3Pillarglobal
Senior Information Security Engineer
productfull-timeRomania
SALARY
Not listed
WORK TYPE
remote
JOB TYPE
full-time
INDUSTRY
general
✦ AutoApply Let us apply to roles like this on your behalf.
Learn more
About the role
Key Responsibilities
Vulnerability & Product Security
- Own the end-to-end vulnerability management program across our SaaS products, cloud infrastructure, containers, and endpoints including identification, triage, prioritization, remediation tracking, and reporting.
- Operate and tune SAST, SCA, and dependency-scanning tooling (e.g., Snyk, GitHub Advanced Security/Dependabot) and partner with engineering teams to drive timely remediation.
- Monitor runtime and infrastructure telemetry (e.g., Datadog) for security signals; investigate alerts and lead containment and follow-up actions.
- Track and report on vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership.
Cloud & Endpoint Security
- Enhance the security posture of our Microsoft Azure environment including identity, networking, data, and workloads through configuration hardening, policy enforcement, and continuous monitoring.
- Administer and improve Microsoft Intune for endpoint configuration, compliance, and mobile device management.
- Tune and maintain Microsoft Defender (Endpoint, Cloud, and related products) for threat detection, response, and reporting.
- Implement and operate Microsoft Purview controls for data classification, DLP, and information protection.
Governance, Risk & Compliance
- Draft, update, and maintain corporate information security policies, standards, and procedures aligned to recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF).
- Lead the response to customer and prospect security questionnaires, RFPs, and due-diligence requests, and maintain a reusable response library.
- Support vendor risk assessments and third-party security reviews.
- Assist with internal and external audits, evidence collection, and remediation of findings.
Security Program & Collaboration
- Partner with Engineering on secure SDLC practices, threat modeling, and code review guidance.
- Contribute to security awareness training, phishing simulations, and a strong security culture across the company.
- Help mature incident response playbooks and participate in tabletop exercises and on-call rotations as needed.
Minimum Qualifications
- 4–6 years of professional experience in information security, application security, cloud security, or a closely related role.
- Hands-on experience securing SaaS applications and workloads running in Microsoft Azure.
- Demonstrated experience with vulnerability management tooling and process including triage, prioritization (e.g., CVSS, EPSS, exploitability context), and driving remediation through engineering teams.
- Working proficiency with several of the following: Microsoft Intune, Microsoft Defender (Endpoint/Cloud), Microsoft Purview, Datadog, GitHub (Advanced Security, Dependabot, code scanning), a
✦ Let us apply for you
We find roles like this and apply on your behalf. Cover letter written for each one. Plans from $15/mo. Cancel anytime.
Get AutoApply