Infosec Engineer

InApp

United States

Hybrid

USD 130,000 - 175,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

InApp is seeking an Infosec Engineer to lead security for a multi‑cloud, multi‑company footprint across AWS and Azure. This senior role reports to the Director, Infrastructure Security and drives the security roadmap for our cloud infrastructure and DevOps processes.

You’ll implement guardrails, MFA/SSO, IAM policies, and vulnerability management across the portfolio. You will work with Infrastructure, DevOps, Engineering, and Global Risk teams to harden posture across 15+ platforms while

Qualifications

  • 5+ years in security engineering or related infrastructure role with a security focus.
  • Hands-on experience securing AWS and Azure environments: IAM, network segmentation, encryption, logging, posture management.
  • Experience with cloud posture management tools (Lacework or equivalent) and AppSec scanning (Snyk, GitHub Advanced Security).
  • Experience running vulnerability management programs in production environments.
  • Familiarity with compliance frameworks (SOC 2, ISO 27001, PCI, HIPAA) and automation platforms (Vanta or equivalent).
  • Experience using IaC (Terraform/OpenTofu) and scripting (Python, Bash).

Responsibilities

  • Implement and maintain cloud security posture across AWS and Azure environments.
  • Investigate and triage security alerts; drive remediation with platform owners.
  • Implement network segmentation, encryption standards, and secrets management improvements.
  • Codify security controls as infrastructure as code wherever possible.
  • Execute MFA enforcement and SSO integration across the cloud portfolio; manage IAM policies.
  • Run vulnerability management: scanning, triage, patching coordination, MTTR tracking.
  • Participate in security incident response and post-incident hardening.
  • Author and maintain security runbooks and standards.

Skills

AWS
Azure
IAM
Cloud Security
Incident Response
Scripting

Tools

Snyk
GitHub Advanced Security
Datadog
Lacework
Terraform/OpenTofu

Job description

Infosec Engineer

Experience : 6+ years Project Location(s) : Hybrid / Remote

Job Description

You’ll be a senior hands‑on engineer executing Capacity’s security program at a pivotal moment. We’ve grown significantly through acquisition, which means we have a multi‑company, multi‑cloud footprint across AWS and Azure spanning 15+ platforms, and a security roadmap with real, meaty work: enforcing authentication security across every acquired cloud account, hardening cloud posture, and building the compliance automation that keeps SOC, ISO, PCI, and HIPAA evidence flowing without manual toil. You’ll report to the Director, Infrastructure Security and be the primary engineering muscle behind the security roadmap for our infrastructure and DevOps processes. Where the Director sets direction,you make it real: in the cloud console, in the IaC, in the SIEM, and in the compliance platform. You’llwork closely with Infrastructure, DevOps, Engineering, and Global Risk and Compliance teams across the full portfolio of platforms.

Key Responsibilities
Cloud Security Engineering
  • Implement and maintain cloud security posture across AWS and Azure environments: guardrails, configuration baselines, and drift detection (AWS Config, Lacework, Datadog)
  • Investigate and triage security alerts and findings; drive remediation to closure with platform owners
  • Implement network segmentation, encryption standards, and secrets management improvements
  • Codify security controls as infrastructure as code (Terraform, OpenTofu) wherever possible Identity and Access Management
  • Execute MFA enforcement and SSO integration across the full cloud portfolio, including acquired-company accounts
  • Implement and maintain IAM policies across AWS Identity Center, Azure PIM / Entra ID, and enterprise SSO
  • Ensure best practices related to IAM are enforced across the portfolio, including avoidance of long‑lived credentials without MFA, principle of least privilege, etc.
Application Security and Vulnerability Management
  • Operate and tune AppSec tooling (Snyk, GitHub Advanced Security) across the organization’s repositories; partner with engineering teams to remediate findings
  • Run vulnerability management: scanning coverage, triage, prioritization, patching coordination, and MTTR tracking
  • Review infrastructure and application changes for security impact Incident Response
  • Participate in security incident response: detection, containment, root cause analysis, and post‑incident hardening
  • Author and maintain security runbooks, standards, and documentation
Requirements
  • 5+ years in security engineering or a closely related infrastructure role with a security focus
  • Hands-on experience securing AWS and Azure environments: IAM, network segmentation,
    encryption, logging, and posture management
  • Experience with security tooling across the stack: cloud posture management (Lacework or
    equivalent), AppSec scanning (Snyk, GitHub Advanced Security, or equivalent), and
    SIEM/monitoring (Datadog or equivalent)
  • Experience running vulnerability management programs in production environments
  • Working knowledge of compliance frameworks (SOC 2, ISO 27001, PCI, HIPAA) and
    compliance automation platforms (Vanta or equivalent)
  • Comfortable with infrastructure as code (Terraform/OpenTofu or equivalent)
  • Previous experience with using scripting languages (Python, Bash, etc) to automate process, Evidence collection, or information gathering is a plus.
  • Experience using Claude, Gemini, Cursor, or equivalent to assist with application
    development and other tasks
  • Experience working across a multi-account, multi-company cloud environment is a big plus
  • Security certifications (e.g. CISSP, AWS Security Specialty, AZ‑500) are a plus
  • Strong cross‑functional communication; comfortable driving remediation with engineers who don’t report to you
  • Experience in a SaaS engineering environment with containerized workloads
InApp India Office

121 Nila, Technopark CampusTrivandrum, Kerala 695581
+91 (471) 277 -1800
mktg@inapp.com

InApp USA Office

999 Commercial St. Ste 210Palo Alto, CA 94303
+1 (650) 283-7833
mktg@inapp.com

InApp Japan Office

6-12 Misuzugaoka, Aoba-ku
Yokohama,225-0016
+81-45-978-0788
mktg@inapp.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer - AWS & Azure (Hybrid/Remote)
Senior Cloud Security Engineer - AWS & Azure (Hybrid/Remote)

InApp • United States

Hybrid
USD 130,000 - 175,000
Application Engineer, Cyber Security
Application Engineer, Cyber Security

Inmar Inc. • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Health insurance
Dental insurance
Vision insurance
+2
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Senior Director, ISO
Senior Director, ISO

Infor • Atlanta (GA)

On-site
USD 150,000 - 200,000
Federal Cloud Security Engineer
Federal Cloud Security Engineer

InEight • United States

Hybrid
USD 120,000 - 150,000
Application Security Architect
Application Security Architect

Alarm.com • Tysons (VA)

On-site
USD 140,000 - 210,000
Federal Cloud Security Engineer
Federal Cloud Security Engineer

InEight • Scottsdale (AZ)

Hybrid
USD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

Hampton North • United States

Remote
USD 110,000 - 150,000
Federal Cloud Security Engineer Omaha, NE
Federal Cloud Security Engineer Omaha, NE

InEight Inc. • Omaha (NE)

Hybrid
USD 110,000 - 155,000
Senior Application Security Engineer
Senior Application Security Engineer

TripleLift • New York (NY)

On-site
USD 180,000 - 230,000