Information Security Engineer- Software as a Service

RESOURCEFUL ENVIRONMENTAL SERVICES, INC.
Chicago, United States of America
yesterday

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior
Compensation
$ 183K

Job location

Remote
Chicago, United States of America

Tech stack

Java
Microsoft Windows
Artificial Intelligence
Amazon Web Services (AWS)
Data analysis
Apple Mac Systems
Asana
Azure
Cisco IOS
Software as a Service
Cloud Computing Security
Computer Security
Computer Programming
Linux
Disaster Recovery
Identity and Access Management
Intrusion Detection and Prevention
Information Systems Security Architecture Professional
PCI Data Security Standards
Power BI
Virtualization Technology
Software Vulnerability Management
Cloud Platform System
Okta
Microsoft Power Automate
Prompt Engineering
Generative AI
Cyber Threat Analysis
Information Technology
Devsecops
Workday

Job description

Serve on a team of Cybersecurity Engineers responsible for supporting the organization's vulnerability and threat management programs (e.g., vulnerability management, threat intelligence, application security testing, and attack surface management). This role focuses on Software as a Service (SaaS) vulnerability management, under the direction of the Vulnerability and Threat Program Manager and collaborates with IT, Cybersecurity, and Technical Stakeholder teams to maximize the security of applications and data. The ideal candidate will have a strong technical background in cybersecurity, hands-on experience with vulnerability management tools, collaborative approach to problem-solving, and ability to communicate clearly and concisely. Job Responsibilities:

  • Conduct continuous identification and assessment of SaaS exposures, to include misconfigurations, permission sprawl, insecure integrations, and identity centric risks across enterprise SaaS platforms.
  • Analyze security findings and provider advisories to identify and prioritize corrective action(s) based on exposure, exploitability, and business criticality.
  • Document and track SaaS security risks, remediation actions, and posture trends using automated risk registers, POA&Ms, and exception requests. Generate and brief technical and executive level reports aligned to applicable regulatory and audit requirements.
  • Develop, implement, and sustain security configuration baselines and hardening standards, mapped to organizationally mandated frameworks ( CIS, NIST CSF, etc.).
  • Partner with SaaS application owners and identity, GRC, and enterprise teams to coordinate remediation of customer controlled SaaS risks.
  • Plan and execute SaaS security posture assessments to measure connected application compliance and alignment across the SaaS portfolio.
  • Participate in cross-functional risk and threat modeling activities and provide actionable recommendations for reduction or transference of risk.
  • Develop, implement, and update vulnerability management policies, standards, and TTPs supporting SaaS vulnerability and exposure management processes.
  • Utilize autonomous skills to leverage organizational Artificial Intelligence (AI) tools to effectively and efficiently assess exposure and risk at scale.
  • Liaison with applications teams, business stakeholders, and vendor representatives to review security posture, remediation ownership, compensating controls, and contractual and regulatory compliance.
  • Support and mature proactive cybersecurity strategies to include CTEM, SaaS Attack Surface Management, Identity Threat Detection and Response (ITDR), and zero trust access models.
  • Maintain up-to-date knowledge of emerging threats, vulnerabilities, and cybersecurity best practices.
  • Assist with cybersecurity tool evaluation and implementation, and operation.
  • Participate in organizational and third-party training and workshops to enhance professional knowledge and team performance., * Manage SaaS platforms - specifically Workday, Monday.com, and Epic and Other SaaS platforms
  • These platforms can't be scanned directly, so a major focus is making sure they're securely configured through other means
  • Build and maintain vendor relationships - including making the case to vendors on why they need to prioritize this work, since they don't currently have visibility/access into these systems
  • Support a shift toward continuous threat exposure management (CTEM) - identifying what's most exposed and where the real risk sits, rather than treating everything as equal priority
  • Discovery work is a big piece of this: building out a repository/inventory of these platforms and figuring out the right order to tackle them
  • Partner with stakeholders to help shift security culture across the org

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience).
  • Professional certification as Certified Information Systems Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP+), GIAC Security Leadership Certification (GSLC), or equivalent.
  • Minimum 5 years of experience in cybersecurity, with at least 3 years focused on vulnerability management, compliance validation, or threat analysis.
  • Experience with multiple operating systems to include Windows, MacOS, Linux, Cisco iOS, etc.
  • Hands-on experience with SSPM, CASB, IAM, or equivalent SaaS vulnerability management tools (e.g., Wiz, Microsoft Defender, Netskope, Entra ID, Okta).
  • Familiarity with prompt engineering and leveraging of AI tools to automate manual processes and supplement data analysis.
  • A strong understanding of networking, infrastructure, application, and information concepts and associated security principles.
  • Experience in risk assessment and mitigation processes, practices, and strategies.
  • Strong analytical, documentation, and communication skills.
  • Ability to lead cybersecurity engineering projects and effectively communicate with business partners.
  • Excellent interpersonal and communications skills, with the ability to work collaboratively in a team environment.
  • Ability to work under pressure and effectively handle multiple responsibilities in a fast-paced and critical heath care environment., * Experience with business efficiency/intelligence tools (e.g., Power BI, Power Automate, Generative AI).
  • Experience with industry cybersecurity frameworks (e.g., CIS, NIST, PCI DSS).
  • Experience with Business Efficiency, Business Intelligence, or Generative AI products.
  • Exposure to incident response and disaster recovery procedures.
  • Exposure to virtualization and cloud platform security (e.g., Azure, AWS).
  • Familiarity with DevSecOps practices and secure software development methodologies

Resource Consultings Services Inc, Minimum qualifications: Bachelor's degree or equivalent practical experience. 2 years of programming experience in Java. 2 years of experience in coding and system design with …

  • 12 days ago

Apply for this position