Назад
Company hidden
23 часа назад

Information Security Engineer (Corporate Technology)

100 000 - 150 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Релокация
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Engineer (AWS/Cloud Security): Identifying and reducing security risk across cloud, SaaS, and enterprise environments with an accent on incident response, vulnerability remediation, threat hunting, and SIEM detection tuning. Focus on leading containment and eradication, partnering with engineering teams, and building scalable security operations for complex cloud environments.

Location: Hybrid schedule based at the South Charlotte, North Carolina headquarters Tuesday through Thursday, with remote work on Mondays and Fridays. Candidates outside Charlotte may be considered if able to relocate to the area. Visa sponsorship or transfer is not available, and corp-to-corp work is not accepted.

Salary: $100,000–$150,000 total cash compensation per year, depending on location, experience, and qualifications.

Company

hirify.global is a global portfolio of high-growth businesses spanning digital consumer experiences, health services, financial services, travel, and strategic investments.

What you will do

  • Identify, assess, and reduce security risk across cloud, SaaS, and enterprise environments.
  • Partner with engineering and development teams to remediate vulnerabilities across code, cloud, and endpoint environments.
  • Lead the full incident response lifecycle, from alert triage through containment, eradication, and post-incident review.
  • Conduct structured threat hunting and maintain and tune SIEM detection rules.
  • Evaluate security tooling, contribute to the security roadmap, and produce post-incident reports for stakeholders.
  • Participate in a rotating team on-call schedule.

Requirements

  • 4+ years of hands-on experience in security monitoring, incident response, vulnerability management, or cloud security.
  • Experience owning end-to-end incident response, including triage, containment, eradication, and post-incident review.
  • Experience applying security controls, monitoring, and response techniques across AWS environments at scale.
  • Hands-on experience with SIEM, endpoint protection, and vulnerability scanning platforms in cloud environments.
  • Strong written and verbal communication skills, including the ability to explain technical findings to non-technical stakeholders.
  • Ability to work the required hybrid schedule in South Charlotte, North Carolina, or relocate to the area; existing work authorization is required because visa sponsorship is unavailable.

Nice to have

  • Threat intelligence and hypothesis-driven threat hunting experience.
  • Identity and access management, least-privilege enforcement, and anomalous access detection experience.
  • SaaS security posture management, Kubernetes and CI/CD security, or security workflow automation experience.
  • Knowledge of PCI DSS, SOC 2, ISO 27001, NIST CSF, MITRE ATT&CK, or CIS 18.
  • AWS Security Specialty, GIAC, or equivalent certifications; experience using AI tools to accelerate detection and response.

Culture & Benefits

  • Health, dental, and vision insurance coverage.
  • Life insurance, short- and long-term disability insurance, and flexible spending accounts.
  • 401(k) plan with employer match and an employee assistance program.
  • Holiday pay and a paid parental bonding benefit program.
  • Flexible paid time off, with 20 days annually for full-time employees and an increase to 25 days after five years.

Hiring process

  • Expect live conversations with hirify.global team members before an offer is made.
  • Recruiting communication will come from official hirify.global or portfolio-company email addresses.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →