Suggested rewrite: Led a cross-functional initiative that improved [business outcome] by [measurable result], demonstrating experience relevant to this role...
Senior Information Security Engineer
Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.
- Remote from
- Portugal
- Salary
- Undisclosed
- Department
- Cybersecurity
- Employment
- Full Time
- Experience
- Director
- Published
- Apply before
- 5 Nov 2026
- Listing views
- 23
- Application actions
- 2
Make your next move.
Prepare your resume, explore your fit, and draft a cover letter for this opportunity.
The role, at a glance.
Five9 is seeking a Senior Information Security Engineer for its Security Risk Management team, with responsibility for identifying, assessing, treating, and reporting security risks across infrastructure, cloud services, corporate systems, and acquisitions. The role maintains the security risk register in Jira, drives ownership and remediation with engineering and operational stakeholders, and coordinates risk acceptance decisions. It also produces leadership-facing dashboards and metrics while improving policies, playbooks, workflows, and risk-management program maturity. The ideal candidate brings risk-management or GRC experience, familiarity with frameworks such as NIST, ISO 27001, PCI, and SOC 2, and strong communication skills for technical and executive audiences.
Role DNA
A quick view of the complexity, pace, ownership and collaboration implied by the job description.
Pace & Pressure
4/5Autonomy Level
5/5Communication Load
5/5Salary analysis
Estimated compensation compared with the broader US market for similar roles.
Core skills
Skills and capabilities most closely associated with this opportunity.
Sample interview questions
I would first validate the finding, identify affected assets and data, and document the threat scenario, likelihood, and business impact. I would use the organization's approved scoring methodology, confirm compensating controls with the service owner, and prioritize remediation based on residual risk, exposure, and operational urgency. I would then record ownership, milestones, and evidence in the risk register.
I would begin by ensuring both sides agree on the facts, affected systems, and threat model. I would explain the risk in terms of business impact and residual exposure, invite the team to propose feasible mitigations, and document agreed actions or rationale. If the residual risk remains above tolerance, I would escalate through the defined governance process for an informed acceptance or prioritization decision.
An effective register has clear, consistently scored risk statements; defined asset and business context; named accountable owners; treatment plans with dates; status tracking; and documented residual-risk or acceptance decisions. It should be operationally useful to teams while also supporting trend reporting for leadership. Regular review and aging analysis help ensure risks do not become stale.
I would focus on concise, decision-oriented reporting: top material risks, changes in exposure, overdue treatment items, risk trends, and areas requiring leadership decisions. Visual dashboards should connect technical issues to customer, operational, financial, or compliance impact. I would avoid unnecessary technical detail while retaining clear drill-down evidence for follow-up.
Vulnerabilities are inputs to risk management, but they should not be treated as risk without context. I would incorporate asset criticality, exploitability, exposure, compensating controls, data sensitivity, and business impact to determine residual risk and remediation priority. This approach helps focus teams on meaningful risk reduction rather than vulnerability counts alone.
About this role.
Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide.
Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves.
We are looking for a Senior Information Security Engineer to join our growing Security Risk Management team. The Security Risk Management team aims to expand beyond traditional risk management; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Five9 and our customers.
As a key contributor to the program the role supports the day-to-day execution of risk identification, assessment, treatment, and reporting across Five9’s infrastructure, services, and acquisitions. You’ll work directly with engineering, operations, and business stakeholders to surface security risks, drive them toward resolution, and maintain a clear picture of Five9’s risk posture for leadership.
Key Responsibilities:
- Identify, document, and assess security risks across Five9’s environment, including production infrastructure, cloud services, corporate systems, and acquired platforms
- Maintain the Security Risk Register in Jira, ensuring risks are accurately categorized, assigned to appropriate owners, and tracked through their lifecycle
- Engage with service owners, engineering leads, and operations teams to establish risk ownership and drive remediation or mitigation plans
- Facilitate the risk acceptance process, including preparing risk acceptance documentation and coordinating approval with appropriate stakeholders
- Develop and deliver risk reporting for security leadership and executive audiences, including dashboards and metrics that communicate risk posture clearly
- Collaborate with compliance, vulnerability management, and other Information Security functions to ensure risk findings are incorporated into the broader security program
- Research and apply risk management frameworks and methodologies to continuously improve program maturity
- Contribute to the development of risk management policies, procedures, and playbooks
Requirements:
- 3+ years of experience in information security, with at least 2 years focused on security risk management or GRC
- Demonstrated experience maintaining a security risk register and driving risk treatment decisions with cross-functional stakeholders
- Strong understanding of risk assessment methodologies (qualitative and quantitative)
- Familiarity with security frameworks such as NIST CSF, NIST 800-53, ISO 27001, PCI, or SOC 2
- Ability to communicate security risks clearly to both technical and non-technical audiences
- Experience with Jira or similar tools for tracking and managing risk workflows
- Self-directed and comfortable engaging directly with service owners, engineers, and leadership to resolve ambiguity around risk ownership
Preferred Skills:
- Experience with cloud environments (GCP, AWS, or Azure), particularly assessing risks related to cloud architecture and services
- Familiarity with vulnerability management programs and how they feed into risk management
- Experience supporting compliance audits or regulatory assessments (ISO 27001, SOC 2, PCI DSS)
- Experience building or contributing to security metrics, KPI dashboards, or executive reporting
- Prior work in a SaaS or contact center / communications platform environment
- Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python
- Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.)
Workplace location: This role is fully remote for candidates who reside outside Porto, Maia, Matosinhos, Gondomar, Valongo e Vila Nova de Gaia. Candidates who reside within those municipalities would be required to work in-office 3 days a week.
Benefits:
- Five9 Shares
- Bonus Scheme
- 10% Flex Benefit
- Meal Allowance
- Medical Insurance
- Life Insurance
- 25 day Annual Leave + Public Holidays
Five9 embraces diversity and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better we are. Five9 is an equal opportunity employer.
Five9 is committed to providing reasonable accommodations for qualified individuals with disabilities throughout the application and interview process. If you need assistance or an accommodation due to a disability, please contact us at accommodations@five9.com to request an accommodation. Requests will be handled confidentially and in accordance with applicable law.
View our privacy policy, including our privacy notice to California residents here: https://www.five9.com/pt-pt/legal.
Note: Five9 will never request that an applicant send money as a prerequisite for commencing employment with Five9.
Annual salary information is not provided for this position. Explore salary ranges for similar roles in our Salary Directory ›
This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.
Apply now.
Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.
Continue on the employer website
Protect your personal information and never pay to secure an interview or job offer. .
