Security Engineer II

3 hours, 22 minutes ago
Full-time
Senior
Cybersecurity
HighLevel

HighLevel

HighLevel provides an all-in-one sales and marketing platform that agencies can white label and resell, offering tools and resources designed to help businesses consolidate their marketing efforts and achieve their growth objectives.

Internet Software & Services
251-1K
Founded 2018
$60M raised

Description

  • Develop, maintain, and improve GRC policies, standards, procedures, and control frameworks.
  • Lead and support SOC 2 Type II, ISO 27001, PCI DSS, and other compliance initiatives, including evidence collection, control validation, and remediation tracking.
  • Partner with Security and Platform teams to ensure security controls are technically implemented.
  • Work with Security Architecture and Engineering to evaluate whether security exceptions meet compliance requirements.
  • Review, reassess, and track approved exceptions to reduce ongoing risk.
  • Partner with Procurement, Legal, and Application Security teams to assess vendor risk and define remediation or contractual security requirements.
  • Design scalable workflows for risk assessments, vendor reviews, evidence management, control testing, and reporting.
  • Deliver GRC and security awareness training on risk ownership, exception handling, and vendor security responsibilities.
  • Prepare risk, compliance, and third-party security posture reports for senior leadership.
  • Perform business impact analysis and facilitate BCDR tabletop exercises.

Requirements

  • Bachelor’s degree in Information Systems, Computer Science, Cybersecurity, or a related field.
  • 4.5+ years of experience in GRC, risk management, or compliance with exposure to technical security controls.
  • Strong understanding of security frameworks and standards such as SOC 2, ISO 27001, and NIST.
  • Hands-on experience with technical risk assessments, exception management, and third-party security reviews.
  • Ability to interpret technical security data such as architecture diagrams, cloud controls, and access models.
  • Strong analytical, documentation, and stakeholder communication skills.
  • Master’s degree in a relevant field is preferred.
  • Certifications such as CISA, CRISC, CGEIT, CISSP, or equivalent are preferred.
  • Experience working in cloud-native or SaaS environments is preferred.
  • Familiarity with TPRM tooling, GRC automation platforms, and risk engineering workflows is preferred.
  • Knowledge of data protection and privacy regulations such as GDPR and CCPA is preferred.

Benefits

  • Remote-first work environment.
  • Opportunity to work for a global company supporting businesses across 150+ countries.
  • Equal Opportunity Employer status with a compliant, transparent hiring process.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Cloud Security Engineer (Azure)

3Cloud 251-1K Internet Software & Services

3Cloud is hiring a Cloud Security Engineer to support complex Azure client environments by implementing secure architectures, monitoring threats, and strengthening identity, compliance, and security operations.

Azure Bash DevSecOps Fortinet HIPAA Palo Alto PowerShell Python SIEM Splunk Terraform
39 minutes ago

Sr. Software Engineer II (6551)

MetroStar 251-1K IT Services

MetroStar is hiring a Sr. Software Engineer II (Trellix) to support enterprise endpoint security operations across DoD and IC environments, with responsibility for sustaining and advancing secure, high-availability systems.

Linux Network Security
54 minutes ago

Sr. Staff Security Engineer, Incident Response

Databricks 1K-5K IT Services

Databricks is hiring a Sr. Staff Security Engineer, Incident Response to lead complex security investigations and shape the company’s long-term incident response strategy for protecting customer, employee, and enterprise data.

Apache Spark AWS Azure macOS MLflow Python SIEM
1 hour, 22 minutes ago

Security Automation Engineer

Calendly 251-1K Internet Software & Services

Calendly is hiring a Security Automation Engineer to help scale its security organization by building automation, internal tools, and reusable workflows that reduce risk and improve operational efficiency.

GCP Go Kubernetes Python Ruby System Design TypeScript
1 hour, 39 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers