Back to Jobs
Keyfactor
Development 8h ago

Information Security Engineer

Keyfactor
United StatesUnited States
Full-time
Not Disclosed
Mid-Level

Job Description

Key Skills Required

Master these to land this role

Python2h 41mFree Trial ✨
Start 10-Day Free Trial
DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
QA Engineer1h 50mFree Trial ✨
Start 10-Day Free Trial
Automation EngineerCybersecurity

Want to know if you're a match for this job?

Calculate My Match Score

We are seeking an experienced Information Security Engineer with a strong background in implementing and managing general information security frameworks, including ISO 27001:2022 and SOC 2 Type II. This role involves designing, maintaining, and improving our security infrastructure to ensure compliance with regulatory standards and support continuous monitoring efforts. The ideal candidate will play a key role in safeguarding the organization’s data and infrastructure while driving adherence to evolving security best practices.

Responsibilities

  • Evaluate the security posture of systems, platforms, and cloud environments, establish appropriate security baselines, and drive implementation and hardening to close identified gaps.
  • Quickly develop proficiency in new SIEM, EDR, and other security platforms as the environment evolves; configure, tune, and integrate these tools with SaaS applications and diverse data sources to expand visibility and detection coverage.
  • Evaluate and optimize security playbooks, runbooks, and processes based on lessons learned, tooling changes, and evolving threats, ensuring documentation and workflows keep pace with the organization's security operations maturity.
  • Experience conducting vulnerability assessments, system audits, and risk analysis using industry-standard scanning tools to support a proactive security posture.
  • Manage and implement continuous monitoring processes to ensure the organization maintains compliance with a variety of information security frameworks, including ISO 27001:2022 and SOC 2 Type II. Experience with government compliance standards such as FedRAMP (NIST SP 800-53) and CMMC is preferred. This role focuses on ensuring robust security practices and adapting to evolving compliance requirements.
  • Actively monitor, analyze, and respond to security alerts and incidents, performing investigations, incident handling, and recommending corrective actions.

Minimum Qualifications, Education, and Skills

  • 5+ years of experience in information security or a similar role
  • Proficiency in vulnerability scanning tools (Nessus, Burpsuite, Tenable, etc…) and interpreting scan results for remediation.
  • Strong knowledge of security standards
  • Demonstrated experience in continuous monitoring, network security, firewalls, VPNs, IDS/IPS, and endpoint protection.
  • Strong analytical skills and a meticulous approach to problem-solving
  • Demonstrated capability to deliver results on-time and to a defined schedule.
  • Relevant certifications (e.g., CISSP, CompTIA Security+, CAP) are strongly preferred
  • Familiarity with cloud security principles
  • Experience with security automation and continuous monitoring tools
  • PKI knowledge a plus
  • Knowledge of scripting languages (Python, PowerShell) to automate security processes
  • Experience with government-regulated environments (AWS GovCloud, Azure Government) preferred

How would you rate this job post?

See what other professionals think about this role.

banner

Keyfactor (operating via keyfactor.com) is a premier cybersecurity and digital trust enterprise engineered to manage and protect machine identities at massive scale. Founded in 2001 and headquartered in Independence, Ohio, the company fundamentally transforms how organizations secure critical infrastructure and prepare for the post-quantum computing era. Moving far beyond traditional, manual certificate management, Keyfactor natively unifies continuous cryptographic discovery, automated certificate lifecycle management (CLM), and Public Key Infrastructure (PKI) as a Service into a single, cohesive ecosystem via its Trust Control Plane. The platform empowers global enterprises to prevent costly outages, enable robust Zero Trust architectures, and seamlessly manage billions of keys and certificates across hybrid, cloud, and IoT environments. Under the hood, their highly scalable architecture leverages advanced cryptography and deep integrations with modern DevOps tools to ensure true crypto-agility. Constantly recognized as an Inc. Best Place to Work and trusted by Fortune 500 leaders globally, Keyfactor remains a definitive cornerstone of the modern digital landscape, securing the invisible connections that power humans, machines, and AI.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More