IT Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The Senior IT Security Engineer is a senior individual contributor role responsible for owning and advancing the security, risk management, and compliance posture across internal systems and operational environments. This position defines security governance frameworks, oversees certification maintenance, and manages technical risk remediation across enterprise infrastructure. Operating with significant autonomy, the incumbent serves as an authoritative advisor on identity management, access controls, vulnerability governance, and vendor risk. Through technical authority and cross-functional influence, this role ensures internal operations maintain continuous alignment with industry security standards and organizational resilience objectives.
What You’ll Do
Owns the enterprise security and compliance program, driving continuous alignment with industry-standard security frameworks, certifications, and audit disciplines.
Establishes and maintains the organizational risk register across physical, logical, and systems infrastructure to prioritize risk mitigation and remediation strategies.
Defines and enforces identity architecture standards, access management controls, and credentials governance to minimize operational exposure.
Drives vulnerability management governance across technical environments by establishing severity SLAs, standardizing inspection metrics, and overseeing remediation adherence.
Leads third-party risk management initiatives by conducting security assessments of software vendors, integrations, and external technologies prior to onboarding.
Oversees security questionnaire workflows and compliance reporting to deliver streamlined assurance for external stakeholders.
Shapes incident response playbooks, conducts regular tabletop simulations, and acts as a primary technical advisor during security events and resilience reviews.
Advises technical and operational teams on secure configuration, access modeling, secrets management, and policy execution.
Evaluates emerging security platforms, governance technologies, and operational controls to continuously elevate enterprise resilience and audit readiness.
Balances security risk considerations against business velocity to recommend practical controls and defensible risk-acceptance thresholds.
Requirements
- Demonstrated experience designing, implementing, and managing enterprise security programs, risk registers, and compliance audit lifecycles.
- Technical expertise in identity and access management (IAM), network security controls, cloud infrastructure security, and vulnerability management governance.
- Proven ability to evaluate third-party vendor risk and govern data access security across complex software environments.
- Practical experience in incident response coordination, playbook development, and conducting technical tabletop exercises.
- Exceptional communication and stakeholder management skills, with the ability to articulate technical risk and security trade-offs to non-technical partners.
- Demonstrated track record of setting technical direction, establishing standards, and influencing cross-functional technical teams without direct formal authority.
- Strong analytical, problem-solving, and decision-making capabilities focused on practical risk reduction and operational enablement.
- Relevant degree in Computer Science, Information Technology, Cybersecurity, or an equivalent combination of senior professional experience and industry certifications.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Walking Into The Era of Supply Chain Risks
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again