IDScan.net
Security Engineer
Share this job
Job Description
Location: New Orleans, LA or remote (US) Reports to: Chief Information Security Officer Type: Full-time
#### About the role
You'd be joining at the start of a program to consolidate our security tooling and mature how we build software. You will help us fix, modernize, and streamline our auditing, vulnerability management, and securing the whole organization.
A DevSecOps Engineer joins alongside you to own identity, API and pipeline work. You'd own the defensive and assurance side.
What you'll own in the first year
Detection engineering. Manage our cloud native SIEM, design the log tiering, and write detections mapped to our actual control set. Own alert quality, a noisy queue is a broken control.
Vulnerability management. Stand up continuous scanning across all of our servers, our Azure configuration and our databases. Build a remediation SLA, measure against it, and report it monthly.
Compliance operations. Own our compliance automation platform end to end: control ownership, evidence collection, framework cross-mapping between SOC 2 and ISO 27001 so we collect each artifact once, and the personnel and access integrations that make joiner-leaver evidence automatic.
Asset inventory. Build an authoritative inventory and reconcile it until unknown assets reach zero.
Backup and recovery assurance. Own restore testing on a schedule. Not backup jobs succeeding, actual documented restores within our stated recovery objective.
Incident response. Help build the new runbooks so we are ready if the worst day ever comes.
#### What we're looking for
3+ years in security operations, detection engineering, or a blue-team role
Hands-on SIEM experience: you've written detection logic, tuned it, and killed rules that produced noise
Azure or comparable cloud security experience, cloud posture, workload protection, identity logs
Vulnerability management in practice: scanning, prioritization that accounts for exploitability
Keep looking