More jobs:
Job Description & How to Apply Below
E INC is the parent company of EBlock and EDealer, unifying our approach to products, services, and strategies under one Vision and one Mission: to create the best digital auction and retailing platform in the world by connecting the automotive wholesale and retail experiences. Our brands and their technologies make it easy for a vehicle to move between buyers and sellers throughout its entire ownership lifecycle.
Learn more at (Use the "Apply for this Job" box below)./about
We are seeking an experienced, detail-oriented Cybersecurity Engineer to strengthen our organization’s information security posture across endpoints, networks, cloud services, and applications.
Responsibilities- Own threat and vulnerability management, driving remediation of misconfigurations and weaknesses across our environment.
- Manage and tune security monitoring and incident response capabilities using SIEM and observability tools (e.g., Datadog and log pipelines).
- Administer our endpoint, web, and Zero Trust security stack, including Sentinel One for EDR/CNAPP, Zscaler for secure access and DLP, and Cloudflare for WAF, DNS, and Zero Trust web security.
- Support compliance and governance efforts (focus on SOC’2, ISO’27001, NIST).
- Work closely with development and cloud teams to secure workloads in AWS and fix vulnerable packages and dependencies in existing applications.
- Collaborate with IT, infrastructure, and application teams to design, implement, and continuously improve security controls that are practical, measurable, and audit‑ready.
- Threat & Vulnerability Management
- Identify, assess, and prioritize vulnerabilities and misconfigurations across endpoints, networks, cloud environments, and applications.
- Work with infrastructure and application owners to define and maintain secure configuration baselines and ensure timely remediation.
- Use vulnerability management and configuration assessment tools (including Sentinel One, cloud‑native security services, and code‑repo/package alerts) to track progress and risk reduction over time.
- Partner with development teams to review and remediate vulnerable third‑party packages and libraries in existing applications.
- Security Monitoring & Incident Response
- Configure, manage, and tune SIEM / security monitoring solutions (Datadog, cloud logs, other telemetry) for high‑quality, actionable alerts.
- Act as an escalation point for high‑severity security incidents, including triage, containment, investigation, and recovery.
- Maintain and improve Incident Response runbooks and procedures (phishing, malware, account compromise, data exfiltration).
- Participate in and design Disaster Recovery (DR) and Business Continuity Planning (BCP) tabletop exercises, incorporating security scenarios.
- Endpoint, Network & Cloud Security
- Administer and optimize Sentinel One for endpoint detection and response.
- Configure and manage Zscaler (Internet, Private Access, DLP) for secure internet and application access.
- Oversee Cloudflare security configurations for web applications and network services (Zero Trust, WAF, DNS).
- Secure AWS workloads (IAM, security groups, network segmentation, logging, encryption) and integrate security controls into existing services.
- Collaborate with network/infrastructure teams to apply Zero Trust and defense‑in‑depth principles across offices, remote users, and auction environments.
- Application & Change Security
- Collaborate with developers and product teams to remediate security findings in existing services.
- Update or replace vulnerable packages and libraries, adjust application and container configurations, and validate fixes with follow‑up testing.
- Provide security input into change management processes, ensuring significant changes consider security impact and include rollback and validation plans.
- Contribute to secure coding and dependency management guidance for teams maintaining existing systems.
- Compliance, Governance & Audit Support
- Support SOC’2 and related compliance programs by maintaining technical evidence of security controls.
- Work with internal stakeholders and external auditors to align security measures with SOC’2, ISO’27001, and NIST‑aligned controls.
- Enhance, document, and automate security controls for…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×