×
Register Here to Apply for Jobs or Post Jobs. X

Information Security Engineer - Remote

Remote / Online - Candidates ideally in
Ashland, Boyd County, Kentucky, 41101, USA
Listing for: HSP Group
Remote/Work from Home position
Listed on 2026-09-11
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 110000 - 140000 USD Yearly USD 110000.00 140000.00 YEAR
Job Description & How to Apply Below
Position: Information Security Engineer New United States - Remote

HSP Group is the premier provider of global expansion services, helping companies simplify the complex challenges ofoperatinginternationally. We deliver a seamless experience across
legal entity setup, global HR, payroll, compliance, tax, and advisory
, enabling our clients to scale faster, stay compliant, and reduce risk in every market they enter.

With scale-up organizations and innovative technology firms expanding at unprecedented speed, HSP is uniquely positioned to become their trusted global partner.

Job Description

This is a remote role.

We are seeking a hands-on, mid-level Information Security Engineer to help protect our SaaS products, harden our cloud and endpoint environments, and mature our overall security program. This role sits at the intersection of technical security operations and governance. You will manage vulnerabilities across our products and infrastructure, contribute to corporate security policies, lead SOC 2 efforts, and serve as a key voice in customer and vendor security conversations.

Our entire technology stack runs in Microsoft Azure, and we leverage the broader Microsoft security ecosystem (Intune, Defender, Purview) alongside best-in-class tooling like Datadog, Git Hub, and Snyk. You will work closely with Engineering, IT, Legal, and Product teams to drive measurable improvements to our security posture.

Responsibilities:
Vulnerability & Product Security
  • Lead the company’s SOC 2 compliance program, including readiness, control implementation, evidence collection, ongoing monitoring, remediation, and coordination with auditors through successful completion of the audit.
  • Lead the vulnerability management program across our SaaS products, cloud infrastructure, containers, and endpoints including identification, triage, prioritization, remediation tracking, and reporting.
  • Operate and tune SAST, SCA, and dependency-scanning tooling (e.g., Snyk, Git Hub Advanced Security/Dependabot) and partner with engineering teams to drive timely remediation.
  • Monitor runtime and infrastructure telemetry (e.g., Datadog) for security signals; investigate alerts and lead containment and follow-up actions.
  • Track and report on vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership.
  • Enhance the security posture of our Microsoft Azure environment including identity, networking, data, and workloads through configuration hardening, policy enforcement, and continuous monitoring.
  • Administer and improve Microsoft Intune for endpoint configuration, compliance, and mobile device management.
  • Tune and maintain Microsoft Defender (Endpoint, Cloud, and related products) for threat detection, response, and reporting.
  • Draft, update, and maintain corporate information security policies, standards, and procedures aligned to recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF).
  • Lead the response to customer and prospect security questionnaires, RFPs, and due-diligence requests, and maintain a reusable response library.
  • Support vendor risk assessments and third-party security reviews.
  • Assist with internal and external audits, evidence collection, and remediation of findings.
Security Program & Collaboration
  • Partner with Engineering on secure SDLC practices, threat modeling, and code review guidance.
  • Contribute to security awareness training, phishing simulations, and a strong security culture across the company.
  • Help mature incident response playbooks and participate in tabletop exercises and on-call rotations as needed.
Requirements:
  • 4–6 years of professional experience in information security, application security, cloud security, or a closely related role.
  • Experience in preparing for SOC 2 Type 2 attestations for SaaS products.
  • Hands-on experience securing SaaS applications and workloads running in Microsoft Azure.
  • Demonstrated experience with vulnerability management tooling and process including triage, prioritization (e.g., CVSS, EPSS, exploitability context), and driving remediation through engineering teams.
  • Working proficiency with several of the following:
    Microsoft Intune, Microsoft Defender (Endpoint/Cloud), Microsoft Purview, Datadog, Git Hub (Advanced Security, Dependabot, code scanning), and Snyk.
  • Solid understanding of identity and access management concepts, particularly Microsoft Entra  (Azure AD), conditional access, and least-privilege design.
  • Experience writing or substantially contributing to security policies, standards, or procedures.
  • Experience in responding to customer security questionnaires and…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary