- Company Name
- TRM-International
- Job Title
- Senior Security Engineer
- Job Description
-
**Job Title:** Senior Security Engineer
**Role Summary:**
Lead and execute the organization’s security program, ensuring SOC 2 Type I/II compliance, hardening cloud and on‑premise infrastructure, managing security tooling, and responding to incidents. Partner with platform and engineering teams to embed security into infrastructure, CI/CD pipelines, and the software development lifecycle.
**Expectations:**
- Drive SOC 2 compliance from policy creation through audit readiness.
- Maintain a secure, hardened environment across Atlassian Cloud, Azure, and OVH Rocky Linux servers.
- Implement and continuously improve secure SDLC practices and vulnerability management.
- Provide incident response, forensics, and risk assessment support.
- Balance rapid delivery needs with rigorous security controls.
**Key Responsibilities:**
- Own SOC 2 Type I/II program: control mapping, evidence collection, audit coordination.
- Harden and monitor Atlassian Cloud, Azure, and OVH bare‑metal Rocky Linux (CIS Level 1).
- Configure, tune, and maintain SIEM, Azure security services, and Microsoft 365 security stack.
- Implement secure SDLC tools (GitHub, Snyk, OWASP SecureCodeBox, DefectDojo) and integrate with CI/CD pipelines.
- Conduct access reviews, vulnerability scans, risk assessments, tabletop exercises, and manage remediation.
- Lead incident response, forensic analysis, and post‑mortem reporting.
- Collaborate with Platform Engineering to embed security controls via Ansible, Terraform, and IaC.
**Required Skills:**
- 5+ years security engineering or management experience in hybrid/multi‑cloud environments.
- Deep knowledge of SOC 2 controls, evidence collection, and audit processes.
- Expertise with Azure security services, SIEM platforms, and M365 security.
- Hands‑on Linux hardening (CIS benchmarks), automation with Ansible and Terraform.
- Proficiency in secure coding practices, SAST/DAST tools, threat modeling, and vulnerability management.
- Strong analytical, communication, and cross‑functional collaboration abilities.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Relevant security certifications preferred (e.g., CISSP, CISM, Azure Security Engineer Associate, AWS Security Specialty).