Information Security Engineer

Red Ventures
Charlotte, NC, United States
11 days ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$100,000.0 - $150,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Artificial Intelligence Amazon Web Services Software as a Service Cloud Computing Cloud Computing Security Cyber Security Continuous Integration Identity and Access Management OAuth PCI Data Security Standards Security Information and Event Management
+5 more
Software Vulnerability Management Delivery Pipeline Mitre Att&ck Cyber Threat Analysis Vulnerability Analysis

Job description

As a Information Security Engineer, you will identify and reduce risk across our cloud and SaaS environments by surfacing vulnerabilities, tuning detections, and driving remediation with the engineering teams who own the systems. You will own the full incident response lifecycle from alert triage through containment, eradication, and post-incident review. You will hunt for threats before they surface in alerts and partner directly with Infrastructure and Engineering teams across our business units. This is a hands-on, high-ownership role for someone who is energized by complex cloud environments, moves fast under pressure, and takes pride in building repeatable, scalable security operations.

If you are a sharp, curious security practitioner who wants real ownership and the chance to shape how security works across a large multi-brand organization, this is that role.

What You’ll Do:

  • Identify, assess, and drive reduction of security risk across cloud, SaaS, and enterprise environments
  • Partner with engineering and development teams to remediate vulnerabilities across code, cloud, and endpoint environments
  • Lead end-to-end incident response across cloud and SaaS environments
  • Own proactive threat hunting on a defined cadence
  • Maintain and tune detection rules in the SIEM
  • Contribute to security tooling evaluation and roadmap
  • Produce post-incident reports and present findings to stakeholders
  • Participate in an on-call rotation shared across the team on a rotating basis

Requirements

This role requires a hybrid schedule and will be based in our South Charlotte, NC Headquarters (Tuesday through Thursday) and work fully remotely on Mondays and Fridays each week. Willing to consider candidates located outside of Charlotte, NC with the ability to relocate to the area., * 4+ years of hands-on experience in one or more of: security monitoring, incident response, vulnerability management, or cloud security

  • Experience in Incident response: end-to-end ownership from triage through containment, eradication, and post-incident review
  • Experience with Cloud security in AWS: applying security controls, monitoring, and response techniques across AWS environments at scale
  • Experience with Security tooling: hands-on experience with SIEM, endpoint protection, and vulnerability scanning platforms in a cloud environment
  • Communication: strong written and verbal skills with the ability to translate technical findings for non-technical stakeholders

Nice to Have:

  • Threat intelligence and hunting: disciplined habit of staying current on attacker TTPs and applying that knowledge through structured, hypothesis-driven hunts across cloud, SaaS, and enterprise environments
  • Identity and access management: policy review, least-privilege enforcement, and anomalous access detection
  • SaaS security posture management: monitoring and tuning SaaS application security controls including impossible travel, OAuth abuse, and integration risks
  • Container and CI/CD pipeline security: understanding of Kubernetes security, image scanning, and securing software delivery pipelines
  • Compliance frameworks: working knowledge of PCI DSS, SOC 2, and ISO 27001 and how they map to technical security controls
  • Familiarity with security frameworks (NIST CSF, MITRE ATT&CK, CIS 18)
  • Experience scripting or automating security workflows, including comfort leveraging AI tools to accelerate detection and response
  • Relevant certifications such as AWS Security Specialty or GIAC equivalents

Benefits & conditions

Total Cash Compensation Range: $100,000 - $150,000 per year, Additionally, the following benefits are provided by Red Ventures, subject to eligibility requirements.

  • Health Insurance Coverage (medical, dental, and vision)
  • Life Insurance
  • Short and Long-Term Disability Insurance
  • Flexible Spending Accounts
  • Holiday Pay
  • 401(k) with match
  • Employee Assistance Program
  • Paid Parental Bonding Benefit Program
  • Flexible Paid Time Off (PTO): We believe time to rest and recharge is essential. That’s why we offer a generous and flexible PTO policy. Full-time employees accrue 20 days of PTO for a full calendar year annually, with an increase to 25 days after five years of service.

About the company

Red Ventures is a global portfolio of high-growth companies - spanning several U.S. businesses, a joint venture in the health services industry, and strategic investments in Europe. Their businesses include The Points Guy, Lonely Planet, Bankrate, the Allconnect Platform, RV Home Client Growth, RV Growth & Transformation, Sage Home Loans Corporation, and more. Across the portfolio, Red Ventures businesses deliver seamless digital experiences for consumers, help Fortune 100 clients solve large-scale digital growth challenges, and create world-class experiences and opportunities for employees. Learn more at redventures.com and follow @RedVentures on LinkedIn and Instagram.

At Red Ventures, we believe diverse, inclusive teams are better. To help you better understand our core values and beliefs, we encourage you to watch this brief YouTube video: Our Belief Statements. This will give you insight into the principles that guide our work and our commitment to fostering an inclusive environment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

5:25 min

Shifting left and creating internal security champion programs

Vandana Verma Sehgal · LIVE

Videos

See all

Related articles

See all