Information Security Engineer
ConsumerAffairsAbout the role
ConsumerAffairs helps consumers make smart buying decisions in moments of need. Every month millions of consumers turn to our site and tools for help with their considered (often emotional) purchases.
We educate them about their options, learn about their specific needs, and connect hundreds of thousands of them directly to brands. These brands use our SaaS tools to manage their reviews and communicate directly with consumers to serve them better. Our business thrives when the consumers who trust us get matched with the right brands for them.
We’re fast-paced and our core values are the bedrock of who we are and who we want to be.
Our employees believe in raising the bar through data-driven innovation, intellectual curiosity, and grit. We have a team-first mentality, and manifest wins by putting the team first. Collaboration and teamwork are in our hearts; we believe winning together is the most fun. But, above all else, we care. We have servant hearts for our consumers, customers, and colleagues. If you want to be part of a globally diverse team focussing on helping people, in an environment where we raise the bar, win as a team, and care above all else—then ConsumerAffairs may be just the place for you!
ABOUT THE JOB:
We are looking for an experienced Information Security Engineer to monitor and manage security on our hardware, software, and networks. This position will be responsible for preventing unauthorized access to our data by searching for vulnerabilities and risks. In this role, the Information Security Engineer should be knowledgeable about security frameworks and possess both deep and wide expertise in the security space. If you’re a problem-solver and quick decision-maker, we’d like to meet you. Your goal will be to ensure that our technology infrastructure is well protected and implement appropriate security measures when needed. Qualified candidates will have a background in Security or Systems Engineering.
RESPONSIBILITIES & EXPECATIONS:
These responsibilities are not to be construed as a complete statement of all duties performed. Employees will be required to perform other job-related duties as required
Responsibilities:
- Monitor and respond to security incidents and threats
- Monitor network activity to identify issues early and communicate them to IT teams
- Conduct regular security assessments, scans, and audits to identify vulnerabilities and threats
- Manage and maintain security systems and tools such as intrusion detection and prevention systems, endpoint protection solutions, and vulnerability scanning tools
- Develop and maintain incident response plans and procedures
- Prepare and document standard operating procedures and protocols
- Engineer, implement, and monitor security measures for the protection of systems, networks, and information
- Configure and troubleshoot security infrastructure devices
- Develop technical solutions and security tools to help mitigate security vulnerabilities and automate repeatable tasks
- Analyze IT specifications to assess security risks
- Manage and maintain security awareness training program on information security standards, policies, and best practices for employees
- Collaborate with internal teams to identify and remediate security vulnerabilities
- Provide technical guidance and support to other teams on security-related issues
- Write comprehensive reports including assessment-based findings, outcomes, and propositions for further system security enhancement
- Develop and carry out information security plans and policies
- Stay up to date with the latest cybersecurity threats and technologies
Requirements
Minimum Qualifications & Credentials
- BSc/BA in Computer Science, Information Technology, or a related field
- Professional certification (e.g. CompTIA Security+, CISSP) is a plus
- At least 4-5 years of experience in Information Security or a related field
Experience
- Experience with vulnerability scanning solutions
- Experience with an enterprise SIEM platform
- Experience in building and maintaining security systems
- Experience with network security and networking technologies
- Experience with system, security, and network monitoring tools
- Proven work experience as a System Security Engineer or Information Security Engineer
- Experience with AWS and cloud platform as a service (PaaS) security
- Experience with change management processes
Hard/Technical Skills
- Well-versed with various security tools such as Burp Suite, Nmap, Nessus, Qualys, etc.
- Understanding of OWASP testing methodology
- Familiarity with public key
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s