Senior Information Security Engineer

Grayson Search Partners

Nashville (TN)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Grayson Search Partners is seeking a Senior Information Security & Compliance Engineer in Nashville to lead security controls, compliance efforts, and risk management across our cloud-based environment.

You will collaborate with MSPs and engineering teams to strengthen security posture, drive audit readiness, and ensure regulatory obligations are met. This role blends hands-on security work with customer-facing compliance activities in a SaaS setting.

Qualifications

  • Minimum of seven years of professional experience in cybersecurity or information security.
  • Hands-on background in security engineering or security operations.
  • Experience supporting SOC 2, ISO 27001, or comparable frameworks.
  • Strong vulnerability identification, prioritization, and remediation.
  • Experience with security monitoring platforms, endpoint protection, and threat management tools.
  • Knowledge of identity and access management principles and best practices.
  • Experience contributing to incident response and cybersecurity investigations.
  • Excellent communication, documentation, and stakeholder engagement skills.

Responsibilities

  • Oversee day-to-day cybersecurity operations in collaboration with managed security providers and technology partners.
  • Direct vulnerability assessment activities and coordinate remediation efforts across systems and applications.
  • Participate in the detection, analysis, containment, and resolution of security incidents.
  • Manage and maintain security technologies such as SIEM platforms, endpoint protection solutions, email security systems, vulnerability management tools, and identity security controls.
  • Contribute to the creation, review, and ongoing enhancement of security policies, practices, and governance documentation.
  • Facilitate internal and external audit engagements, including preparation and collection of supporting evidence.
  • Perform security risk evaluations and technical control assessments.
  • Assist with customer due diligence reviews and responses to security-related inquiries.
  • Ensure adherence to established security requirements, regulatory obligations, and compliance standards.
  • Work closely with infrastructure and software development teams to strengthen the organization's overall security posture.
  • Review proposed system and process changes for security implications and compliance alignment.
  • Monitor corrective action plans and drive continuous improvement initiatives across the security program.

Skills

Cybersecurity
Security operations
Vulnerability management
Incident response
Audit readiness
Regulatory compliance
Communication

Tools

SIEM
Endpoint protection
Threat management tools
Identity security controls

Job description

Senior Information Security & Compliance Engineer

Position Overview

The Senior Information Security & Compliance Engineer reports to the Senior Infrastructure Manager and plays a critical role in safeguarding the organization's systems, data, and regulatory posture. This individual is responsible for developing, administering, and enhancing security controls, compliance initiatives, and risk management practices across the enterprise.

Serving as a key security subject matter expert, the role focuses on operational cybersecurity, governance, audit readiness, vulnerability management, and compliance oversight within a SOC 2 Type II cloud-based software environment. The position combines hands-on technical expertise with regulatory and customer-facing compliance responsibilities to help ensure a secure and compliant operating environment.

Primary Responsibilities

  • Oversee day-to-day cybersecurity operations in collaboration with managed security providers and technology partners.
  • Direct vulnerability assessment activities and coordinate remediation efforts across systems and applications.
  • Participate in the detection, analysis, containment, and resolution of security incidents.
  • Manage and maintain security technologies such as SIEM platforms, endpoint protection solutions, email security systems, vulnerability management tools, and identity security controls.
  • Contribute to the creation, review, and ongoing enhancement of security policies, practices, and governance documentation.
  • Facilitate internal and external audit engagements, including preparation and collection of supporting evidence.
  • Perform security risk evaluations and technical control assessments.
  • Assist with customer due diligence reviews and responses to security-related inquiries.
  • Ensure adherence to established security requirements, regulatory obligations, and compliance standards.
  • Work closely with infrastructure and software development teams to strengthen the organization's overall security posture.
  • Review proposed system and process changes for security implications and compliance alignment.
  • Monitor corrective action plans and drive continuous improvement initiatives across the security program.

Required Experience & Qualifications

  • Minimum of seven years of professional experience in cybersecurity or information security.
  • Hands-on background in security engineering, security operations, or related disciplines.
  • Experience supporting compliance programs such as SOC 2, ISO 27001, or comparable frameworks.
  • Strong understanding of vulnerability identification, prioritization, and remediation processes.
  • Experience working with security monitoring platforms, endpoint detection technologies, and threat management tools.
  • Knowledge of identity and access management principles and best practices.
  • Experience contributing to incident response and cybersecurity investigations.
  • Excellent communication, documentation, and stakeholder engagement skills.

Preferred Experience & Credentials

  • Industry certifications such as CISSP, GSEC, Security+, or equivalent credentials.
  • Previous experience supporting software-as-a-service (SaaS) organizations.
  • Familiarity with cloud security architecture and related security technologies.
  • Experience leading or supporting customer security reviews and assessments.
  • Background conducting risk assessments, control evaluations, and compliance reviews.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

Advanced Operations Partners • United States

On-site
USD 140,000 - 190,000
Sr. Application Engineer, Cyber Security
Sr. Application Engineer, Cyber Security

inmar • Winston-Salem (NC)

On-site
USD 120,000 - 180,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Cyber Security Specialist
Cyber Security Specialist

X-Bow Systems Inc. • Luling (TX)

On-site
USD 70,000 - 110,000
Senior Information Security Analyst -CISSP
Senior Information Security Analyst -CISSP

ARK Strategies • Rancho Cordova (CA)

On-site
USD 120,000 - 150,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Madison-Davis, LLC • Boston (MA)

On-site
USD 90,000 - 120,000
Senior Security Engineer
Senior Security Engineer

Fusion Energy Base • San Leandro (CA)

On-site
USD 140,000 - 170,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000