We’re looking for a Security Engineer who will be a key member of the IT Operations team, providing assistance in designing, engineering, and deploying security solutions throughout our corporate environment. You’ll work closely with stakeholders across multiple departments, acting as a subject matter expert. You’ll ensure that high-impact projects are implemented with security best practices and multiple compliance frameworks in mind.
*Visa sponsorship is NOT available at this time*
*Please note this will be a 1099 fixed term US based contract
What You'll Do
-
Work in partnership with other FloQast IT teams to design, implement, and maintain corporate IT security systems
-
Assist with third-party vendor and contractor security reviews
-
Audit 3rd party SaaS systems for security best practices and lead remediation efforts
-
Regularly triage security events with our Managed Detection & Response (MDR) partner
-
Assist with the analysis of security events & incidents, including investigating and escalating issues and participating in security event escalations
-
Maintaining existing compliance attestations and participating in risk assessment exercises
-
Assist with vulnerability management efforts, ensuring issues are triaged, prioritized, and remediated according to defined SLA’s
-
Assist with maintaining and securing internal corporate endpoints (macOS and Windows)
-
Assist with administering our endpoint management platform for enterprise-wide monitoring and dashboarding
-
Participate in IT Sprint cadence for project and initiative tracking
-
Assist with security awareness and training programs
-
Stay abreast of new and emerging security technologies and paradigms
What You'll Bring
-
4 - 6 years as a Security Engineer or IT security professional
-
Proficiency in writing custom scripts & queries to drive technical decisions and ensure repeatable, auditable configuration changes
-
Experience balancing commercial objectives and initiatives with security and compliance obligations
-
Foundational understanding of network and application fundamentals and best practices, e.g., HTTP/S, DNS, VPN, Load Balancing, SAML, OAuth, and other modern cloud/SaaS protocols
-
Experience with cloud environments AWS, GCP, Okta, or Azure/Entra ID (AWS preferred)
-
Experience enforcing security policies across macOS and Windows endpoints
-
Strong sense of ownership, urgency, and drive
-
Experience with zero-trust security concepts
-
Experience securing multi-tenant enterprise SaaS products
-
Experience with hardening tools and frameworks such as CIS benchmarks, NIST
-
Knowledge of common compliance frameworks e.g., SOC, SOX, PCI, and ISO standards
Nice To Haves/Other
-
3 - 5 years experience working within an IT team in a hyper-growth environment or startup
-
Experience supporting both onsite and remote workforces
-
Experience with Cisco Meraki and/or general network security best practices
-
Experience or participation in automation initiatives of employee onboarding and offboarding process a plus
-
Bachelor’s degree in the field of Information Technology, Computer Science, and/or relevant industry certification a plus
#LI-JP1
#LI-Hybrid