Senior Security Engineer - Threat & Compliance Leader
Listed on 2026-06-21
-
IT/Tech
Cybersecurity, Information Security, IT Consultant, Network Security
Trofi Security is a nationally recognized firm of cyber security thought leaders and technical advisors at the leading edge of IT security consulting. This entrepreneurial culture is built on innovation and service excellence, and thrives in the fast‑growing IT sector.
Senior Security EngineerTrofi Security is looking for an expert Security Engineer to join our consulting team to ensure that our client’s applications and infrastructure are designed and implemented to the highest standards, thereby maintaining and enhancing customer trust.
Key responsibilities include:
- Identify security issues and risks, and develop mitigation plans
- Architect, design, implement, support, and evaluate security-focused tools and services, including project leadership roles
- Develop and interpret security policies and procedures
- Mentor junior team members
- Participate in security compliance efforts (e.g., PCI DSS, SOX)
- Develop and deliver training materials and perform general security awareness and specific security technology training
- Conduct acquisition and vendor risk assessment due diligence
- Evaluate and recommend new and emerging security products and technologies
- Participate in tier 2 and tier 3 security operations support
- Participate in incident handling
- Advocate for security within the company and promote customer trust
Basic qualifications:
- BS/MS in Computer Science or equivalent desired
- Emerging company-wide reputation in the field of information security
- Consistent implementation of security solutions at the business unit level
- At least 3 years experience in infrastructure or application-level vulnerability testing and auditing
- At least 3 years of system, network, and/or application security experience
- Strong experience and detailed technical knowledge in security engineering, system and network security, authentication and security protocols, cryptography, and application security
- Knowledge of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols)
Preferred qualifications:
- Experience with service‑oriented architecture and web services security
- Experience with threat modeling or other risk identification techniques
- Detailed knowledge of system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits
- Scripting skills (e.g., PERL, shell scripting)
- Excellent written and verbal communication skills
- Excellent leadership and teamwork skills
- Results-oriented, high energy, self‑motivated
You provide expertise to client organizations in the areas of Information Security Strategy and Regulatory Compliance, conduct information security assessments, and provide guidance on industry‑best practices for implementing formal information security governance programs.
Required skills:
- Experience in an IT security audit and compliance role, with working knowledge of PCI, GLBA, FISMA, ISO 27000, HIPAA, and NIST.
- Strong IT background/understanding with respect to networks, servers, workstations, and applications
- Excellent written, oral communication, and presentation skills
- Self‑motivated and able to work independently or with a team
- Willingness to travel up to 50% of the time
Preferred skills:
- Risk assessment execution and reporting
- Ability to comfortably interact with senior management in a consultative manner
- Gap analysis execution and reporting
- Virtualization and cloud technology knowledge
Education/Certifications/
Experience:
- Minimum of 5 years in Information Technology or Security
- Minimum of 5 years in an IT security audit and/or compliance role
- Minimum of 1 information security certification such as CISSP, CISA, or CISM; QSA a plus
You think out of the box and enjoy the challenge of compromising systems. Black box, grey box, or white box testing is acceptable.
Required skills:
- 5+ years of experience in information security with application/network penetration testing experience
- Deep understanding of web frameworks, including XML, SOAP, JSON, and Ajax
- Experience with scripting languages such as bash, PERL, Python, Ruby, VB/WScript, or Power Shell
- Experience exploiting web applications and services
- Working knowledge of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).