Information Security Engineer
About Keyfactor
Our focus is on creating a connected society built on trust, with security at the forefront for every individual and machine. Keyfactor is dedicated to helping organizations establish and maintain digital trust efficiently on a large scale. We have a wealth of cybersecurity experience, serving over 1,500 global companies. Recognized as a top workplace, our exceptional team drives our culture as we expand. Trust your future with Keyfactor!
Location: United States; Remote
Experience Level: Mid-Level
Job Function: IT Compliance
Employment Type: Full-Time
Industry: Computer Network & Security
Job Summary
We are looking for an Information Security Engineer proficient in implementing and managing general information security frameworks, including ISO 27001:2022 and SOC 2 Type II. Preferably, candidates should have experience with government compliance frameworks like FedRAMP and CMMC. This role entails designing, maintaining, and enhancing our security infrastructure for regulatory compliance and continuous monitoring. The ideal candidate will be pivotal in securing the organization's data and systems while ensuring adherence to evolving security standards.
Responsibilities
- Evaluate vulnerabilities, conduct system audits, and analyze risks using standard scanning tools to maintain a proactive security stance.
- Oversee and execute continuous monitoring processes to ensure compliance with various information security frameworks. Emphasis on ISO 27001:2022 and SOC 2 Type II, with a preference for expertise in FedRAMP (NIST SP 800-53) and CMMC. The role involves maintaining stringent security measures and adapting to evolving compliance standards.
- Collaborate with IT, DevOps, Engineering, and Compliance departments to enforce security policies, procedures, and best practices.
- Monitor and respond to security alerts and incidents, conducting investigations, incident handling, and proposing necessary corrective measures.
- Provide expert advice on security issues to support secure operations and development.
- Aid in creating, managing, and revising security documentation including System Security Plans (SSPs) and Plan of Actions & Milestones (POA&Ms) required for FedRAMP.
- Implement and validate Security Technical Implementation Guides (STIGs) and federal guidelines for securing systems across various platforms and technologies.
Minimum Qualifications
- 5+ years in information security or a related field
- Proficiency in vulnerability scanning tools and interpretation of scan results for remediation.
- Strong grasp of security standards and practices
- Experience in continuous monitoring, network security, firewalls, VPNs, IDS/IPS, and endpoint protection.
- Excellent analytical skills and a methodical problem-solving approach
- Demonstrated ability to deliver on schedule
- Preferred certifications such as CISSP, CompTIA Security+, or CAP
- Familiarity with cloud security principles
- Experience with security automation tools and continuous monitoring
- Knowledge of Public Key Infrastructure (PKI) would be beneficial
- Proficiency in scripting languages (Python, PowerShell) for automating security processes
- Familiarity with STIG configuration and implementation practices across diverse environments
- Expertise in government-related InfoSec compliance frameworks like NIST 800-53, NIST 800-171
- Experience in government-regulated environments (AWS GovCloud, Azure Government) is advantageous
Level of Authority
- Limited decision-making authority that involves operational tasks and seeking guidance for significant changes or actions from more experienced team members or supervisors.
Travel Requirements
- Up to 10% travel anticipated.
Compensation
Salary to be aligned with experience level.
Culture, Career Opportunities, and Benefits
We foster a culture of continuous improvement and growth, challenging you to develop personally and professionally every day. With a blend of freedom and structure, we encourage creativity and innovation in an entrepreneurial setting. Our unique initiatives include company-wide days off, comprehensive benefits, paid parental leave, employee-focused programs, commitment to diversity and inclusion, wellness resources, volunteering opportunities, and ample professional development support.
Core Values
We operate based on core values critical to our business and integral in every team member:
- Trust: Integrity and trustworthiness are fundamental to every aspect of our business.
- Customers: Guided by a customer-centric approach focused on their security interests.
- Innovation: Committed to staying ahead of the innovation curve through investment and focus.
- Agility: Thrive in dynamic environments, driving towards strategic goals amidst change.
- Respect: Unified by respect, promoting diversity, inclusivity, equity, empathy, and openness.
- Teamwork: Achieving shared goals through teamwork, partnerships, and unity.
Keyfactor is proud to be an equal opportunity employer. If applicants require accommodations due to disabilities, they can contact our People team.