At Barracuda, we aim to protect businesses with cloud‑enabled, enterprise‑grade security solutions that are easy to buy, deploy, and use.
We are looking for a highly motivated and detail‑oriented Information Security Engineer to support our organization’s security posture. The successful candidate will have a strong background in information security, with at least two years of relevant experience.
Responsibilities include:
- Performing vulnerability assessments and penetration testing.
- Developing and implementing security policies and procedures.
- Collaborating with cross‑functional teams to maintain a robust security posture.
- Onboarding and implementing GRC tools.
- Responding to security events, incidents, and threat hunting activities.
- Supporting day‑to‑day GRC activities, such as control tracking, evidence collection, audit coordination, and remediation follow‑up.
- Assisting with internal and external audit readiness for ISO 27001:2022, SOC 2 Type 2, and similar frameworks.
- Responding to customer security and compliance questionnaires and maintaining consistency with approved documentation.
- Coordinating with internal teams (Security, IT, Engineering, Legal, Sales, Customer‑facing teams) for audits and compliance reviews.
- Tracking open compliance gaps, audit findings, third‑party risks, and customer assurance follow‑ups.
- Supporting updates to security policies, procedures, standards, and internal documentation.
- Gaining exposure to SOC workflows, such as incident evidence collection and security control validation.
Technologies and Platforms
- Microsoft 365 tools (Teams, SharePoint, OneDrive, Excel, Power Apps).
- Jira or similar ticketing/tracking tools.
- Audit evidence repositories and internal documentation platforms.
- Basic exposure to cloud environments (AWS, Azure, Microsoft 365).
- Limited exposure to security operations workflows and evidence collection processes.
Qualifications
- 2+ years of experience in Information Security, GRC, IT risk, compliance, audit support, customer assurance, TPRM, or a related area.
- Basic understanding of security governance, risk management, compliance controls, audit processes, and security documentation.
- Exposure to audits or compliance assessments (ISO 27001:2022, SOC 2 Type 2, internal audits, customer audits).
- Experience supporting customer security questionnaires and compliance documentation.
- Basic understanding of Third‑Party Risk Management and vendor risk reviews.
- Strong written communication skills for preparing clear compliance responses.
- Ability to coordinate with internal stakeholders to gather information and close open items.
- Foundational knowledge of security concepts (access control, logging, vulnerability management, incident response, data protection, encryption, change management, business continuity).
- Bachelor’s degree in information security, IT, computer science, cybersecurity, risk management, or equivalent practical experience.
Nice to Have
- Familiarity with ISO 27001:2022, SOC 2 Type 2, NIST CSF, CIS Controls, PCI DSS, GDPR, or similar frameworks.
- Experience with customer trust, assurance, or RFP security responses.
- Background in vendor security reviews or third‑party risk assessments.
- Entry‑level certifications such as CompTIA Security+, ISC² Certified In Cybersecurity, ISO 27001 Foundation/Internal Auditor.
Benefits
A supportive team environment, internal mobility opportunities, and equity (non‑qualifying options). Barracuda complies with all applicable nondiscrimination and equal opportunity laws.