Onit

Senior Security Engineer

Onit

full-time

Posted on:

Origin:  • 🇺🇸 United States

Visit company website
AI Apply
Apply

Job Level

Senior

Tech Stack

AnsibleAWSCloudEC2FirewallsLinuxPythonTerraform

About the role

  • Support the Onit security function during US Central Time business hours
  • Manage and conduct vulnerability testing, penetration testing, and client security audits
  • Implement and manage cloud-native security tools and third-party solutions for threat detection and incident response
  • Define, maintain, and execute the Incident Response plan, investigating and resolving incident escalations
  • Perform regular risk assessments and vulnerability scans of cloud infrastructure, ensuring timely remediation
  • Collaborate with Dev, DevOps, and Infra teams to remediate identified vulnerabilities, discuss security best practices, and assist with security incident response
  • Analyze EDR alerts and logs to identify potential security incidents and take appropriate action
  • Continuously evaluate and implement security tools and practices to enhance the security posture of the Onit environment
  • Assist with security awareness programs for employees regarding security best practices
  • Assist with the development and updates of Security Policies for SOC2 and ISO27001 compliance
  • Perform quarterly access reviews

Requirements

  • Minimum of 5 years of experience in information security
  • At least 3 years focused on cloud security for enterprise SaaS applications
  • Proficient in AWS with strong understanding of AWS networking/VPC, IAM, Security Groups, EC2, RDS, S3, and containers (EKS/ECS)
  • Extensive hands-on experience investigating security incidents
  • Creation, management, and execution of security runbooks / playbooks
  • Knowledge of AWS Native Security tools, security frameworks, and CSPM tools
  • Experience with vulnerability scanners, IDS/IPS, SIEM, firewalls, and endpoint security monitoring
  • Experience with threat detection and threat intelligence
  • Proficient in Linux
  • Application security experience with understanding of SAST, DAST, SBOMs, and other scans and artifacts
  • Familiarity with security frameworks such as NIST and ISO 27001
  • Strong communication, problem-solving, and collaboration skills
  • Support security function during US Central Time business hours (required availability)
  • Desired certifications: CCSP, AWS Security, OSCP, or equivalent
  • Experience with Cloudflare and/or AWS WAF configurations
  • Experience with AWS Guard Duty and CrowdStrike
  • Automation experience with AWS CLI, Bash, Python, Ansible (preferred)
  • Experience with Microsoft Entra and Mimecast
  • Self-starter with ability to multi-task in a fast-paced environment