Senior Information Security Engineer

COMPLY Logo

COMPLY

💵 $125k-$140k
📍Remote - United States

Summary

Join COMPLY, a leading global provider of regulatory compliance software and solutions, as a Senior Information Security Engineer. This fully remote role requires 7-10 years of IT and cybersecurity experience and involves designing, implementing, and maintaining security controls and policies aligned with SOC 2 and ISO 27001 standards. You will lead vulnerability management, SIEM administration, incident response, and continuous security monitoring. Collaboration with internal teams and external auditors is crucial, as is contributing to security awareness training. The ideal candidate is solutions-oriented, a self-starter, and possesses excellent communication skills. This pivotal role strengthens COMPLY's security posture and ensures compliance with industry standards.

Requirements

  • 7–10 years of combined experience in IT and cybersecurity
  • Bachelor’s degree from an accredited institution in Computer Science, Information Security, Information Technology, or a related field
  • Proactive and self-driven individual with the ability to work independently in a remote setting. Excellent collaboration and communication skills with cross-functional and international teams
  • Knowledge of SOC 2, ISO 27001, or similar standards and experience aligning security programs with these or similar frameworks
  • Hands-on experience managing vulnerability management, EDR, and SIEM systems with preference on Rapid7, SentinelOne, and Microsoft Defender
  • Demonstrated proficiency with security in cloud and enterprise environments (AWS, Microsoft 365, Azure)
  • Experience developing continuous monitoring processes, detection systems, and incident response best practices
  • $125,000 - $140,000 a year

Responsibilities

  • Design, implement, and maintain security controls and policies to ensure compliance with SOC 2 and ISO 27001 standards
  • Developing and updating security procedures, access controls, and monitoring mechanisms in line with these frameworks’ requirements for delegation
  • Lead the organization’s vulnerability management program, including regular vulnerability scanning, assessment, and remediation efforts with Rapid7 InsightVM. Track and report on vulnerability status and trends monthly and drive continuous improvement in reducing risk exposure
  • Manage, configure, tune, optimize, and develop reports using the company’s Security Information and Event Management (SIEM) system Rapid7 InsightIDR
  • Investigate suspected security events and ensure that threats are detected, analyzed, and escalated in a timely manner. Coordinate with Infrastructure Operations and our 24/7/365 SOC vendor to resolve security incidents
  • Deploy and maintain detection tools like SentinelOne, Defender for Cloud/Endpoint, AWS GuardDuty, AlertLogic WAF, and cloud security monitoring that provide real-time visibility into security events
  • Establish processes to review logs and alerts, watch for anomalous behavior or indicators of compromise, and take proactive action when issues arise
  • Manage and administer the organization’s email spam filter, Mimecast, to include developing email filters and executing quarterly phishing exercises
  • Coordinate with external auditors to support security audits, assessments, and certifications such as SOC 1, SOC 2, and ISO 27001
  • Gather evidence of control effectiveness, maintain documentation (policies, procedures, risk assessments, etc.), and remediate any findings or non-conformities identified during audits. Pursue methods to automate artifact collection for annual audits
  • Lead routine internal audits to ensure ongoing compliance with security policies and standards, and drive improvements based on observations
  • Develop and refine security policies, standards, exercises, and guidelines in collaboration with the CTO senior leadership team
  • Ensure that policies address compliance requirements (e.g., access management, data protection, incident response) and are updated regularly
  • Contribute to security awareness training efforts and phishing exercises and educate employees on cybersecurity best practices
  • As a senior member of the security team, be prepared to lead out incident response activities, determine root cause, and impact to COMPLY
  • Tune security tools for better incident detection and participating in post-incident reviews to implement lessons learned
  • Collaborate with Infrastructure, Product, and Engineering teams to ensure security is embedded in development, IT infrastructure, and new projects
  • Advise and assist in implementing system configurations, conducting security design reviews, and recommending enhancements to meet security best practices in cloud-based environments (AWS, Azure.)
  • Support due diligence requests from customers to include responding to questionnaires, engaging with customers via phone or email on an as-needed basis, supporting assessments, and building/maintaining COMPLY’s Trust Center

Preferred Qualifications

  • At least one industry certification with CISSP, CCSP, CASP+, CISM, or GIAC certifications being highly preferred
  • Experience supporting security for a B2B SaaS enterprise offering services to a regulated industry (e.g., Finance, Healthcare, Government) is preferred

Benefits

  • Comprehensive medical, dental and vision insurance at little to no cost starting on day one
  • 401k with a company match
  • Supplemental benefits at a discounted rate including home, auto and pet insurance
  • Unlimited PTO
  • Professional Development reimbursements
  • Remote opportunities available for most positions
  • Time to get together in person for company happy hours, team offsites and more

Share this job:

Disclaimer: Please check that the job is real before you apply. Applying might take you to another website that we don't own. Please be aware that any actions taken during the application process are solely your responsibility, and we bear no responsibility for any outcomes.