Remote job
Security Engineer I, Information Technology
Job details
About this role
Role overview Strengthen and optimize the security posture of a global communications technology organization by designing secure architectures across cloud, on-premise, and third-party environments. The role partners with engineering, R&D, and compliance teams to embed security into development workflows, respond to incidents, and advance cryptographic and identity practices.
Responsibilities - Design, implement, and maintain security architectures across cloud, third-party, and on-premises systems while evaluating emerging security technologies - Embed security into CI/CD pipelines, define standards, and conduct secure code reviews with development teams - Manage encryption for data at rest and in transit, including cryptographic key handling aligned with industry standards - Build and operate identity and authentication solutions using SSO, identity providers, and federation protocols such as SAML, OAuth, and OpenID Connect - Apply GRC frameworks (for example NIST, SOC2, ISO 27001, Cyber Essentials) to align technical controls with audit and regulatory needs - Perform risk assessments, threat modeling, and vulnerability analyses; lead incident response and continuous monitoring in collaboration with the SOC - Mentor junior engineers and act as a subject matter expert across cross-functional teams
Requirements - Deep familiarity with security standards and frameworks such as NIST, ISO 27001, and CIS Controls, alongside regulations like GDPR, HIPAA, and PCI-DSS - Hands-on experience with security tools including IDS/IPS, SIEM, vulnerability scanners, and penetration testing platforms - Experience securing cloud platforms such as AWS, Azure, GCP, OCI, or Alibaba and protecting cloud-native applications - Proficiency in programming languages such as Python, Java, or C++ and automation tools such as Terraform or Ansible - Strong knowledge of networking protocols, firewalls, VPNs, proxies, and security monitoring tools - 5+ years of relevant experience in security engineering and GRC-focused solution development - Extensive DevSecOps experience integrating controls into CI/CD pipelines - Proven expertise in cryptography, key management, and digital signatures
Nice to have - Familiarity with identity platforms such as Okta or Keycloak
Benefits and work setup - Friendly, learning-focused environment with an extensive people development program and access to Udemy - 25 vacation days plus additional days based on age and children, and a cafeteria benefit via a SZEP card - Private health insurance for employees and family members - 10% of time allocated to personal projects, reading groups, and tech talks - Flexible working with remote options - After-hours availability required for urgent incident response - Interview process includes a hands-on practical exercise via screen sharing