Sr. Security Engineer
VELOCITOR SOLUTIONS Charlotte, North Carolina, United States
Software Development · 51-200 employees
About the role
The Senior Security Engineer will own the day-to-day security posture of the infrastructure and application platform, including vulnerability management and penetration testing. They will also lead identity and access control hardening, incident response, and ensure compliance with SOC 2 and GDPR standards.
What they look for
Requirements
Candidates must have at least 8-10 years of IT technical experience, with at least 8 years specifically in security analysis or cloud security. Proficiency in Azure security, Kubernetes, and identity management systems is required, along with a bachelor's degree.
Benefits
Full description
Job DetailsJob Location: Charlotte, NC 28217Position Type: Full TimeJob Category: Information TechnologySr. Security Engineer
Type: Full-time Location: Charlotte, NC (Onsite) Team: IT / Information Security
About Velocitor Solutions
Velocitor Solutions is a leader in enterprise fleet management and mobile innovation, celebrating over 25 years of profitably growing technology. We go beyond standard telematics by offering a comprehensive, managed ecosystem—managing over 200,000 mobile assets for Fortune 500 clients across North America. Our V-Track platform integrates GPS tracking, AI-powered video telematics, and real-time data to drive safety and efficiency. We are in a pivotal phase of growth and looking to expand technology team.
Why Join Velocitor Solutions
You will own security for a platform that runs mission-critical fleet operations for national enterprise clients. The work is visible, the stakes are concrete, and the roadmap is active. You will have the mandate to fix what you find.
Role Summary
We are hiring a Senior Security Engineer in IT to own the day-to-day security posture of Velocitor's infrastructure and application platform. You will drive vulnerability management, lead and coordinate penetration testing, harden our Azure and AKS environments, and tighten identity and access controls across the organization. You will work closely with the platform, DevOps, engineering, and client-facing teams, and you will translate findings into fixes that ship. This is a hands-on role for someone who can both run the assessment and shape the remediation of the environment.
Key Responsibilities
Own vulnerability management across Azure, AKS, on-premises systems, and client-facing applications. Prioritize by real risk and client impact, not raw CVE counts. Lead and coordinate penetration testing engagements, including scoped tests against client UAT and production environments. Manage internal testers and third-party firms, track findings to closure, and produce client-ready results. Harden our identity stack on Entra ID and Auth0. Drive least-privilege access, reduce standing Domain Admin exposure through Restricted Management Administrative Units, and close IAM gaps as access volume scales. Secure the AKS platform and CI/CD pipelines. Review container images, cluster configuration, secrets management, and network policy. Build and maintain security runbooks, incident response procedures, and detection logic. Participate in the security on-call rotation and lead incident response when events occur. Own compliance and audit readiness end to end, including SOC 2 and GDPR. Manage relationships with external auditors and security vendors, coordinate evidence collection, and drive remediation of findings. Own client security requirements and questionnaires. Lead RCAs and remediation plans when incidents touch client environments. Partner with DevOps and engineering to embed security into the delivery pipeline rather than gating it at the end. Track and report platform security posture to leadership with clear metrics and recommendations.
QualificationsRequired Qualifications Bachelor Degree or at least 8-10 years of IT Technical experience. 8+ years in security analysis, application security, or cloud security, with at least 2 years in a senior or lead capacity. Strong hands-on Azure security experience: Defender for Cloud, Entra ID, network security, key management. Working knowledge of Kubernetes and container security, ideally AKS. Solid grasp of identity and access management, including RBAC, privileged access, and modern auth patterns (OAuth, OIDC, SSO). Hands-on experience owning or leading compliance programs, specifically SOC 2 and GDPR, including audit coordination and evidence management. Scripting for automation (PowerShell, Python). Comfort working across a distributed organization, coordinating with the offshore engineering teams and engaging directly with client stakeholders. Incident response experience, including participation in an on-call rotation and leading response during active incidents. Clear written communication. You can turn a finding into a decision. Preferred Skills Security certifications such as CISSP, OSCP, GCIH, or Azure Security Engineer Associate. Experience securing telematics, IoT, or fleet platforms. Experience with EU data residency and multi-region deployment security. Compensation & Benefits Competitive salary commensurate with experience and qualifications. Comprehensive health, dental, and vision insurance. Paid time off and holidays. Retirement savings plan options. Opportunities for career advancement and professional growth.
Similar roles
-
Cybersecurity Engineer
Stellar Solutions Inc El Segundo, California, United States · $115K–$145K/yr
-
Application Security Engineer
MyFitnessPal United States · $90K–$130K/yr
-
Cybersecurity Solutions Operations Support (Senior)
Interclypse, Inc. Annapolis Junction, Maryland, United States
-
Cybersecurity Solutions Operations Support (Mid)
Interclypse, Inc. Annapolis Junction, Maryland, United States
-
Staff Security Engineer, Product & Platform Security
Nscale San Francisco, California, United States · $190K–$230K/yr
-
Cybersecurity Solutions Operations Support (Junior)
Interclypse, Inc. Annapolis Junction, Maryland, United States