All remote jobs
Open role
Remote opportunity atCision

Security Engineer I, Information Technology

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Published
39Listing views
2Application actions
26 Sep 2026Apply before
Opportunity details

About this role.

AI Summary

Cision is seeking a Security Engineer to strengthen cloud, on-premises, and third-party security architecture across the organization. The role combines security engineering, DevSecOps, identity and access management, cryptography, threat management, and GRC control alignment. The engineer will partner closely with R&D and other departments, embed security in CI/CD processes, assess incidents and vulnerabilities, and help protect customer data. Although titled Engineer I, the requirement for 5+ years of relevant experience and broad technical ownership indicates an experienced individual contributor role. The position is remote within Hungary and includes availability for urgent after-hours incident response.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

5/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

4/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThis is a broad, technically demanding security role requiring hands-on expertise across cloud security, DevSecOps, IAM, cryptography, incident response, and compliance frameworks. The engineer must independently assess risk while communicating technical controls and priorities across R&D, compliance, and operational stakeholders.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$130,000
US market range$110k–$155k
AI insightNo actual salary, pay range, or other candidate compensation is disclosed in the posting. The figures are estimated annual USD compensation for the US market for an experienced security engineering professional with approximately 5+ years of experience and responsibilities spanning cloud security, DevSecOps, GRC, and incident response; actual Hungary-based compensation may differ materially.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How would you embed security effectively into an existing CI/CD pipeline?

I would first map the current delivery workflow and identify high-risk points, then introduce automated controls such as SAST, dependency and secret scanning, IaC scanning, container scanning, and policy gates. Findings should be risk-prioritized, integrated into developers’ existing tools, and supported by clear remediation guidance so security improves delivery rather than becoming a late-stage blocker.

Describe your approach to securing a cloud-native application that handles customer data.

I would apply defense in depth: least-privilege IAM, network segmentation, encryption in transit and at rest, managed key lifecycle controls, centralized logging, continuous configuration monitoring, and vulnerability management. I would also threat-model the application, validate backup and incident-response processes, and map controls to applicable privacy and compliance requirements.

How do SAML, OAuth, and OpenID Connect differ, and when would you use them?

SAML is commonly used for enterprise browser-based single sign-on through signed XML assertions. OAuth 2.0 is an authorization framework for delegated access to APIs, while OpenID Connect adds an identity layer on top of OAuth 2.0 for authentication. I would generally use SAML or OIDC for workforce SSO depending on platform support, and OAuth/OIDC for modern application and API authorization flows.

How would you conduct a threat model for a new service?

I would define the service scope, architecture, assets, trust boundaries, data flows, and external dependencies. Using a structured method such as STRIDE, I would identify likely threats, assess likelihood and business impact, assign owners, and document mitigations such as stronger authentication, validation, rate limiting, encryption, monitoring, or design changes. The threat model should be revisited as the system changes.

An alert suggests anomalous access to a production cloud account. What are your first actions?

I would validate the alert and quickly establish scope using identity, API, endpoint, and network logs. If credible, I would contain the activity by disabling or restricting affected credentials and sessions while preserving evidence, then assess data exposure, eradicate the cause, recover safely, and communicate status through the incident process. Afterwards, I would lead a post-incident review focused on root cause, detection improvements, and durable preventative controls.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.

At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As part of our global team, you’ll thrive in an environment that champions curiosity, collaboration, and innovation, all while making meaningful contributions to the brands we accelerate.

Join us in shaping the future of communication and building authentic connections that matter. Whether you’re solving complex problems or driving bold innovations, your growth is our success, and together, we’ll create the conversations of tomorrow.

Empower your impact at Cision. Be seen, be understood, be you.

This role strengthens and optimizes the organization’s security capabilities by reviewing existing tools, applications, and processes to identify gaps. It establishes and maintains cloud security architecture best practices, focusing on cloud platforms and integrates new and existing security platforms. The role collaborates with R&D teams to maintain a secure architecture and analyzes security events for anomalous activity. It contributes to the organization’s security posture and ensures a secure environment. The individual works on issues requiring the analysis of relevant factors and exercises considerable judgment within defined procedures to determine appropriate action.

This individual will work across multiple departments to design, implement, and manage security solutions that protect both internal and third party (vendor) systems and customer data. You will play a critical role in ensuring that security practices are aligned with compliance requirements while driving technical solutions for secure systems and data protection across the entire organization.

Responsibilities:
• Security Engineering & Architecture: Must have expertise in designing, implementing, and maintaining security architectures across cloud, third-party, and on-premises environments, including evaluating and integrating emerging security technologies.
• DevSecOps: Should possess deep knowledge of embedding security within CI/CD pipelines, establishing security standards, and conducting secure code reviews with development teams.
• Cryptography: Must understand encryption technologies for securing data at rest and in transit, with experience managing cryptographic keys and ensuring compliance with industry standards.
• Identity & Authentication: Requires knowledge of designing and managing secure identity solutions, including Single Sign-On (SSO), Identity Providers (IdPs), and federation protocols such as SAML, OAuth, and OpenID Connect. Familiarity with Okta and Keycloak preferred.
• Secure Coding: Should be proficient in secure coding practices, training teams, and developing standards to prevent vulnerabilities like injection flaws, XSS, and authentication issues.
• Governance, Risk, & Compliance (GRC): Must have a strong grasp of GRC frameworks (e.g., NIST, SOC2, ISO 27001, Cyber Essentials etc) and experience in aligning technical controls with regulatory and audit requirements.
• Threat Management: Requires expertise in performing risk assessments, threat modeling, vulnerability assessments, and mitigation planning to address security risks.
• Incident Response & Monitoring: Should have knowledge of incident response strategies, SOC collaboration, and implementing continuous monitoring tools to ensure compliance and security standards.
• Collaboration & Leadership: Must demonstrate the ability to work with cross-functional teams, mentor junior engineers, and act as a subject matter expert in security technologies, tools, and frameworks.

Requirements:
• Deep understanding of security standards and frameworks such as NIST, ISO 27001, CIS Controls, and industry compliance regulations (GDPR, HIPAA, PCI-DSS).
• Hands-on experience with security tools such as IDS/IPS, SIEM, vulnerability scanners, and penetration testing platforms.
• Experience with cloud platforms (AWS, Azure, GCP, OCI or Alibaba) and securing cloud-native applications.
• Proficiency in programming languages (e.g., Python, Java, C++) and automation tools (e.g., Terraform, Ansible).
• Strong knowledge of networking protocols, firewalls, VPNs, proxies, and security monitoring tools.
• 5+ years of relevant experience in security engineering and GRC-focused security solutions development.
• Extensive hands-on experience in DevSecOps, integrating security in CI/CD pipelines, and supporting development teams in secure coding practices.
• Proven expertise in cryptography, including encryption, key management, and digital signatures.

What we offer:

  • Friendly and welcoming environment focused on people, learning & development
  • 25 vacation days and extra vacation days after age and after children
  • Cafeteria benefit via SZEP card
  • Medicover private health insurance for employees and their family members
  • 10% of your time to work on anything you like, reading groups, tech talks
  • Flexible working and working from home
  • An extensive people development program, including access to Udemy

Please note:

  • Candidates must be available for after-hours incident response when urgent security events require investigation or support.
  • The interview process will include a hands-on practical exercise conducted through screen sharing, where candidates will be asked to demonstrate relevant technical skills.

Cision is the global leader in consumer and media intelligence, engagement, and communication solutions. We equip PR and corporate communications, marketing, and social media professionals with the tools they need to excel in today’s data driven world. Our deep expertise, exclusive data partnerships, and award-winning products, including CisionOne, Brandwatch, and PR Newswire, enable over 75,000 companies and organizations, including 84% of the Fortune 500, to see and be seen, understand and be understood by the audiences that matter most to them.

Cision is committed to fostering an inclusive environment where all employees can be their authentic selves and perform at their best. We believe diversity, equity, and inclusion is vital to driving our culture, sparking innovation and achieving long-term success. Cision is proud to have joined more than 600 companies in signing the CEO Action for Diversity & Inclusion™ pledge and named a “Top Diversity Employer” for 2021 by DiversityJobs.com.

Cision is proud to be an equal opportunity employer, seeking to create a welcoming and diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or other protected statuses.

Cision is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Cision will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly, if reasonable accommodation is required to fully participate in the job application or interview process, to perform the essential functions of the position, and/or to receive all other benefits and privileges of employment, please contact hr.support@cision.com

Cision, Inc. “the Company” only communicates with candidates and extends job offers through direct channels, not third parties.

Please review our Global Candidate Data Privacy Statement to learn about Cision’s commitment to protecting personal data collected during the hiring process.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.
Application method

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. View safety guidance.

Log in to save
One quick step before you apply

Create your free account, then apply.

Build a more organized job search on Jobicy and continue to the employer's application when you're ready.

  • Never lose a promising opportunitySave roles and return to them from your dashboard.
  • See your entire search at a glanceTrack applications, stages and next steps in one place.
  • Get matched with relevant remote jobsChoose the alerts and digests that work for you.
or continue without an account
Applying is free. The employer's application opens in a new tab.
Add alert
Jobs Talent AI Tools Salaries
Menu