Information Security Engineer (Corporate Technology)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Hybrid schedule based at the South Charlotte, North Carolina headquarters Tuesday through Thursday, with remote work on Mondays and Fridays. Candidates outside Charlotte may be considered if able to relocate to the area. Visa sponsorship or transfer is not available, and corp-to-corp work is not accepted.
Salary: $100,000–$150,000 total cash compensation per year, depending on location, experience, and qualifications.
Company
is a global portfolio of high-growth businesses spanning digital consumer experiences, health services, financial services, travel, and strategic investments.
What you will do
- Identify, assess, and reduce security risk across cloud, SaaS, and enterprise environments.
- Partner with engineering and development teams to remediate vulnerabilities across code, cloud, and endpoint environments.
- Lead the full incident response lifecycle, from alert triage through containment, eradication, and post-incident review.
- Conduct structured threat hunting and maintain and tune SIEM detection rules.
- Evaluate security tooling, contribute to the security roadmap, and produce post-incident reports for stakeholders.
- Participate in a rotating team on-call schedule.
Requirements
- 4+ years of hands-on experience in security monitoring, incident response, vulnerability management, or cloud security.
- Experience owning end-to-end incident response, including triage, containment, eradication, and post-incident review.
- Experience applying security controls, monitoring, and response techniques across AWS environments at scale.
- Hands-on experience with SIEM, endpoint protection, and vulnerability scanning platforms in cloud environments.
- Strong written and verbal communication skills, including the ability to explain technical findings to non-technical stakeholders.
- Ability to work the required hybrid schedule in South Charlotte, North Carolina, or relocate to the area; existing work authorization is required because visa sponsorship is unavailable.
Nice to have
- Threat intelligence and hypothesis-driven threat hunting experience.
- Identity and access management, least-privilege enforcement, and anomalous access detection experience.
- SaaS security posture management, Kubernetes and CI/CD security, or security workflow automation experience.
- Knowledge of PCI DSS, SOC 2, ISO 27001, NIST CSF, MITRE ATT&CK, or CIS 18.
- AWS Security Specialty, GIAC, or equivalent certifications; experience using AI tools to accelerate detection and response.
Culture & Benefits
- Health, dental, and vision insurance coverage.
- Life insurance, short- and long-term disability insurance, and flexible spending accounts.
- 401(k) plan with employer match and an employee assistance program.
- Holiday pay and a paid parental bonding benefit program.
- Flexible paid time off, with 20 days annually for full-time employees and an increase to 25 days after five years.
Hiring process
- Expect live conversations with team members before an offer is made.
- Recruiting communication will come from official or portfolio-company email addresses.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →