About the role
The Information Security Engineer will manage client security questionnaires, due diligence requests, and policy updates to ensure business compliance. They will also optimize security frameworks like ISO 27001 and SOC 2 while partnering with internal and external audit teams.
What they look for
Requirements
Candidates must have 2-5 years of experience in information security compliance and a proven track record with audit programs. Proficiency in ISO 27001, SOC 2, and data privacy frameworks is required, along with strong communication skills for stakeholder management.
Full description
The Role: Information Security Engineer
Step into a pivotal position as our Information Security Engineer where your expertise directly shapes our security posture, compliance standards, and market trust. You will own complex client due diligence, manage critical framework audits, and execute compliance strategy with precision from day one. If you are looking to bring deep, practical mastery of security operations to a high-velocity team, this is where you can make an immediate impact.
Responsibilities
- Execute client security questionnaire responses, due diligence requests, and policy updates on a daily and weekly basis to drive measurable business outcomes.
- Manage and optimize ISO 27001, SOC 2, and DPIA compliance frameworks utilizing our core documentation and security management tools.
- Partner closely with internal audit teams, external certification bodies, and penetration testing partners, ensuring clear alignment, robust service delivery, and strict adherence to SLAs.
- Translate complex data, technical security constraints, or compliance requirements into highly actionable strategies and audit evidence.
- Drive continuous operational excellence while navigating a high-velocity, resilient work environment.
Required Skills & Qualifications
- Domain Expertise: 2–5 years of professional experience in information security compliance, with a proven track record of successfully navigating multiple recent audit programs (specifically SOC 2) and maintaining audit readiness. Demonstrated deep fluency in ISO 27001, SOC 2, and Data Privacy frameworks (GDPR/DPIA).
- Program Management: 2–5 years of hands-on experience managing compliance programs, leading internal audits, and responding to customer security questionnaires.
- Tech Stack Mastery: Advanced, day-one capability utilizing vulnerability management tracking tools, penetration testing remediation systems, and compliance management platforms. ISO 27001 Lead Auditor or Implementer certification preferred. Experience with automated compliance tools (such as Vanta, Drata, or Secureframe) is a nice-to-have.
- Communication: Exceptional executive storytelling; proven ability to articulate security controls, ROI, and compliance documentation to external clients, enterprise stakeholders, and audit bodies.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Similar roles
-
Cybersecurity Analyst
Skechers Manhattan Beach, California, United States · $90K–$120K/yr
-
Senior IT Security Engineer
Singapore Post Miami, Florida, United States
-
Information System Security Engineer (ISSE)
SOSi Aiea, Hawaii, United States · $125K–$168K/yr
-
Senior Security Engineer - Certificate Automation Engineer
Truist Bank Atlanta, Georgia, United States · $120K–$160K/yr
-
Application Security Remediation Engineer
Arctiq New York, New York, United States
-
Security Engineer (Remote)
Cisco Denver, Colorado, United States · $139K–$204K/yr