[![Image](https://upload.wikimedia.org/wikipedia/commons/8/82/Telegram_logo.svg) Fresh remote jobs, sorted by category — join Jobicy on Telegram  › Fresh remote jobs on Telegram  ›](https://t.me/JobicyJobs) [All remote jobs](https://jobicy.com/jobs.md)Open role[![Keyfactor, Inc. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/ba8ae349-221.png)](https://jobicy.com/company/keyfactor-inc.md)Remote opportunity at[Keyfactor, Inc.](https://jobicy.com/company/keyfactor-inc.md)

# Information Security Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/keyfactor-inc.md)Share1 Sep 2026Published36Listing views4Application actions1 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryKeyfactor is hiring a mid-level Information Security Engineer to strengthen corporate security infrastructure, continuous monitoring, and regulatory compliance. The role evaluates and hardens cloud, system, and network environments; administers SIEM and EDR tooling; and investigates security alerts and incidents. It requires at least five years of information security experience, with hands-on vulnerability management, security controls, and automation skills. Core compliance exposure includes ISO 27001:2022 and SOC 2 Type II, while FedRAMP, CMMC, PKI, AWS GovCloud, and Azure Government experience are preferred. The position is full-time and remote within the United States, with Atlanta or Cleveland preferred.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

4/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

4/5GuidedFull ownership

### Communication Load

4/5IndependentCollaborative

AI insightThis role combines operational security engineering, incident response, vulnerability remediation, and compliance-driven continuous monitoring across evolving platforms. Success requires independent technical judgment as well as the ability to translate findings into documented controls, remediation plans, and stakeholder actions.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$135,000US market range$115k–$160k0$176k

AI insightNo numeric salary is disclosed; “commensurate with experience” is not a usable pay range. Estimated US annual base salary for a mid-level Information Security Engineer with 5+ years of experience and compliance/cloud-security responsibilities is approximately $115,000–$160,000 USD, with an estimated midpoint of $135,000 USD. This is a market estimate, not compensation stated by Keyfactor.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Information Security](https://jobicy.com/jobs?search_keywords=Information%20Security.md)[ISO 27001](https://jobicy.com/jobs?search_keywords=ISO%2027001.md)[SOC 2](https://jobicy.com/jobs?search_keywords=SOC%202.md)[Vulnerability Management](https://jobicy.com/jobs?search_keywords=Vulnerability%20Management.md)[SIEM](https://jobicy.com/jobs?search_keywords=SIEM.md)[EDR](https://jobicy.com/jobs?search_keywords=EDR.md)[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[Security Automation](https://jobicy.com/jobs?search_keywords=Security%20Automation.md)[Python and PowerShell](https://jobicy.com/jobs?search_keywords=Python%20and%20PowerShell.md)

Sample interview questionsHow would you establish and maintain a security baseline across cloud and SaaS environments?I would first inventory assets, data flows, identities, and existing controls, then map required baseline controls to applicable frameworks such as ISO 27001 and SOC 2. I would use configuration assessments and vulnerability scans to identify gaps, prioritize them by risk, assign remediation ownership, and continuously measure compliance through automated monitoring and periodic reviews.

Describe your approach to tuning a SIEM to improve detection quality without overwhelming the security team with alerts.

I begin by validating data-source coverage, log quality, and use cases tied to meaningful threats. I tune rules using historical alert outcomes, asset criticality, user context, threat intelligence, and suppression logic for known benign behavior. I document changes, track false-positive and detection metrics, and regularly reassess rules as the environment and threat landscape change.

How do ISO 27001 and SOC 2 influence day-to-day security engineering work?

They turn security practices into demonstrable, repeatable controls. In daily work, that means ensuring configurations, access reviews, vulnerability remediation, incident procedures, evidence collection, and change management are documented, consistently performed, and measurable against control objectives.

What steps would you take after identifying a critical vulnerability in an internet-facing production system?

I would validate the finding, assess exploitability and business impact, identify affected assets, and immediately involve the system owner and incident stakeholders. I would recommend compensating controls if an immediate patch is not feasible, coordinate remediation and verification, document risk acceptance if needed, and preserve evidence for compliance and post-remediation reporting.

How have you used scripting to improve security operations?

I use Python or PowerShell to automate repetitive tasks such as collecting configuration evidence, enriching alerts, querying APIs, normalizing scan results, and tracking remediation status. Automation is most effective when it includes error handling, access controls, clear documentation, and outputs that integrate with existing ticketing, SIEM, or reporting workflows.

About Keyfactor

Our mission is to securely connect the world: humans, machines, and AI. Keyfactor is the leader in trust infrastructure for AI and machines, helping the world’s largest enterprises and government agencies take control of the cryptographic identities that safeguard every digital interaction. Behind the platform is a global team of people who care deeply about the work and each other. We move fast, think big, and show up for one another every day. If you’re looking for work that matters and a team that brings out your best, we hope you’ll trust your future with Keyfactor!

Title: Information Security Engineer

Location: USA; Remote (Atlanta or Cleveland preferred)

Experience: Mid-Level

Job Function: Corporate IT

Employment Type: Full-Time

Industry: Computer & Network Security

About the position

We are seeking an experienced Information Security Engineer with a strong background in implementing and managing general information security frameworks, including ISO 27001:2022 and SOC 2 Type II. This role involves designing, maintaining, and improving our security infrastructure to ensure compliance with regulatory standards and support continuous monitoring efforts. The ideal candidate will play a key role in safeguarding the organization’s data and infrastructure while driving adherence to evolving security best practices.

Responsibilities

* Evaluate the security posture of systems, platforms, and cloud environments, establish appropriate security baselines, and drive implementation and hardening to close identified gaps.
* Quickly develop proficiency in new SIEM, EDR, and other security platforms as the environment evolves; configure, tune, and integrate these tools with SaaS applications and diverse data sources to expand visibility and detection coverage.
* Evaluate and optimize security playbooks, runbooks, and processes based on lessons learned, tooling changes, and evolving threats, ensuring documentation and workflows keep pace with the organization’s security operations maturity.
* Experience conducting vulnerability assessments, system audits, and risk analysis using industry-standard scanning tools to support a proactive security posture.
* Manage and implement continuous monitoring processes to ensure the organization maintains compliance with a variety of information security frameworks, including ISO 27001:2022 and SOC 2 Type II. Experience with government compliance standards such as FedRAMP (NIST SP 800-53) and CMMC is preferred. This role focuses on ensuring robust security practices and adapting to evolving compliance requirements.
* Actively monitor, analyze, and respond to security alerts and incidents, performing investigations, incident handling, and recommending corrective actions.

Minimum Qualifications, Education, and Skills

* 5+ years of experience in information security or a similar role
* Proficiency in vulnerability scanning tools (Nessus, Burpsuite, Tenable, etc…) and interpreting scan results for remediation.
* Strong knowledge of security standards
* Demonstrated experience in continuous monitoring, network security, firewalls, VPNs, IDS/IPS, and endpoint protection.
* Strong analytical skills and a meticulous approach to problem-solving
* Demonstrated capability to deliver results on-time and to a defined schedule.
* Relevant certifications (e.g., CISSP, CompTIA Security+, CAP) are strongly preferred
* Familiarity with cloud security principles
* Experience with security automation and continuous monitoring tools
* PKI knowledge a plus
* Knowledge of scripting languages (Python, PowerShell) to automate security processes
* Experience with government-regulated environments (AWS GovCloud, Azure Government) preferred #LI-NA1

Compensation

Salary will be commensurate with experience. 

Culture, Career Opportunities and Benefits

We build teams that continually strive to get better than the day before. You will be challenged daily and given opportunities to grow personally and professionally. We balance autonomy and structure to create an entrepreneurial environment to spur creativity and new ideas. 

Here are just some of the initiatives that make our culture special:  

* Second Fridays (a company-wide day off on the second Friday of every month minus November and December due to the Holiday schedule). Please note that this benefit is subject to change.
* Comprehensive benefit coverage globally.
* Paid Parental Leave is available to new parents. Structure varies based on regional/government requirements. In regions where government-paid leave doesn’t exist, like in the U.S., the company offers generous paid parental leave, along with comprehensive adoption and fertility support.
* Competitive time off globally.
* Dedicated employee-focused ambassadors via Key Contributors & Culture Committees.
* DIVERSE Commitment, a call to action for a more inclusive and diverse future in business, society, and technology.
* The Keyfactor Alliance Program to support DEIB efforts.
* Wellbeing resources, wellness allowance, mindfulness app free membership, Wellness Wednesdays.
* Global Volunteer Day, company non-profit matching, and 3 volunteer days off.
* Monthly Talent development and Cross Functional meetings to support professional development.
* Regular All Hands meetings – followed by group gatherings.

Our Core Values

Our core values are extremely important to how we run our business and what we look for in every team member:  

Trust is paramount.  

We deliver security software and solutions where trust and openness are of the highest importance for our customers. We are honest and a trusted partner in every aspect of business.  

Customers are core.  

We strategize, operate, and execute through a customer-centric view. We prioritize the security interests of our customers, and we act as if their data were our own.  

Innovation never stops, it only accelerates.  

The speed of change is accelerating. We are committed, through investment and focus, to stay ahead of the innovation curve.  

We deliver with agility.   

We thrive in high-paced and continually changing environments. We navigate through newly added variables, adjust accordingly, while driving towards our strategic goals.  

United by respect.   

Respect for all is what unites us. We promote diversity, inclusivity, equity, and acting with empathy and openness, both in our business and in our communities.  

Teams make “it” happen.  

Vision and goals are not individually achievable – they require teamwork. We pride ourselves in operating as a cohesive team, creating promoters and partners, and winning as one.  

Keyfactor is a proud equal opportunity employer including but not limited to veterans and individuals with disabilities. 

REASONABLE ACCOMMODATION: Applicants with disabilities may contact a member of Keyfactor’s People team via people@keyfactor.com and/or telephone at 1.216.785.2990 to request and arrange for accommodations at any time.

[Keyfactor Privacy Notice](https://www.keyfactor.com/privacy-policy/)

Show more

[Apply now >](https://jobicy.com/jobs/152303-information-security-engineer.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Karbon logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13eaf3d2-221.png)
Karbon  Sep 1

### [Senior Security Engineer](https://jobicy.com/jobs/152293-senior-security-engineer-3.md)

About Karbon Karbon is the global leader in AI-powered practice management software for accounting firms. We provide an award-winning cloud platform that helps tens of thousands of accounting professionals work…

*
![Karbon logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/13eaf3d2-221.png)
Karbon  Sep 1

### [AppSec Engineer](https://jobicy.com/jobs/152273-appsec-engineer.md)

About Karbon Karbon is the global leader in AI-powered practice management software for accounting firms. We provide an award-winning cloud platform that helps tens of thousands of accounting professionals work…

*
![Zscaler logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/b3234031-221.png)
Zscaler  Aug 31

### [Director, Specialist Sales Engineering – Data Security](https://jobicy.com/jobs/152257-director-specialist-sales-engineering-data-security.md)

About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the…

*
![Reddit logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/Reddit.jpg)
Reddit  Aug 31

### [Staff Product Security Engineer](https://jobicy.com/jobs/152256-staff-product-security-engineer.md)

Reddit is a community of communities. It’s built on shared interests, passion, and trust, and is home to the most open and authentic conversations on the internet. Every day, Reddit…

*
![SWORD Health logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/5dda1790-221.jpg)
SWORD Health  Aug 31

### [Senior Security Operations Engineer](https://jobicy.com/jobs/152254-senior-security-operations-engineer-2.md)

At Sword, we’re building AI to heal billions and unlock humanity’s full potential. In doing so, we’re pioneering AI Care, a fundamentally new approach to healthcare built for medical reasoning,…

*
![Apollo.io logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/f3c639242c4d1f4cb9c0730ac3842a72.jpeg)
Apollo.io  Aug 31

### [Senior Application Security Engineer](https://jobicy.com/jobs/152253-senior-application-security-engineer-2.md)

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world’s largest enterprises….

*
![Reddit logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/Reddit.jpg)
Reddit  Aug 31

### [Senior Security Engineer, AI Security](https://jobicy.com/jobs/152252-senior-security-engineer-ai-security.md)

Reddit is a community of communities. It’s built on shared interests, passion, and trust, and is home to the most open and authentic conversations on the internet. Every day, Reddit…

*
![Maven Clinic logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/c4b2d5ecf34b-221.webp)
Maven Clinic  Aug 31

### [Staff Software Engineer – Product Security](https://jobicy.com/jobs/152250-staff-software-engineer-product-security.md)

Maven Clinic is the world’s largest virtual clinic for women and families on a mission to make healthcare work for all of us. Through Maven Enterprise, the company partners with…

*
![SWORD Health logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/5dda1790-221.jpg)
SWORD Health  Aug 31

### [Security Operations Lead (SecOps)](https://jobicy.com/jobs/152249-security-operations-lead-secops.md)

At Sword, we’re building AI to heal billions and unlock humanity’s full potential. In doing so, we’re pioneering AI Care, a fundamentally new approach to healthcare built for medical reasoning,…

*
![Apollo.io logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/f3c639242c4d1f4cb9c0730ac3842a72.jpeg)
Apollo.io  Aug 31

### [Engineering Manager, Security Detection & Response](https://jobicy.com/jobs/152248-engineering-manager-security-detection-response.md)

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world’s largest enterprises….