> Markdown version of [/jobs/ext/3469544-senior-information-security-specialist](https://www.wearedevelopers.com/jobs/ext/3469544-senior-information-security-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Security Specialist - **Company:** HALCYON MASSAGE - **Location:** Austin, TX, United States - **Experience:** Expert - **Salary:** $120,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, CompTIA Security+, Cyber Security, Disaster Recovery, Software Engineering, Software Vulnerability Management, Gsuite, CIS Benchmarks, Devsecops - **Published:** September 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=eb899bd815a23376 ## About the Role * 5+ years of experience in information security, GRC, or IT risk management. * Strong understanding of cybersecurity concepts, controls, and risk frameworks. * Demonstrated experience with third-party risk management processes and tooling. * Proven ability to coordinate security testing and vulnerability management efforts. * Excellent communication, documentation, and cross-functional collaboration skills. * Ability to assess and implement technical and administrative controls across cloud and hybrid environments. * Experience with regulatory compliance and audit support in fast-paced environments. * Hands-on participation in incident response or disaster recovery exercises is a plus. Bonus Skills and Qualifications: * Experience with compliance platforms (e.g., Drata, Vanta). * Knowledge of security frameworks beyond SOC 2 and ISO 27001, such as NIST 800-53 or CIS Controls. * Familiarity with secure software development practices or DevSecOps principles. * Background in auditing or supporting third-party security assessments. * Experience with Microsoft 365 and/or Google Workspace security configuration. * Exposure to regulatory environments such as HIPAA, GDPR, or CCPA. * Certifications such as CISSP, CISA, CISM, Security+, or similar are a plus. ## Description * Perform and maintain third-party risk assessments and track vendor remediation activities. * Support coordination and analysis of internal and external security testing, including vulnerability scans and penetration tests. * Develop, track, and follow up on corrective action plans for identified security gaps or audit findings. * Collaborate with managed security service providers and internal stakeholders to monitor and manage security events and escalations. * Partner with engineering and operations teams to ensure implementation of security and compliance requirements across the organization. * Assist in developing, maintaining, and communicating information security policies, standards, and procedures. * Coordinate security incident response planning, disaster recovery testing, and business continuity exercises. * Monitor and support enforcement of technical and administrative security controls across the enterprise. * Stay current with evolving security and privacy regulations and frameworks (e.g., SOC 2, ISO 27001, TX-RAMP, FedRAMP). ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)