Summary
HSP Group provides global expansion services covering legal entity setup, global HR, payroll, compliance, tax, and advisory services. The company is seeking a hands-on Information Security Engineer to protect its SaaS products, secure Azure cloud and endpoint environments, manage vulnerabilities, lead SOC 2 compliance, and support security governance and customer security engagements.
Responsibilities
- Lead the company’s SOC 2 compliance program, including readiness, control implementation, evidence collection, ongoing monitoring, remediation, and coordination with auditors through successful completion of the audit
- Lead the vulnerability management program across our SaaS products, cloud infrastructure, containers, and endpoints including identification, triage, prioritization, remediation tracking, and reporting
- Operate and tune SAST, SCA, and dependency-scanning tooling (e.g., Snyk, GitHub Advanced Security/Dependabot) and partner with engineering teams to drive timely remediation
- Monitor runtime and infrastructure telemetry (e.g., Datadog) for security signals; investigate alerts and lead containment and follow-up actions
- Track and report on vulnerability SLAs, mean-time-to-remediate, and other security KPIs to leadership
- Enhance the security posture of our Microsoft Azure environment including identity, networking, data, and workloads through configuration hardening, policy enforcement, and continuous monitoring
- Administer and improve Microsoft Intune for endpoint configuration, compliance, and mobile device management
- Tune and maintain Microsoft Defender (Endpoint, Cloud, and related products) for threat detection, response, and reporting
- Draft, update, and maintain corporate information security policies, standards, and procedures aligned to recognized frameworks (e.g., SOC 2, ISO 27001, NIST CSF)
- Lead the response to customer and prospect security questionnaires, RFPs, and due-diligence requests, and maintain a reusable response library
- Support vendor risk assessments and third-party security reviews
- Assist with internal and external audits, evidence collection, and remediation of findings
- Partner with Engineering on secure SDLC practices, threat modeling, and code review guidance
- Contribute to security awareness training, phishing simulations, and a strong security culture across the company
- Help mature incident response playbooks and participate in tabletop exercises and on-call rotations as needed
Skills
- * 4–6 years of professional experience in information security, application security, cloud security, or a closely related role
- * Experience in preparing for SOC 2 Type 2 attestations for SaaS products
- * Hands-on experience securing SaaS applications and workloads running in Microsoft Azure
- * Demonstrated experience with vulnerability management tooling and process including triage, prioritization (e.g., CVSS, EPSS, exploitability context), and driving remediation through engineering teams
- * Working proficiency with several of the following: Microsoft Intune, Microsoft Defender (Endpoint/Cloud), Microsoft Purview, Datadog, GitHub (Advanced Security, Dependabot, code scanning), and Snyk
- * Solid understanding of identity and access management concepts, particularly Microsoft Entra ID (Azure AD), conditional access, and least-privilege design
- * Experience writing or substantially contributing to security policies, standards, or procedures
- * Experience in responding to customer security questionnaires and supporting compliance efforts
- * Strong written and verbal communication skills and able to translate technical risk for both engineers and non-technical stakeholders
- * Industry certifications such as CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent
- * Experience with container and Kubernetes security
- * Exposure to threat modeling, secure code review, or penetration testing
- * Prior experience in a SaaS company or regulated industry
Qualifications
Must Haves
- * 4–6 years of professional experience in information security, application security, cloud security, or a closely related role
- * Experience in preparing for SOC 2 Type 2 attestations for SaaS products
- * Hands-on experience securing SaaS applications and workloads running in Microsoft Azure
- * Demonstrated experience with vulnerability management tooling and process including triage, prioritization (e.g., CVSS, EPSS, exploitability context), and driving remediation through engineering teams
- * Working proficiency with several of the following: Microsoft Intune, Microsoft Defender (Endpoint/Cloud), Microsoft Purview, Datadog, GitHub (Advanced Security, Dependabot, code scanning), and Snyk
- * Solid understanding of identity and access management concepts, particularly Microsoft Entra ID (Azure AD), conditional access, and least-privilege design
- * Experience writing or substantially contributing to security policies, standards, or procedures
- * Experience in responding to customer security questionnaires and supporting compliance efforts
- * Strong written and verbal communication skills and able to translate technical risk for both engineers and non-technical stakeholders
Nice to Haves
- * Industry certifications such as CISSP, CCSP, AZ-500, SC-200, SC-100, GCIH, GSEC, or equivalent
- * Experience with container and Kubernetes security
- * Exposure to threat modeling, secure code review, or penetration testing
- * Prior experience in a SaaS company or regulated industry
Benefits