Назад
Company hidden
1 день назад

Information Security Engineer (Azure)

Формат работы
remote (только Spain)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US/Spain
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Security Engineer (Azure): Protecting SaaS products and hardening Microsoft Azure cloud and endpoint environments with an accent on vulnerability management, SOC 2 compliance, and Microsoft security tooling. Focus on tuning SAST and dependency scanning, improving identity and access controls, leading remediation through engineering teams, and strengthening security governance.

Location: Spain - Remote

Company

hirify.global provides global expansion services covering legal entity setup, global HR, payroll, compliance, tax, and advisory.

What you will do

  • Lead the SOC 2 compliance program, including control implementation, evidence collection, monitoring, remediation, and auditor coordination.
  • Manage vulnerabilities across SaaS products, Azure infrastructure, containers, and endpoints, including prioritization, remediation tracking, reporting, and SLA monitoring.
  • Operate and tune SAST, SCA, dependency-scanning, runtime monitoring, and security telemetry tools such as Snyk, GitHub Advanced Security, Dependabot, and Datadog.
  • Harden Microsoft Azure environments and administer Microsoft Intune and Microsoft Defender for endpoint, cloud, identity, networking, data, and workload security.
  • Develop security policies and procedures aligned with SOC 2, ISO 27001, and NIST CSF, and support vendor risk assessments, audits, and customer security reviews.
  • Partner with Engineering, IT, Legal, and Product on secure SDLC practices, threat modeling, security awareness, incident response, and tabletop exercises.

Requirements

  • 4–6 years of professional experience in information security, application security, cloud security, or a related field.
  • Experience preparing for SOC 2 Type 2 attestations for SaaS products.
  • Hands-on experience securing SaaS applications and workloads in Microsoft Azure.
  • Experience with vulnerability management, including CVSS or EPSS-based prioritization and remediation coordination with engineering teams.
  • Working proficiency with several of Microsoft Intune, Microsoft Defender, Microsoft Purview, Datadog, GitHub Advanced Security, Dependabot, and Snyk.
  • Knowledge of Microsoft Entra ID, conditional access, least-privilege design, security policy development, compliance processes, and communicating technical risk to technical and non-technical stakeholders.

Nice to have

  • CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent certification.
  • Container and Kubernetes security experience.
  • Experience with threat modeling, secure code review, or penetration testing.
  • Previous experience in a SaaS company or regulated industry.

Culture & Benefits

  • Remote work arrangement in Spain.
  • Collaboration across Engineering, IT, Legal, and Product functions.
  • Participation in security awareness training, phishing simulations, incident response exercises, and on-call rotations as needed.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →