Senior Information Security Engineer

Grayson Search Partners

Nashville (TN)

On-site

USD 120,000 - 150,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Grayson Search Partners is seeking a Senior Information Security & Compliance Engineer in Nashville to lead security controls, compliance efforts, and risk management across our cloud-based environment.

You will collaborate with MSPs and engineering teams to strengthen security posture, drive audit readiness, and ensure regulatory obligations are met. This role blends hands-on security work with customer-facing compliance activities in a SaaS setting.

Qualifications

  • Minimum of seven years of professional experience in cybersecurity or information security.
  • Hands-on background in security engineering or security operations.
  • Experience supporting SOC 2, ISO 27001, or comparable frameworks.
  • Strong vulnerability identification, prioritization, and remediation.
  • Experience with security monitoring platforms, endpoint protection, and threat management tools.
  • Knowledge of identity and access management principles and best practices.
  • Experience contributing to incident response and cybersecurity investigations.
  • Excellent communication, documentation, and stakeholder engagement skills.

Responsibilities

  • Oversee day-to-day cybersecurity operations in collaboration with managed security providers and technology partners.
  • Direct vulnerability assessment activities and coordinate remediation efforts across systems and applications.
  • Participate in the detection, analysis, containment, and resolution of security incidents.
  • Manage and maintain security technologies such as SIEM platforms, endpoint protection solutions, email security systems, vulnerability management tools, and identity security controls.
  • Contribute to the creation, review, and ongoing enhancement of security policies, practices, and governance documentation.
  • Facilitate internal and external audit engagements, including preparation and collection of supporting evidence.
  • Perform security risk evaluations and technical control assessments.
  • Assist with customer due diligence reviews and responses to security-related inquiries.
  • Ensure adherence to established security requirements, regulatory obligations, and compliance standards.
  • Work closely with infrastructure and software development teams to strengthen the organization's overall security posture.
  • Review proposed system and process changes for security implications and compliance alignment.
  • Monitor corrective action plans and drive continuous improvement initiatives across the security program.

Skills

Cybersecurity
Security operations
Vulnerability management
Incident response
Audit readiness
Regulatory compliance
Communication

Tools

SIEM
Endpoint protection
Threat management tools
Identity security controls

Job description

Senior Information Security & Compliance Engineer

Position Overview

The Senior Information Security & Compliance Engineer reports to the Senior Infrastructure Manager and plays a critical role in safeguarding the organization's systems, data, and regulatory posture. This individual is responsible for developing, administering, and enhancing security controls, compliance initiatives, and risk management practices across the enterprise.

Serving as a key security subject matter expert, the role focuses on operational cybersecurity, governance, audit readiness, vulnerability management, and compliance oversight within a SOC 2 Type II cloud-based software environment. The position combines hands-on technical expertise with regulatory and customer-facing compliance responsibilities to help ensure a secure and compliant operating environment.

Primary Responsibilities

  • Oversee day-to-day cybersecurity operations in collaboration with managed security providers and technology partners.
  • Direct vulnerability assessment activities and coordinate remediation efforts across systems and applications.
  • Participate in the detection, analysis, containment, and resolution of security incidents.
  • Manage and maintain security technologies such as SIEM platforms, endpoint protection solutions, email security systems, vulnerability management tools, and identity security controls.
  • Contribute to the creation, review, and ongoing enhancement of security policies, practices, and governance documentation.
  • Facilitate internal and external audit engagements, including preparation and collection of supporting evidence.
  • Perform security risk evaluations and technical control assessments.
  • Assist with customer due diligence reviews and responses to security-related inquiries.
  • Ensure adherence to established security requirements, regulatory obligations, and compliance standards.
  • Work closely with infrastructure and software development teams to strengthen the organization's overall security posture.
  • Review proposed system and process changes for security implications and compliance alignment.
  • Monitor corrective action plans and drive continuous improvement initiatives across the security program.

Required Experience & Qualifications

  • Minimum of seven years of professional experience in cybersecurity or information security.
  • Hands-on background in security engineering, security operations, or related disciplines.
  • Experience supporting compliance programs such as SOC 2, ISO 27001, or comparable frameworks.
  • Strong understanding of vulnerability identification, prioritization, and remediation processes.
  • Experience working with security monitoring platforms, endpoint detection technologies, and threat management tools.
  • Knowledge of identity and access management principles and best practices.
  • Experience contributing to incident response and cybersecurity investigations.
  • Excellent communication, documentation, and stakeholder engagement skills.

Preferred Experience & Credentials

  • Industry certifications such as CISSP, GSEC, Security+, or equivalent credentials.
  • Previous experience supporting software-as-a-service (SaaS) organizations.
  • Familiarity with cloud security architecture and related security technologies.
  • Experience leading or supporting customer security reviews and assessments.
  • Background conducting risk assessments, control evaluations, and compliance reviews.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

Advanced Operations Partners • United States

On-site
USD 140,000 - 190,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Senior Manager of Information Security
Senior Manager of Information Security

Plume • United States

On-site
USD 180,000 - 240,000
Senior Director, Cybersecurity Operations & Compliance
Senior Director, Cybersecurity Operations & Compliance

Ddn • Santa Clara (CA)

On-site
USD 150,000 - 210,000
Cyber Security Specialist
Cyber Security Specialist

X-Bow Systems Inc. • Luling (TX)

On-site
USD 70,000 - 110,000
Information Systems Security Professional
Information Systems Security Professional

Vytwo • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

On-site
USD 80,000 - 110,000
Senior Information Security Engineer
Senior Information Security Engineer

Coforge • Chicago (IL)

On-site
USD 120,000 - 180,000
Health insurance
Paid time off
SECURITY COMPLIANCE ENGINEER
SECURITY COMPLIANCE ENGINEER

Target Labs, Inc • Scottsdale (AZ)

On-site
USD 80,000 - 120,000
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000