compliance knowledge, excellent communication skills, and holds at minimum a CompTIA Security+ certification.Key ResponsibilitiesSecurity Operations & Monitoring
- Monitor security alerts, logs, and reports across customer and internal environments
- Identify, analyze, and respond to security threats and vulnerabilities
- Assist with incident response, investigation, and remediation efforts
- Ensure security tools (EDR, MDR, SIEM, email security, firewall, etc.) are properly configured and functioning
Penetration Testing & Risk Management
- Review penetration testing and vulnerability scan reports from third-party vendors
- Translate technical findings into clear, customer-friendly explanations
- Conduct post-pen-test review meetings with customers to explain risks, impact, and remediation steps
- Track remediation progress and validate corrective actions
Compliance Program Management (Internal & Client)
- Oversee and coordinate compliance efforts within Vector Choice and for external clients to ensure operational procedures and business processes comply with applicable laws, regulations, and contractual agreements
- Develop, improve, and maintain company policies, standards, and procedures that outline ethical, safe, and efficient operations
- Create, update, and execute the Compliance and Ethics Program Plan
- Establish and reinforce a culture of compliance throughout the organization
- Monitor and test policies and procedures to ensure they result in effective compliance
- Perform risk assessments and compliance reviews to verify adherence
- Recommend investigative procedures in response to alleged violations of rules, regulations, policies, procedures, or the Code of Conduct
- Provide guidance on effective responses to detected problems and recommend corrective actions
- Preside over and direct the work of the Compliance Committee (as applicable)
- Govern reporting of misconduct/noncompliance, reporting pathways, and protection from retaliation
- Stay current with changes in federal, state, and industry regulations and ensure the organization and clients remain informed and compliant
FTC Safeguards Rule Compliance
- Ensure clients meet FTC requirements for protecting consumer data, including the development, implementation, and maintenance of appropriate safeguards
- Perform regular audits and assessments to verify compliance with FTC regulations
- Provide recommendations to enhance data protection and safeguard measures
CMMC Compliance
- Guide clients through the CMMC certification process, ensuring they meet all required cybersecurity practices
- Conduct gap analyses and readiness assessments to identify areas of non-compliance
- Develop remediation plans and provide ongoing support to achieve and maintain CMMC certification
CyberGuard Compliance & WISP Development
- Support CyberGuard compliance efforts, including related assessments, documentation, and ongoing compliance maintenance
- Develop, write, update, and maintain Written Information Security Programs (WISPs) for internal use and customer environments
Compliance Audits, Assessments & Documentation
- Perform routine compliance audits for clients to identify and address potential risks
- Prepare comprehensive audit reports and present findings to clients with actionable recommendations
- Maintain detailed records of compliance activities, assessments, and client communications
- Develop and update compliance-related documentation, including policies, procedures, and training materials
- Provide regular reports to management on compliance status, issues, and resolutions
Customer-Facing Engagement & Training
- Act as a security and compliance subject-matter expert during customer meetings and reviews
- Provide security and compliance recommendations aligned with industry best practices and frameworks (CIS Controls, NIST, HIPAA, PCI, FTC Safeguards, CMMC, etc.)
- Assist account managers and engineers with security assessments, compliance proposals, and risk prioritization discussions
- Provide clients with ongoing support in implementing and maintaining compliance measures
- Develop and deliver training sessions for client teams on compliance best practices and regulatory changes
- Serve as a primary point of contact for client inquiries regarding security and compliance issues
Security Governance & Continuous Improvement
- Maintain and improve security standards, policies, and procedures
- Recommend improvements to tools, processes, and security controls
- Support audits, compliance initiatives, and security documentation when required
- Stay current with emerging threats, vulnerabilities, and security trends
Requirements
- CompTIA Security+ certification (required)
- Bachelor’s Degree in Law, Finance, Business Administration, Information Security, or a related field
- 2+ years of experience in cybersecurity, IT security, compliance, or related roles
- Working knowledge of network and endpoint security, firewalls, MFA, EDR/MDR, email security, vulnerability management, and risk assessment
- Experience with or strong understanding of FTC Safeguards Rule and CMMC requirements
- Ability to clearly explain technical security and compliance concepts to non-technical users
- Strong documentation, policy-writing, and communication skills (including WISP development)
- Proficiency with Microsoft Office (Word, Excel, Email, Scheduling)
- Ability to type at least 40 words per minute, * Additional certifications: CySA+, CEH, SSCP, CMMC-related credentials, or similar
- Experience in an MSP or multi-tenant environment
- Familiarity with compliance frameworks such as CIS Controls, NIST, HIPAA, PCI, SOC 2, and CyberGuard compliance processes
- Hands-on experience developing or maintaining Written Information Security Programs (WISPs)
- Experience reviewing third-party security assessments or penetration tests
- Prior experience leading or supporting a Compliance Committee or ethics program
Soft Skills & Competencies
- Strong analytical, problem-solving, and judgment skills
- Excellent customer service and interpersonal skills; manages difficult situations professionally
- Clear oral and written communication; speaks persuasively and writes informatively
- Leadership presence with the ability to influence and motivate others
- Detail-oriented with strong follow-through and organizational skills
- Ability to balance multiple clients and priorities
- Proactive, continuously learning mindset with a commitment to quality and ethics
- Maintains confidentiality and works with integrity
Work Environment & Physical Demands
- Remote in USA (or as determined by the organization)
- Occasional after-hours work may be required for security incidents
- Client-facing role requiring professionalism and clear communication
- Must occasionally lift and/or move up to 10 pounds
- Valid driver’s license with reliable transportation required
- Noise level in the work environment is usually moderate
Benefits & conditions
$75,000 - $100,000 a year - Full-time, Pulled from the full job description
- 401(k)
- Health insurance
- Paid time off
- Vision insurance
- Dental insurance, * Competitive salary: $75,000 - $100,000 based on experience and certifications
- Training and certification reimbursement
- Growth path into Senior Security Analyst, Security Engineer, or Compliance leadership roles
- 401(k)
- Dental, Health, and Vision insurance
- Paid time off, * 401(k)
- Dental insurance
- Health insurance
- Paid time off
- Vision insurance
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
Best Paying Jobs in Technology
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Is Software Engineering Over-Saturated?