Role overview

Sr. Information Security Engineer

Requirements and responsibilities

Readable role content extracted into sections for faster review.

1. Cloud and Infrastructure Security

  • Design and maintain secure architectures across AWS, Azure, and GCP environments.
  • Implement guardrails and controls using services such as AWS Security Hub, GuardDuty, Config, and IAM.
  • Conduct regular vulnerability scans, configuration reviews, and remediation tracking for infrastructure and workloads.
  • Develop and enforce network segmentation, encryption, and key management policies.

2. Application & SaaS Security

  • Collaborate with DevOps and Engineering to integrate security into CI/CD pipelines (Snyk, StackHawk, etc.).
  • Perform threat modeling, code reviews, and secure design reviews for microservices and APIs.
  • Support penetration testing and application security validation efforts.
  • Help ensure PHI/PII is protected across all SaaS platforms.

3. Endpoint & Identity Security

  • Manage and enhance EDR/XDR solutions (e.g., Cortex, Defender for Endpoint).
  • Implement and monitor identity security controls through Microsoft Entra ID (Azure AD), Conditional Access, and PIM.
  • Support Intune and MDM compliance policies for Windows, macOS, and mobile devices.

4. Security Operations & Incident Response

  • Monitor alerts, investigate incidents, and coordinate responses with the SOC.
  • Develop and improve incident response runbooks, playbooks, and forensic analysis procedures.
  • Support SIEM integrations and continuous improvement of detection use cases.

5. Governance, Risk & Compliance

  • Support audits and evidence collection for HIPAA, HITRUST, SOC 2, and customer security assessments.
  • Maintain asset inventories, risk registers, and remediation tracking.
  • Collaborate with Compliance to ensure alignment between security controls and policies.
  • Contribute to security awareness and training initiatives.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, or equivalent experience.
  • 5+ years of experience in security engineering or related technical security roles.
  • Strong knowledge of cloud-native security (AWS, Azure) and modern SaaS architectures.
  • Hands-on experience with SIEM, EDR/XDR, IAM, vulnerability management, and security automation.
  • Familiarity with HIPAA, HITRUST, and SOC 2 requirements.
  • Experience securing containerized and serverless workloads (e.g., EKS, Lambda).

Preferred:

  • Certifications such as CISSP, CISM, CCSP, AWS Security Specialty, or GIAC (GSEC, GCIA, GCIH).
  • Experience with Terraform, Ansible, or CloudFormation for infrastructure-as-code security.
  • Experience in DevSecOps pipelines and tools (e.g., Jenkins, Bitbucket).
  • Strong scripting skills (Python, PowerShell, or Bash).

Key Competencies

  • Analytical and detail-oriented with strong problem-solving skills.
  • Ability to balance business needs with risk mitigation.
  • Excellent communication skills, able to translate complex technical topics for non-technical stakeholders.
  • Collaborative team player with a proactive approach to continuous improvement.
Similar roles

Keep a backup shortlist.

Browse stack
FocusInformation SecurityRole area
Seniority signalSeniorCandidate level
StackAWS, Azure, CI/CDPrimary skills
Location1 accepted countryEligibility

Stack

Use these tags to compare similar remote roles.

Location eligibility

Candidates should apply only when their profile country is listed here.

Your profileCountry not setSign in to check your country against this role.

Hiring flow

WithMira shows the role, then sends candidates to the company application.

1Check role fit, stack, and location eligibility in WithMira.
2Open the company application page from the tracked apply link.
3Save the role or subscribe for similar opportunities before leaving.
Apply on company siteCompany siteOpen link