Cape logo
Cape
Posted 23 days agoVerified live 1d ago

Security Engineer, Corporate Security

Brief overview

Remote
UndergradOr in progress
$180k–$220k/yrStated range
2+ yrsMinimum
2 H-1B approvalsDept. of Labor
1 green cardsCertified filings
Identity and Access Management (IAM)Endpoint Detection and Response (EDR)Mobile Device Management (MDM)Network SecurityVulnerability ManagementThird-Party Risk ManagementSecurity Compliance Frameworks SOC 2Security Compliance Frameworks ISO 27001Privacy Regulations GDPRPrivacy Regulations CCPASecure Software Development Lifecycle (SSDLC)Python or Shell ScriptingEncryption

About the company

A privacy-centric movement in mobile connectivity.

Visa sponsorship history

2 years sponsoring, last filed FY2025

Data powered by U.S. Department of Labor. This does not guarantee sponsorship for this specific role.
2H-1B approved
100%approval rate
1PERM certified
H-1B Petition ApprovalsVisas USCIS actually granted: the strongest sign the company sponsors.
20241
20251
Green Card (PERM) FilingsCertified green card filings: a long-term commitment to international hires.
20251

Job description

Summary

Cape is a privacy-first mobile carrier focused on building secure telecommunications infrastructure and protecting personal information. The Security Engineer will lead corporate security efforts across identity, endpoint, network, information security, vulnerability management, compliance, vendor risk, incident response, and security awareness.

Responsibilities

  • Design, implement, and manage security controls and policies across corporate IT systems, focusing on the confidentiality, integrity, and availability of employee, customer, and business data
  • Own and mature identity and access management (IAM/SSO/MFA), endpoint security (EDR, MDM), and email/network security (phishing defense, DLP, firewalls, VPN) across the organization
  • Perform comprehensive security assessments of corporate systems and vendors to identify vulnerabilities, assess risk, and recommend actionable mitigation strategies
  • Establish governance, guardrails, and monitoring for emerging employee tooling, including the associated data-handling, access, and third-party risks
  • Own the vulnerability management lifecycle across the corporate fleet: scanning, risk-based prioritization, remediation and patch SLAs, and closure tracking across endpoints and internal systems
  • Lead security awareness and phishing simulation programs to build an organization-wide culture of security
  • Contribute to compliance and audit efforts as needed, lending security context where it helps the business move faster
  • Assess and manage third-party/vendor security risk, including security questionnaires, contract reviews, and ongoing vendor monitoring
  • Assist in running and addressing findings from penetration tests, red team exercises, and internal audits, ensuring prompt and effective remediation
  • Stay informed about the latest security threats, vulnerabilities, and compliance mandates affecting corporate environments; provide strategic guidance on technologies and best practices
  • Investigate security incidents and insider-threat concerns in partnership with HR, Legal, and IT as needed
  • Raise the security bar across the company by mentoring engineers and partners on secure practices, fostering a culture of security awareness and continuous improvement
  • Collaborate with stakeholders to integrate security requirements effectively into IT projects and broader business initiatives

Skills

  • Bachelor's degree in Computer Science, Information Security, or a related field or equivalent experience
  • A minimum of 2 years of experience in information security, with meaningful experience across corporate/IT security domains (identity, endpoint, network, GRC)
  • Deep understanding of enterprise identity providers and SSO/MFA platforms, endpoint/EDR tooling, MDM platforms, and email security tooling
  • Working knowledge of common compliance frameworks (e.g., SOC 2, ISO 27001)
  • Working knowledge of consumer privacy regulations (GDPR, CCPA, and other regional privacy laws) as they apply to handling customer data
  • Exposure to secure software development lifecycle (SSDLC) practices and partnering with engineering on secure design reviews
  • Proficiency in scripting or automation (Python, shell scripting, or similar) to streamline security operations and reporting
  • Familiarity with vendor/third-party risk management processes and tooling
  • Solid knowledge of network security, encryption technologies, and secure business-system configuration
  • Excellent analytical skills for identifying and mitigating complex security vulnerabilities and risks
  • Strong communication and leadership abilities, capable of working collaboratively across teams and effectively conveying technical information to non-technical stakeholders
  • Organized and able to manage multiple priorities in a dynamic, fast-paced environment
  • Experience identifying and resolving security issues across corporate systems (identity, endpoint, network, and data). Secure-by-design principles, and partnering with IT/engineering during design time
  • Collects data and information; uses critical thinking to solve problems and make sound decisions
  • Builds partnerships with others to reach common goals. Able to share credit with coworkers, display enthusiasm and promote a friendly group-working environment. Works closely with other departments as necessary, supports group decisions and solicits opinions from coworkers
  • Presents information through verbal and written communication; reads and interprets complex information; listens well. Develops and delivers multi-mode communications that convey clear understanding of unique audiences
  • Acts quickly to solve problems and exercises good judgment by making sound and well-informed decisions. Perceives the impact and implications of decisions; makes effective and timely decisions, even when data is limited
  • Possesses the personal discipline and diligence necessary to keep commitments and to complete tasks. Is accountable for actions and outcomes. Makes effort to improve situations without explicit instructions; a self-starter who consciously manages his/her own time and resources
  • Adjusts quickly to changing priorities, conditions, and challenges. Copes effectively with complexity and change. Is comfortable navigating ambiguity. Can handle business changes with ease and without frustration or a feeling of defeat. Feels comfortable dealing with limited unknowns in an area they are well versed in
  • Manages multiple projects, determines project urgency in a meaningful and practical way, uses goals to guide actions, creates detailed action plans, and organizes tasks
  • Advanced degrees or certifications (e.g., CISSP, GIAC, Security+, CISM) are advantageous
  • Familiarity with government/public-sector security frameworks (FedRAMP, FISMA, NIST SP 800 series, CJIS) is a plus, given Cape's government-facing customer base

Qualifications

Must Haves

  • Bachelor's degree in Computer Science, Information Security, or a related field or equivalent experience
  • A minimum of 2 years of experience in information security, with meaningful experience across corporate/IT security domains (identity, endpoint, network, GRC)
  • Deep understanding of enterprise identity providers and SSO/MFA platforms, endpoint/EDR tooling, MDM platforms, and email security tooling
  • Working knowledge of common compliance frameworks (e.g., SOC 2, ISO 27001)
  • Working knowledge of consumer privacy regulations (GDPR, CCPA, and other regional privacy laws) as they apply to handling customer data
  • Exposure to secure software development lifecycle (SSDLC) practices and partnering with engineering on secure design reviews
  • Proficiency in scripting or automation (Python, shell scripting, or similar) to streamline security operations and reporting
  • Familiarity with vendor/third-party risk management processes and tooling
  • Solid knowledge of network security, encryption technologies, and secure business-system configuration
  • Excellent analytical skills for identifying and mitigating complex security vulnerabilities and risks
  • Strong communication and leadership abilities, capable of working collaboratively across teams and effectively conveying technical information to non-technical stakeholders
  • Organized and able to manage multiple priorities in a dynamic, fast-paced environment
  • Experience identifying and resolving security issues across corporate systems (identity, endpoint, network, and data). Secure-by-design principles, and partnering with IT/engineering during design time
  • Collects data and information; uses critical thinking to solve problems and make sound decisions
  • Builds partnerships with others to reach common goals. Able to share credit with coworkers, display enthusiasm and promote a friendly group-working environment. Works closely with other departments as necessary, supports group decisions and solicits opinions from coworkers
  • Presents information through verbal and written communication; reads and interprets complex information; listens well. Develops and delivers multi-mode communications that convey clear understanding of unique audiences
  • Acts quickly to solve problems and exercises good judgment by making sound and well-informed decisions. Perceives the impact and implications of decisions; makes effective and timely decisions, even when data is limited
  • Possesses the personal discipline and diligence necessary to keep commitments and to complete tasks. Is accountable for actions and outcomes. Makes effort to improve situations without explicit instructions; a self-starter who consciously manages his/her own time and resources
  • Adjusts quickly to changing priorities, conditions, and challenges. Copes effectively with complexity and change. Is comfortable navigating ambiguity. Can handle business changes with ease and without frustration or a feeling of defeat. Feels comfortable dealing with limited unknowns in an area they are well versed in
  • Manages multiple projects, determines project urgency in a meaningful and practical way, uses goals to guide actions, creates detailed action plans, and organizes tasks

Nice to Haves

  • Advanced degrees or certifications (e.g., CISSP, GIAC, Security+, CISM) are advantageous
  • Familiarity with government/public-sector security frameworks (FedRAMP, FISMA, NIST SP 800 series, CJIS) is a plus, given Cape's government-facing customer base

Benefits

  • Meaningful equity so you share in the value you help create
  • 401(k) match
  • 100% coverage of medical, dental, and vision premiums for you and your dependents
  • 12 weeks paid parental leave (for all parents, no waiting period)
  • Stipends for family-forming needs
  • Stipends for gender-affirming care
  • Unlimited PTO

More jobs like this