Padmi
3Pillar logo
3Pillar

AI transformation · AI-native products

Senior Information Security Engineer

Remote · RomaniaPosted 1 month ago
SecuritySeniorFull Time
Apply at 3Pillar

Opens the source posting on jobs.lever.co

Source description

About the role

View original

Vulnerability & Product Security :

Own the end-to-end vulnerability management program across our SaaS products, cloud infrastructure, containers, and endpoints including identification, triage, prioritization, remediation tracking, and reporting.

Operate and tune SAST, SCA, and dependency-scanning tooling (e.g., Snyk, GitHub Advanced Security/Dependabot) and partner with engineering teams to drive timely remediation.

Monitor runtime and infrastructure telemetry (e.g., Datadog) for security signals; investigate alerts and lead containment and follow-up actions.

Track and report on vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership.

Cloud & Endpoint Security:

Enhance the security posture of our Microsoft Azure environment including identity, networking, data, and workloads through configuration hardening, policy enforcement, and continuous monitoring.

Administer and improve Microsoft Intune for endpoint configuration, compliance, and mobile device management.

Tune and maintain Microsoft Defender (Endpoint, Cloud, and related products) for threat detection, response, and reporting.

Implement and operate Microsoft Purview controls for data classification, DLP, and information protection.

Governance, Risk & Compliance:

Draft, update, and maintain corporate information security policies, standards, and procedures aligned to recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF).

Lead the response to customer and prospect security questionnaires, RFPs, and due-diligence requests, and maintain a reusable response library.

Support vendor risk assessments and third-party security reviews.

Assist with internal and external audits, evidence collection, and remediation of findings.

Security Program & Collaboration:

Partner with Engineering on secure SDLC practices, threat modeling, and code review guidance.

Contribute to security awareness training, phishing simulations, and a strong security culture across the company.

Help mature incident response playbooks and participate in tabletop exercises and on-call rotations as needed.

More at 3Pillar

Related open roles

View all roles