Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Information Security Engineer image - Rise Careers
Job details

Information Security Engineer

Keyfactor is seeking an experienced Information Security Engineer to help maintain and improve their security infrastructure, ensuring compliance with regulatory standards.

Skills

  • Vulnerability scanning tools experience
  • Knowledge of security standards
  • Network security expertise
  • Analytical problem-solving skills
  • Cloud security principles familiarity

Responsibilities

  • Conduct vulnerability assessments and system audits using scanning tools.
  • Manage continuous monitoring processes for compliance with security frameworks.
  • Collaborate with IT and Engineering teams to enforce security policies.
  • Monitor, analyze, and respond to security incidents.
  • Assist in developing and managing security documentation.

Education

  • Bachelor's degree in Information Security or related field
  • Relevant certifications preferred

Benefits

  • Comprehensive benefit coverage
  • Generous paid parental leave
  • Unlimited time off
  • Wellbeing resources and wellness allowance
To read the complete job description, please click on the ‘Apply’ button

Average salary estimate

$100000 / YEARLY (est.)
min
max
$80000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Information Security Engineer, Keyfactor, Inc.

Join Keyfactor as an Information Security Engineer and become an integral part of a team dedicated to building a connected society rooted in trust. Here at Keyfactor, we are driven by the mission of establishing identity-first security across machines and humans alike. If you have a robust background in implementing security frameworks like ISO 27001:2022 and SOC 2 Type II, and you're passionate about ensuring compliance with regulations such as FedRAMP and CMMC, this role is tailored for you! In this position, you will take the lead in designing, maintaining, and enhancing security infrastructures, while implementing continuous monitoring to safeguard our data and infrastructure. You will work closely with cross-functional teams, including IT, DevOps, and Engineering, promoting security best practices and responding to security alerts and incidents. If you possess strong analytical skills and experience with vulnerability assessments using tools such as Nessus and Burpsuite, we encourage you to trust your future with us at Keyfactor. As part of our company culture, enjoy the autonomy to excel, make an impact, and take advantage of our generous benefits, including unlimited time off and a commitment to diversity and inclusion. We are excited to see how you will contribute to our mission!

Frequently Asked Questions (FAQs) for Information Security Engineer Role at Keyfactor, Inc.
What are the key responsibilities of an Information Security Engineer at Keyfactor?

As an Information Security Engineer at Keyfactor, you will be responsible for implementing and managing security frameworks like ISO 27001:2022 and SOC 2 Type II, conducting vulnerability assessments, and managing continuous monitoring processes. Your role will also involve collaborating with IT and DevOps teams to enforce security policies and providing expert guidance on security matters.

Join Rise to see the full answer
What qualifications are required for the Information Security Engineer role at Keyfactor?

Keyfactor requires candidates for the Information Security Engineer position to have a minimum of 5 years’ experience in information security, proficiency with vulnerability scanning tools like Nessus and Burpsuite, and a strong knowledge of security standards. Relevant certifications such as CISSP or CompTIA Security+ are preferred.

Join Rise to see the full answer
Is remote work an option for the Information Security Engineer position at Keyfactor?

Yes, the Information Security Engineer role at Keyfactor can be performed remotely within the United States, allowing you to work from the comfort of your home while contributing to our mission of ensuring digital trust.

Join Rise to see the full answer
What tools and technologies will I work with as an Information Security Engineer at Keyfactor?

In your role at Keyfactor, you will work with a variety of security tools including vulnerability scanning tools like Nessus, Azure security tools, and Tenable. Experience with security automation and continuous monitoring tools will also be valuable.

Join Rise to see the full answer
What makes Keyfactor a great place to work for Information Security Engineers?

Keyfactor is recognized as a Best Place to Work, fostering a culture of trust, innovation, and teamwork. We offer comprehensive benefits, opportunities for professional growth, and a commitment to diversity and inclusion. Plus, enjoy perks like Second Fridays off, unlimited time off, and wellbeing resources.

Join Rise to see the full answer
Common Interview Questions for Information Security Engineer
Can you explain your experience with ISO 27001 and SOC 2 compliance?

When answering this question, highlight specific projects where you've implemented or maintained ISO 27001 or SOC 2 standards. Discuss the frameworks' requirements, your approach to audits, and any improvements you've made in these areas.

Join Rise to see the full answer
How do you conduct a vulnerability assessment?

In your response, explain the step-by-step process you follow for conducting vulnerability assessments. Mention the tools you use, how you prioritize findings, and your approach to remediating identified vulnerabilities.

Join Rise to see the full answer
Describe your experience with incident response and what steps you take during a security incident.

Detail your experience in responding to security incidents by outlining the processes you follow, such as detection, containment, eradication, and recovery, while emphasizing the importance of documentation and learning from each incident.

Join Rise to see the full answer
What security tools are you proficient in?

Enumerate the security tools you're familiar with, like Nessus, Burpsuite, and others, and provide examples of how you've utilized them in past roles. Highlight any specific contributions these tools allowed you to make to enhance security.

Join Rise to see the full answer
How do you stay updated on the latest security trends and threats?

Discuss the methods you use to stay informed, such as following industry blogs, attending webinars and conferences, participating in security forums, or taking relevant courses. Show your commitment to professional development.

Join Rise to see the full answer
Can you describe a challenge you faced in previous security roles and how you overcame it?

Share a specific situation that posed a challenge, your thought process in addressing it, and the successful outcome. This will showcase your problem-solving skills and resilience in difficult situations.

Join Rise to see the full answer
What approach do you take to collaborate with IT and DevOps teams on security initiatives?

Explain your philosophy on cross-team collaboration, possibly detailing how communication and shared goals contribute to effective security practices. Offer examples of past experiences where teamwork led to successful security implementations.

Join Rise to see the full answer
How do you manage and prioritize multiple security tasks and projects?

Describe your method for prioritization, whether through risk assessments, the impact of tasks on business objectives, or using project management tools. Illustrate with examples where you successfully managed competing priorities.

Join Rise to see the full answer
What role do you believe employee training plays in an organization's security posture?

Discuss the critical importance of employee training in reducing security risks, how you would develop a training program, and any past experiences where your initiatives positively impacted security awareness in an organization.

Join Rise to see the full answer
How would you approach regulatory compliance in a constantly evolving landscape?

Emphasize the need for continuous improvement and staying informed about regulatory changes. Explain strategies like developing adaptable policies, monitoring compliance, and regularly assessing security measures to meet evolving standards.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Keyfactor, Inc. Remote Remote, United States; Remote, United Kingdom
Posted 13 days ago
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Posted 5 days ago
Photo of the Rise User
Posted 6 hours ago
Photo of the Rise User
Posted 20 hours ago
Photo of the Rise User
Posted 8 days ago

Keyfactor empowers enterprises of all sizes to close their critical trust gap - when breaches, outages and failed audits from digital certificates and keys impact brand loyalty and the bottom line. Powered by an award-winning PKI as-a-service plat...

21 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
SALARY RANGE
$80,000/yr - $120,000/yr
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 10, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!