High Street Partners Logo

High Street Partners

Information Security Engineer

Posted Yesterday
Remote
Hiring Remotely in United States
Mid level
Remote
Hiring Remotely in United States
Mid level
Hands-on Information Security Engineer responsible for SOC 2 Type 2 compliance, vulnerability management, Azure and endpoint security, security tooling, governance, customer security questionnaires, vendor risk, secure SDLC practices, incident response, and security awareness. The role partners across Engineering, IT, Legal, and Product to improve the company’s SaaS security posture.
The summary above was generated by AI
About Us

HSP Group is the premier provider of global expansion services, helping companies simplify the complex challenges of operating internationally. We deliver a seamless experience across legal entity setup, global HR, payroll, compliance, tax, and advisory, enabling our clients to scale faster, stay compliant, and reduce risk in every market they enter. 

With scale-up organizations and innovative technology firms expanding at unprecedented speed, HSP is uniquely positioned to become their trusted global partner. 

Job Description

This is a remote role.

We are seeking a hands-on, mid-level Information Security Engineer to help protect our SaaS products, harden our cloud and endpoint environments, and mature our overall security program. This role sits at the intersection of technical security operations and governance. You will manage vulnerabilities across our products and infrastructure, contribute to corporate security policies, lead SOC 2 efforts, and serve as a key voice in customer and vendor security conversations.

Our entire technology stack runs in Microsoft Azure, and we leverage the broader Microsoft security ecosystem (Intune, Defender, Purview) alongside best-in-class tooling like Datadog, GitHub, and Snyk. You will work closely with Engineering, IT, Legal, and Product teams to drive measurable improvements to our security posture.

Responsibilities: Vulnerability & Product Security
  • Lead the company’s SOC 2 compliance program, including readiness, control implementation, evidence collection, ongoing monitoring, remediation, and coordination with auditors through successful completion of the audit.
  • Lead the vulnerability management program across our SaaS products, cloud infrastructure, containers, and endpoints including identification, triage, prioritization, remediation tracking, and reporting.
  • Operate and tune SAST, SCA, and dependency-scanning tooling (e.g., Snyk, GitHub Advanced Security/Dependabot) and partner with engineering teams to drive timely remediation.
  • Monitor runtime and infrastructure telemetry (e.g., Datadog) for security signals; investigate alerts and lead containment and follow-up actions.
  • Track and report on vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership.
Cloud & Endpoint Security
  • Enhance the security posture of our Microsoft Azure environment including identity, networking, data, and workloads through configuration hardening, policy enforcement, and continuous monitoring.
  • Administer and improve Microsoft Intune for endpoint configuration, compliance, and mobile device management.
  • Tune and maintain Microsoft Defender (Endpoint, Cloud, and related products) for threat detection, response, and reporting.
Governance, Risk & Compliance
  • Draft, update, and maintain corporate information security policies, standards, and procedures aligned to recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF).
  • Lead the response to customer and prospect security questionnaires, RFPs, and due-diligence requests, and maintain a reusable response library.
  • Support vendor risk assessments and third-party security reviews.
  • Assist with internal and external audits, evidence collection, and remediation of findings.
Security Program & Collaboration
  • Partner with Engineering on secure SDLC practices, threat modeling, and code review guidance.
  • Contribute to security awareness training, phishing simulations, and a strong security culture across the company.
  • Help mature incident response playbooks and participate in tabletop exercises and on-call rotations as needed.
Requirements: 
  • 4–6 years of professional experience in information security, application security, cloud security, or a closely related role.
  • Experience in preparing for SOC 2 Type 2 attestations for SaaS products.
  • Hands-on experience securing SaaS applications and workloads running in Microsoft Azure.
  • Demonstrated experience with vulnerability management tooling and process including triage, prioritization (e.g., CVSS, EPSS, exploitability context), and driving remediation through engineering teams.
  • Working proficiency with several of the following: Microsoft Intune, Microsoft Defender (Endpoint/Cloud), Microsoft Purview, Datadog, GitHub (Advanced Security, Dependabot, code scanning), and Snyk.
  • Solid understanding of identity and access management concepts, particularly Microsoft Entra ID (Azure AD), conditional access, and least-privilege design.
  • Experience writing or substantially contributing to security policies, standards, or procedures.
  • Experience in responding to customer security questionnaires and supporting compliance efforts.
  • Strong written and verbal communication skills and able to translate technical risk for both engineers and non-technical stakeholders.
Nice to Have: 
  • Industry certifications such as CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent.
  • Experience with container and Kubernetes security.
  • Exposure to threat modeling, secure code review, or penetration testing.
  • Prior experience in a SaaS company or regulated industry.

If you’re a driven individual who wants to make your mark in the heart of the innovation economy, we’d love to meet you. Join our #HSPGlobalSolutionTeam and help us power the next wave of global growth.

Similar Jobs

8 Days Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
134K-168K Annually
Senior level
134K-168K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Protect corporate data through DLP implementation, tuning, alert review, false-positive reduction, and control optimization across web, endpoint, email, cloud, and SaaS environments. The engineer will review data protection programs, improve monitoring and blocking controls, collaborate with business partners, and use automation and emerging AI tools to strengthen security operations.
Top Skills: Ai ToolsCloud Data StoresData Loss Prevention (Dlp)SaaSZscaler DspmZscaler Zero Trust ExchangeZscaler Zia
11 Days Ago
In-Office or Remote
Mid level
Mid level
Artificial Intelligence • Fintech • Software • Financial Services
Own vulnerability management across endpoints, servers, and cloud infrastructure; prioritize remediation and track SLA performance. Harden AWS environments, improve identity management, investigate cloud alerts, and support application security through SAST, DAST, dependency scanning, secure code reviews, and threat modeling. Resolve security tickets, document incidents and remediation, and lead security initiatives while collaborating with engineering, IT, and compliance.
Top Skills: AWSAws ConfigBashCloudtrailDastGuarddutyIamJIRALinearOwasp Top 10PythonQualysS3SastScaSecurity HubSnykSoc 2TenableVpcWiz
Yesterday
Remote
USA
80K-105K Annually
Junior
80K-105K Annually
Junior
Agency • Automotive • Marketing Tech
Performs vulnerability management, WordPress and dependency security, Linux hardening, security-focused code reviews, incident response support, SOC 2 evidence collection, and platform engineering. Maintains PHP and JavaScript applications, Ubuntu/Debian servers, nginx, DNS, certificates, MySQL, deployments, and automation scripts. The role requires hands-on WordPress and PHP expertise, web security fundamentals, Linux command-line skills, scripting, and U.S. work authorization without sponsorship.
Top Skills: APIsAWSBashDebianDnsGCPGithub ActionsHTTPJavaScriptLinuxMySQLNessusNginxOpenvasPHPPythonTlsTrivyTypescriptUbuntuWordpressWpscan

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account