Senior Information Security Engineer

Five9

United States

On-site

USD 140,000 - 210,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Shares
Bonus Scheme
Flex Benefit
Meal Allowance
Medical Insurance
Life Insurance
25 days annual leave + public holidays

Job summary

United States Digital Space LLC is seeking a Senior Information Security Engineer to join our Security Risk Management team, shaping an engineering-driven program for risk identification, assessment, and remediation across cloud and on-prem environments. You will collaborate with engineering, operations, and leadership to surface risks and sustain leadership visibility into our risk posture.

The role emphasizes partnership with compliance and vulnerability teams, building metrics, dashboards,

Qualifications

  • 3+ years of experience in information security, with at least 2 years focused on security risk management or GRC.
  • Experience maintaining a security risk register and driving risk treatment decisions with cross-functional stakeholders.
  • Strong understanding of risk assessment methodologies (qualitative and quantitative).
  • Familiarity with security frameworks such as NIST CSF, NIST 800-53, ISO 27001, PCI, or SOC 2.
  • Ability to communicate security risks clearly to both technical and non-technical audiences.
  • Experience with Jira or similar tools for tracking and managing risk workflows.
  • Self-directed and comfortable engaging directly with service owners, engineers, and leadership to resolve ambiguity around risk ownership.

Responsibilities

  • Identify, document, and assess security risks across the company's environment.
  • Maintain the Security Risk Register in Jira, ensuring risks are accurately categorized and tracked.
  • Engage with service owners, engineering leads, and operations teams to establish risk ownership.
  • Facilitate the risk acceptance process and coordinate approvals with stakeholders.
  • Develop and deliver risk reporting for security leadership and executives.
  • Collaborate with compliance, vulnerability management, and other Information Security functions to integrate findings into the program.
  • Research and apply risk management frameworks to improve program maturity.
  • Contribute to development of risk management policies, procedures, and playbooks.

Skills

Security Risk Management
GRC
Risk Assessment
Communication
Stakeholder Engagement
Self-directed
Risk Ownership

Tools

Jira
Cursor
Claude Code
Copilot

Job description

Join us in bringing joy to customer experience. the company is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide.

Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves.

We are looking for a Senior Information Security Engineer to join our growing Security Risk Management team. The Security Risk Management team aims to expand beyond traditional risk management; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect the company and our customers.

As a key contributor to the program the role supports the day-to-day execution of risk identification, assessment, treatment, and reporting across the company's infrastructure, services, and acquisitions. You'll work directly with engineering, operations, and business stakeholders to surface security risks, drive them toward resolution, and maintain a clear picture of the company's risk posture for leadership.

Key Responsibilities
  • Identify, document, and assess security risks across the company's environment, including production infrastructure, cloud services, corporate systems, and acquired platforms
  • Maintain the Security Risk Register in Jira, ensuring risks are accurately categorized, assigned to appropriate owners, and tracked through their lifecycle
  • Engage with service owners, engineering leads, and operations teams to establish risk ownership and drive remediation or mitigation plans
  • Facilitate the risk acceptance process, including preparing risk acceptance documentation and coordinating approval with appropriate stakeholders
  • Develop and deliver risk reporting for security leadership and executive audiences, including dashboards and metrics that communicate risk posture clearly
  • Collaborate with compliance, vulnerability management, and other Information Security functions to ensure risk findings are incorporated into the broader security program
  • Research and apply risk management frameworks and methodologies to continuously improve program maturity
  • Contribute to the development of risk management policies, procedures, and playbooks
Requirements
  • 3+ years of experience in information security, with at least 2 years focused on security risk management or GRC
  • Demonstrated experience maintaining a security risk register and driving risk treatment decisions with cross-functional stakeholders
  • Strong understanding of risk assessment methodologies (qualitative and quantitative)
  • Familiarity with security frameworks such as NIST CSF, NIST 800-53, ISO 27001, PCI, or SOC 2
  • Ability to communicate security risks clearly to both technical and non-technical audiences
  • Experience with Jira or similar tools for tracking and managing risk workflows
  • Self-directed and comfortable engaging directly with service owners, engineers, and leadership to resolve ambiguity around risk ownership
Preferred Skills
  • Experience with cloud environments (GCP, AWS, or Azure), particularly assessing risks related to cloud architecture and services
  • Familiarity with vulnerability management programs and how they feed into risk management
  • Experience supporting compliance audits or regulatory assessments (ISO 27001, SOC 2, PCI DSS)
  • Experience building or contributing to security metrics, KPI dashboards, or executive reporting
  • Prior work in a SaaS or contact center / communications platform environment
  • Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python
  • Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.)
Workplace location

This role is fully remote for candidates who reside outside Porto, Maia, Matosinhos, Gondomar, Valongo e Vila Nova de Gaia. Candidates who reside within those municipalities would be required to work in-office 3 days a week.

Benefits
  • the company Shares
  • Bonus Scheme
  • 10% Flex Benefit
  • Meal Allowance
  • Medical Insurance
  • Life Insurance
  • 25 day Annual Leave + Public Holidays

the company embraces diversity and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better we are. the company is an equal opportunity employer.

the company is committed to providing reasonable accommodations for qualified individuals with disabilities throughout the application and interview process. If you need assistance or an accommodation due to a disability, please contact us at hr@unitedstatesdigital.space to request an accommodation. Requests will be handled confidentially and in accordance with applicable law.

View our privacy policy, including our privacy notice to California residents here: https://www.the company.com/pt-pt/legal.

Note: the company will never request that an applicant send money as a prerequisite for commencing employment with the company.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior DevOps Engineer
Senior DevOps Engineer

Five9 • United States

On-site
USD 130,000 - 195,000
Company shares
Bonus scheme
10% Flex Benefit
+4
Cloud Governance Engineer
Cloud Governance Engineer

Five9 • United States

On-site
USD 150,000 - 190,000
Equity Programs
Bonus Scheme
10% Flex Benefit
+4
Regional Sales Manager, Portugal (Remote)
Regional Sales Manager, Portugal (Remote)

CrowdStrike Inc. • United States

Hybrid
USD 134,000 - 269,000
Compensation & equity
Wellness programs
Vacation & holidays
+5
Software Engineer II (Portugal)
Software Engineer II (Portugal)

Iterable, Inc. • United States

Remote
USD 62,000 - 76,000
Private Medical Insurance
Life/Risk Assurance
Meal Allowance: € per day
+4
Office Manager (São Paulo, Brazil)
Office Manager (São Paulo, Brazil)

Figma • United States

On-site
USD 65,000 - 90,000
Senior Product Security Architect
Senior Product Security Architect

Axonius • United States

On-site
USD 180,000 - 240,000
DevSecOps Engineer
DevSecOps Engineer

WeHireYou • Lisbon (IN)

Hybrid
USD 62,000 - 69,000
Hybrid mode of work
Flexible schedule
Healthcare benefits
+12
Security Risk Management Specialist
Security Risk Management Specialist

Jobgether SRL • Spain (TX)

On-site
EUR 60,000 - 90,000
Remote-first
Learning budget
Travel opportunities
+5
Account Executive, Strategic (São Paulo, Brazil)
Account Executive, Strategic (São Paulo, Brazil)

Figma • United States

On-site
USD 120,000 - 190,000
Senior Security Engineer - freelance
Senior Security Engineer - freelance

Netcompany • United States

Hybrid
USD 140,000 - 190,000