> Markdown version of [/jobs/ext/2734312-it-security-engineer](https://www.wearedevelopers.com/jobs/ext/2734312-it-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Engineer - **Company:** Simpro Group - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cloud Computing Security, Cyber Security, Data Security, Identity and Access Management, Key Management, Network Security, Software Vulnerability Management, Information Technology - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/senior-it-security-engineer-bigchange-limited-9931288 ## About the Role * Demonstrated experience designing, implementing, and managing enterprise security programs, risk registers, and compliance audit lifecycles. * Technical expertise in identity and access management (IAM), network security controls, cloud infrastructure security, and vulnerability management governance. * Proven ability to evaluate third-party vendor risk and govern data access security across complex software environments. * Practical experience in incident response coordination, playbook development, and conducting technical tabletop exercises. * Exceptional communication and stakeholder management skills, with the ability to articulate technical risk and security trade-offs to non-technical partners. * Demonstrated track record of setting technical direction, establishing standards, and influencing cross-functional technical teams without direct formal authority. * Strong analytical, problem-solving, and decision-making capabilities focused on practical risk reduction and operational enablement. * Relevant degree in Computer Science, Information Technology, Cybersecurity, or an equivalent combination of senior professional experience and industry certifications. ## Description The Senior IT Security Engineer is a senior individual contributor role responsible for owning and advancing the security, risk management, and compliance posture across internal systems and operational environments. This position defines security governance frameworks, oversees certification maintenance, and manages technical risk remediation across enterprise infrastructure. Operating with significant autonomy, the incumbent serves as an authoritative advisor on identity management, access controls, vulnerability governance, and vendor risk. Through technical authority and cross-functional influence, this role ensures internal operations maintain continuous alignment with industry security standards and organizational resilience objectives. What You'll Do Owns the enterprise security and compliance program, driving continuous alignment with industry-standard security frameworks, certifications, and audit disciplines. Establishes and maintains the organizational risk register across physical, logical, and systems infrastructure to prioritize risk mitigation and remediation strategies. Defines and enforces identity architecture standards, access management controls, and credentials governance to minimize operational exposure. Drives vulnerability management governance across technical environments by establishing severity SLAs, standardizing inspection metrics, and overseeing remediation adherence. Leads third-party risk management initiatives by conducting security assessments of software vendors, integrations, and external technologies prior to onboarding. Oversees security questionnaire workflows and compliance reporting to deliver streamlined assurance for external stakeholders. Shapes incident response playbooks, conducts regular tabletop simulations, and acts as a primary technical advisor during security events and resilience reviews. Advises technical and operational teams on secure configuration, access modeling, secrets management, and policy execution. Evaluates emerging security platforms, governance technologies, and operational controls to continuously elevate enterprise resilience and audit readiness. Balances security risk considerations against business velocity to recommend practical controls and defensible risk-acceptance thresholds. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [This Machine Ends Data Breaches](https://www.wearedevelopers.com/videos/574-this-machine-ends-data-breaches) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)