Information Security Engineer New United States - Remote

HSP Group

Northern (KY)

Remote

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Remote work

Job summary

HSP Group is seeking a hands-on mid-level Information Security Engineer for a remote role. You will protect SaaS products, harden Azure and endpoints, and mature the security program.

You will lead SOC 2 efforts, manage vulnerabilities, and collaborate with Engineering, IT, Legal, and Product to improve security posture. Requirements include 4–6 years in information security, Azure security experience, and strong communication skills.

Qualifications

  • 4–6 years of professional information security experience.
  • Experience preparing for SOC 2 Type 2 attestations for SaaS.
  • Hands-on security for SaaS workloads in Microsoft Azure.
  • Experience with vulnerability management tooling and remediation.
  • Familiarity with IAM concepts, especially Azure AD and conditional access.
  • Experience writing security policies, standards, or procedures.
  • Strong written and verbal communication for technical and non-technical audiences.

Responsibilities

  • Lead SOC 2 readiness and audit coordination.
  • Manage vulnerability program across SaaS products and cloud infra.
  • Operate SAST, SCA and dependencies tooling and drive remediation.
  • Monitor telemetry (Datadog) and investigate security alerts.
  • Report security KPIs and drive improvements with leadership.
  • Hardening of Azure identity, networking, data and workloads.
  • Administer Microsoft Intune and Defender for endpoints.
  • Draft and maintain security policies and procedures.
  • Support vendor risk assessments and customer questionnaires.

Skills

SOC 2 readiness
Azure security
Vulnerability management
Identity & access management
Policy writing
Security audits
Communication

Tools

Datadog
GitHub Advanced Security
Dependabot
Snyk
Microsoft Defender
Microsoft Intune
Purview

Job description

HSP Group is the premier provider of global expansion services, helping companies simplify the complex challenges ofoperatinginternationally. We deliver a seamless experience acrosslegal entity setup, global HR, payroll, compliance, tax, and advisory, enablingour clients to scale faster, stay compliant, and reduce risk in every market they enter.

With scale-up organizations and innovative technology firms expanding at unprecedented speed, HSP is uniquely positioned to become their trusted global partner.

Job Description

This is a remote role.

We are seeking a hands-on, mid-level Information Security Engineer to help protect our SaaS products, harden our cloud and endpoint environments, and mature our overall security program. This role sits at the intersection of technical security operations and governance. You will manage vulnerabilities across our products and infrastructure, contribute to corporate security policies, lead SOC 2 efforts, and serve as a key voice in customer and vendor security conversations.

Our entire technology stack runs in Microsoft Azure, and we leverage the broader Microsoft security ecosystem (Intune, Defender, Purview) alongside best-in-class tooling like Datadog, GitHub, and Snyk. You will work closely with Engineering, IT, Legal, and Product teams to drive measurable improvements to our security posture.

Responsibilities:
Vulnerability & Product Security
  • Lead the company’s SOC 2 compliance program, including readiness, control implementation, evidence collection, ongoing monitoring, remediation, and coordination with auditors through successful completion of the audit.
  • Lead the vulnerability management program across our SaaS products, cloud infrastructure, containers, and endpoints including identification, triage, prioritization, remediation tracking, and reporting.
  • Operate and tune SAST, SCA, and dependency-scanning tooling (e.g., Snyk, GitHub Advanced Security/Dependabot) and partner with engineering teams to drive timely remediation.
  • Monitor runtime and infrastructure telemetry (e.g., Datadog) for security signals; investigate alerts and lead containment and follow-up actions.
  • Track and report on vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership.
  • Enhance the security posture of our Microsoft Azure environment including identity, networking, data, and workloads through configuration hardening, policy enforcement, and continuous monitoring.
  • Administer and improve Microsoft Intune for endpoint configuration, compliance, and mobile device management.
  • Tune and maintain Microsoft Defender (Endpoint, Cloud, and related products) for threat detection, response, and reporting.
  • Draft, update, and maintain corporate information security policies, standards, and procedures aligned to recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF).
  • Lead the response to customer and prospect security questionnaires, RFPs, and due-diligence requests, and maintain a reusable response library.
  • Support vendor risk assessments and third-party security reviews.
  • Assist with internal and external audits, evidence collection, and remediation of findings.
Security Program & Collaboration
  • Partner with Engineering on secure SDLC practices, threat modeling, and code review guidance.
  • Contribute to security awareness training, phishing simulations, and a strong security culture across the company.
  • Help mature incident response playbooks and participate in tabletop exercises and on-call rotations as needed.
Requirements:
  • 4–6 years of professional experience in information security, application security, cloud security, or a closely related role.
  • Experience in preparing for SOC 2 Type 2 attestations for SaaS products.
  • Hands-on experience securing SaaS applications and workloads running in Microsoft Azure.
  • Demonstrated experience with vulnerability management tooling and process including triage, prioritization (e.g., CVSS, EPSS, exploitability context), and driving remediation through engineering teams.
  • Working proficiency with several of the following: Microsoft Intune, Microsoft Defender (Endpoint/Cloud), Microsoft Purview, Datadog, GitHub (Advanced Security, Dependabot, code scanning), and Snyk.
  • Solid understanding of identity and access management concepts, particularly Microsoft Entra ID (Azure AD), conditional access, and least-privilege design.
  • Experience writing or substantially contributing to security policies, standards, or procedures.
  • Experience in responding to customer security questionnaires and supporting compliance efforts.
  • Strong written and verbal communication skills and able to translate technical risk for both engineers and non-technical stakeholders.
Nice to Have:
  • Industry certifications such as CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent.
  • Experience with container and Kubernetes security.
  • Exposure to threat modeling, secure code review, or penetration testing.
  • Prior experience in a SaaS company or regulated industry.

If you’re a driven individual who wants to make your mark in the heart of the innovation economy, we’d love to meet you. Join our#HSPGlobalSolutionTeam and help us power the next wave of global growth.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Remote Information Security Engineer - SOC 2 & Cloud Security
Remote Information Security Engineer - SOC 2 & Cloud Security

HSP Group • Northern (KY)

Hybrid
USD 110,000 - 140,000
Remote work
Security Engineer
Security Engineer

Gravity IT Resources • Salt Lake City (UT)

On-site
USD 120,000 - 160,000
Remote Information Security Engineer: SOC2 & Azure Security
Remote Information Security Engineer: SOC2 & Azure Security

HSP Group • United States

On-site
USD 90,000 - 130,000
Cloud Security Engineer New United States - Remote
Cloud Security Engineer New United States - Remote

CyberSheath Services International, LLC • Northern (KY)

Hybrid
USD 85,000 - 100,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

Advanced Operations Partners • United States

On-site
USD 140,000 - 190,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Application Security Engineer
Application Security Engineer

Hampton North • United States

Remote
USD 110,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000