1 день назад
Information Security Engineer (Azure)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Information Security Engineer (Azure): Protecting SaaS products and hardening Microsoft Azure cloud and endpoint environments with an accent on vulnerability management, SOC 2 compliance, and Microsoft security tooling. Focus on tuning SAST and dependency scanning, improving identity and access controls, leading remediation through engineering teams, and strengthening security governance.
Location: Spain - Remote
Company
provides global expansion services covering legal entity setup, global HR, payroll, compliance, tax, and advisory.
What you will do
- Lead the SOC 2 compliance program, including control implementation, evidence collection, monitoring, remediation, and auditor coordination.
- Manage vulnerabilities across SaaS products, Azure infrastructure, containers, and endpoints, including prioritization, remediation tracking, reporting, and SLA monitoring.
- Operate and tune SAST, SCA, dependency-scanning, runtime monitoring, and security telemetry tools such as Snyk, GitHub Advanced Security, Dependabot, and Datadog.
- Harden Microsoft Azure environments and administer Microsoft Intune and Microsoft Defender for endpoint, cloud, identity, networking, data, and workload security.
- Develop security policies and procedures aligned with SOC 2, ISO 27001, and NIST CSF, and support vendor risk assessments, audits, and customer security reviews.
- Partner with Engineering, IT, Legal, and Product on secure SDLC practices, threat modeling, security awareness, incident response, and tabletop exercises.
Requirements
- 4–6 years of professional experience in information security, application security, cloud security, or a related field.
- Experience preparing for SOC 2 Type 2 attestations for SaaS products.
- Hands-on experience securing SaaS applications and workloads in Microsoft Azure.
- Experience with vulnerability management, including CVSS or EPSS-based prioritization and remediation coordination with engineering teams.
- Working proficiency with several of Microsoft Intune, Microsoft Defender, Microsoft Purview, Datadog, GitHub Advanced Security, Dependabot, and Snyk.
- Knowledge of Microsoft Entra ID, conditional access, least-privilege design, security policy development, compliance processes, and communicating technical risk to technical and non-technical stakeholders.
Nice to have
- CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent certification.
- Container and Kubernetes security experience.
- Experience with threat modeling, secure code review, or penetration testing.
- Previous experience in a SaaS company or regulated industry.
Culture & Benefits
- Remote work arrangement in Spain.
- Collaboration across Engineering, IT, Legal, and Product functions.
- Participation in security awareness training, phishing simulations, incident response exercises, and on-call rotations as needed.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
5 дней назад
Security Engineer, Cloud (Azure)
6 дней назад
Security Engineer (Microsoft Cloud)
5 дней назад
Information Security Analyst (Cybersecurity)
6 дней назад
Application Security Engineer (Cybersecurity)
2 дня назад
IT Security & Identity Engineer (m/w/d)
3 267€
2 дня назад