IT Security Engineer

Simpro Group
United States
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Security Cyber Security Data Security Identity and Access Management Key Management Network Security Software Vulnerability Management Information Technology

Job description

The Senior IT Security Engineer is a senior individual contributor role responsible for owning and advancing the security, risk management, and compliance posture across internal systems and operational environments. This position defines security governance frameworks, oversees certification maintenance, and manages technical risk remediation across enterprise infrastructure. Operating with significant autonomy, the incumbent serves as an authoritative advisor on identity management, access controls, vulnerability governance, and vendor risk. Through technical authority and cross-functional influence, this role ensures internal operations maintain continuous alignment with industry security standards and organizational resilience objectives.

What You’ll Do

Owns the enterprise security and compliance program, driving continuous alignment with industry-standard security frameworks, certifications, and audit disciplines.

Establishes and maintains the organizational risk register across physical, logical, and systems infrastructure to prioritize risk mitigation and remediation strategies.

Defines and enforces identity architecture standards, access management controls, and credentials governance to minimize operational exposure.

Drives vulnerability management governance across technical environments by establishing severity SLAs, standardizing inspection metrics, and overseeing remediation adherence.

Leads third-party risk management initiatives by conducting security assessments of software vendors, integrations, and external technologies prior to onboarding.

Oversees security questionnaire workflows and compliance reporting to deliver streamlined assurance for external stakeholders.

Shapes incident response playbooks, conducts regular tabletop simulations, and acts as a primary technical advisor during security events and resilience reviews.

Advises technical and operational teams on secure configuration, access modeling, secrets management, and policy execution.

Evaluates emerging security platforms, governance technologies, and operational controls to continuously elevate enterprise resilience and audit readiness.

Balances security risk considerations against business velocity to recommend practical controls and defensible risk-acceptance thresholds.

Requirements

  • Demonstrated experience designing, implementing, and managing enterprise security programs, risk registers, and compliance audit lifecycles.
  • Technical expertise in identity and access management (IAM), network security controls, cloud infrastructure security, and vulnerability management governance.
  • Proven ability to evaluate third-party vendor risk and govern data access security across complex software environments.
  • Practical experience in incident response coordination, playbook development, and conducting technical tabletop exercises.
  • Exceptional communication and stakeholder management skills, with the ability to articulate technical risk and security trade-offs to non-technical partners.
  • Demonstrated track record of setting technical direction, establishing standards, and influencing cross-functional technical teams without direct formal authority.
  • Strong analytical, problem-solving, and decision-making capabilities focused on practical risk reduction and operational enablement.
  • Relevant degree in Computer Science, Information Technology, Cybersecurity, or an equivalent combination of senior professional experience and industry certifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:41 min

Protecting etcd databases using Key Management System plugins

Alex Soto Alex Soto · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

Videos

See all

Related articles

See all