2 часа назад
Senior Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Engineer (Cybersecurity): Building and continuously improving Overstory’s security and compliance program for systems, data, infrastructure, and applications with an accent on vulnerability management, cloud security, identity and access management, and SOC 2 and ISO 27001 alignment. Focus on designing secure-by-default controls, leading audit readiness, managing third-party risk, and translating security risks into actionable guidance across technical and business teams.
Location: Remote for candidates living and working in the United States, the Netherlands, the United Kingdom, Ireland, Estonia, Portugal, France, Sweden, Switzerland, Denmark, or Canada. Working hours must align with Eastern North America time zones: NST, AST, or EST.
Company
uses AI and satellite imagery to identify vegetation risks around power lines, helping utility companies prevent outages, reduce wildfire risks, and build a more resilient electrical grid.
What you will do
- Own and continuously improve the security and compliance program across infrastructure, applications, and internal systems.
- Manage vulnerability detection, prioritization, remediation workflows, and collaboration with engineering teams.
- Lead compliance activities for SOC 2 and ISO 27001, including control design, evidence collection, audit readiness, and auditor coordination.
- Improve identity and access management, endpoint security, IT security operations, and secure-by-design architecture practices.
- Own vendor security and third-party risk management, including assessments, risk evaluation, and mitigation.
- Partner with customer-facing teams on security questionnaires, awareness, documentation, and scalable response processes.
Requirements
- 5+ years of experience in security engineering, security operations, or a related field.
- Direct experience with SOC 2 and/or ISO 27001 frameworks and audit processes.
- Deep experience with vulnerability management, including tooling, prioritization, and remediation.
- Experience across AWS, GCP, or Azure and modern SaaS environments.
- Experience with identity and access management, endpoint security, and IT/security operations.
- Strong written communication, documentation, stakeholder communication, and cross-functional influencing skills.
Nice to have
- Experience designing or improving SIEM, logging, and alerting pipelines.
- Familiarity with Drata, Vanta, Tugboat, or similar compliance automation platforms.
- Application or cloud security engineering experience.
- Experience mentoring or guiding junior team members.
- Experience using AI tooling to accelerate business impact.
Culture & Benefits
- Flexible, autonomous, collaborative, remote-first working environment.
- Home office stipend, coworking budget, and ongoing education budget.
- Competitive, location-specific compensation and benefits.
- Annual in-person team gathering and occasional in-person collaboration opportunities.
- Mission-driven work focused on reducing wildfires, protecting natural resources, and addressing climate change.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 часа назад
Cybersecurity Engineer - Internal Security (Cloud/ISO 27001)
25 минут назад
Senior Information Security Engineer (Cloud Security)
2 часа назад
Security Engineer (Cybersecurity)
2 часа назад
Senior IT Security & Compliance Lead (AI)
2 дня назад
Security Architect (Cloud Security)
175 000 - 200 000$
7 часов назад