Jobs · Information Technology · Colorado

Information Security Engineer II

Vertafore · Denver, CO · 1 wk ago
Information Technology$110k–$135k/yrFull-time

About the role

The Security Engineer II will play a critical role in designing, implementing, and optimizing security solutions for cloud-based and application security environments. This role focuses on advancing cloud security (AWS & Azure), securing APIs, and ensuring effective WAF deployment to protect both modern and legacy web applications.

Core Responsibilities

  • Architect and implement cloud security solutions in AWS and Azure, focusing on IAM, encryption, security logging, and network segmentation.
  • Manage and optimize Web Application Firewalls (WAF), implementing custom rulesets and exception handling for legacy applications.
  • Conduct in-depth application security reviews, threat modeling, and code assessments to identify vulnerabilities and enforce best practices.
  • Design and integrate security controls into CI/CD pipelines, ensuring a DevSecOps-first approach.
  • Develop and maintain security automation scripts and Infrastructure-as-Code (Terraform, Ansible, etc.).
  • Work closely with compliance teams to align security measures with SOC 2, ISO 27001, and insurance industry regulations.
  • Assess security risks in applications and cloud environments, providing recommendations that balance security with business needs.
  • Support security audits and compliance initiatives by providing evidence and technical explanations for security controls.
  • Act as an escalation point for Security Operations incidents and participate in an on-call Security Operations rotation every 4-6 weeks.

Knowledge, Skills, and Abilities

  • Strong knowledge of modern application architectures (microservices, containers, APIs) and their security implications.
  • Hands-on experience with AWS and Azure security services, including IAM, Security Groups, KMS, WAF, and Defender for Cloud.
  • Deep understanding of WAF tuning strategies for modern and legacy applications.
  • Experience with securing APIs, container security (Docker, Kubernetes), and DevSecOps practices.
  • Proficiency in Python, Go, or PowerShell for security automation.
  • Strong ability to assess risks, propose mitigation strategies, and communicate technical security concepts to engineering teams.

Qualifications

  • Master's degree in Cybersecurity, Computer Science, or related field OR equivalent experience (7+ years in security engineering or related field).
  • Security certifications are a plus (AWS Security Specialty, Azure Security Engineer Associate, GCP Security Engineer).

Pay

$110,000 - $135,000 / year

Similar jobs