Information Security Engineer II
Vertafore · Denver, CO · 1 wk ago
Information Technology$110k–$135k/yrFull-time
About the role
The Security Engineer II will play a critical role in designing, implementing, and optimizing security solutions for cloud-based and application security environments. This role focuses on advancing cloud security (AWS & Azure), securing APIs, and ensuring effective WAF deployment to protect both modern and legacy web applications.
Core Responsibilities
- Architect and implement cloud security solutions in AWS and Azure, focusing on IAM, encryption, security logging, and network segmentation.
- Manage and optimize Web Application Firewalls (WAF), implementing custom rulesets and exception handling for legacy applications.
- Conduct in-depth application security reviews, threat modeling, and code assessments to identify vulnerabilities and enforce best practices.
- Design and integrate security controls into CI/CD pipelines, ensuring a DevSecOps-first approach.
- Develop and maintain security automation scripts and Infrastructure-as-Code (Terraform, Ansible, etc.).
- Work closely with compliance teams to align security measures with SOC 2, ISO 27001, and insurance industry regulations.
- Assess security risks in applications and cloud environments, providing recommendations that balance security with business needs.
- Support security audits and compliance initiatives by providing evidence and technical explanations for security controls.
- Act as an escalation point for Security Operations incidents and participate in an on-call Security Operations rotation every 4-6 weeks.
Knowledge, Skills, and Abilities
- Strong knowledge of modern application architectures (microservices, containers, APIs) and their security implications.
- Hands-on experience with AWS and Azure security services, including IAM, Security Groups, KMS, WAF, and Defender for Cloud.
- Deep understanding of WAF tuning strategies for modern and legacy applications.
- Experience with securing APIs, container security (Docker, Kubernetes), and DevSecOps practices.
- Proficiency in Python, Go, or PowerShell for security automation.
- Strong ability to assess risks, propose mitigation strategies, and communicate technical security concepts to engineering teams.
Qualifications
- Master's degree in Cybersecurity, Computer Science, or related field OR equivalent experience (7+ years in security engineering or related field).
- Security certifications are a plus (AWS Security Specialty, Azure Security Engineer Associate, GCP Security Engineer).
Pay
$110,000 - $135,000 / year