[All remote jobs](https://jobicy.com/jobs.md)[![Five9 logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/7c3d754e-221.png)](https://jobicy.com/company/five9.md)[Five9](https://jobicy.com/company/five9.md)

# Senior Information Security Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/five9.md)ShareRemote from[Portugal](https://jobicy.com/job-region/portugal.md)SalaryUndisclosedDepartment[Cybersecurity](https://jobicy.com/categories/cybersecurity.md)EmploymentFull TimeExperienceDirectorPublished6 Oct 2026Apply before5 Nov 2026Listing views32Application actions2Application toolkit

## Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

## The role, at a glance.

Five9 is seeking a Senior Information Security Engineer for its Security Risk Management team, with responsibility for identifying, assessing, treating, and reporting security risks across infrastructure, cloud services, corporate systems, and acquisitions. The role maintains the security risk register in Jira, drives ownership and remediation with engineering and operational stakeholders, and coordinates risk acceptance decisions. It also produces leadership-facing dashboards and metrics while improving policies, playbooks, workflows, and risk-management program maturity. The ideal candidate brings risk-management or GRC experience, familiarity with frameworks such as NIST, ISO 27001, PCI, and SOC 2, and strong communication skills for technical and executive audiences.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

4/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a senior, cross-functional security risk role requiring sound judgment across cloud, infrastructure, compliance, vulnerability management, and business priorities. The engineer must independently resolve ambiguous ownership questions and translate complex risk information into actionable executive reporting.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$135,000US market range$115k–$160k0$176k

AI insightNo actual salary is disclosed in the posting, so these are estimated US-market annual base-salary figures in USD for a senior information security engineer focused on security risk management/GRC. Estimated market range: $115,000-$160,000, with an estimated midpoint of $135,000; actual compensation may vary by location, scope, bonus, and equity.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Security Risk Management](https://jobicy.com/jobs?search_keywords=Security%20Risk%20Management.md)[GRC](https://jobicy.com/jobs?search_keywords=GRC.md)[Information Security](https://jobicy.com/jobs?search_keywords=Information%20Security.md)[Risk Assessment](https://jobicy.com/jobs?search_keywords=Risk%20Assessment.md)[NIST CSF](https://jobicy.com/jobs?search_keywords=NIST%20CSF.md)[ISO 27001](https://jobicy.com/jobs?search_keywords=ISO%2027001.md)[Security Risk Register](https://jobicy.com/jobs?search_keywords=Security%20Risk%20Register.md)[Jira](https://jobicy.com/jobs?search_keywords=Jira.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[Executive Reporting](https://jobicy.com/jobs?search_keywords=Executive%20Reporting.md)

Sample interview questionsHow would you assess and prioritize a newly identified security risk affecting a production cloud service?I would first validate the finding, identify affected assets and data, and document the threat scenario, likelihood, and business impact. I would use the organization's approved scoring methodology, confirm compensating controls with the service owner, and prioritize remediation based on residual risk, exposure, and operational urgency. I would then record ownership, milestones, and evidence in the risk register.

Describe how you would drive remediation when an engineering team disagrees with the severity of a risk.

I would begin by ensuring both sides agree on the facts, affected systems, and threat model. I would explain the risk in terms of business impact and residual exposure, invite the team to propose feasible mitigations, and document agreed actions or rationale. If the residual risk remains above tolerance, I would escalate through the defined governance process for an informed acceptance or prioritization decision.

What makes an effective security risk register?

An effective register has clear, consistently scored risk statements; defined asset and business context; named accountable owners; treatment plans with dates; status tracking; and documented residual-risk or acceptance decisions. It should be operationally useful to teams while also supporting trend reporting for leadership. Regular review and aging analysis help ensure risks do not become stale.

How would you present security risk posture to executive leadership?

I would focus on concise, decision-oriented reporting: top material risks, changes in exposure, overdue treatment items, risk trends, and areas requiring leadership decisions. Visual dashboards should connect technical issues to customer, operational, financial, or compliance impact. I would avoid unnecessary technical detail while retaining clear drill-down evidence for follow-up.

How do vulnerability-management findings fit into a risk-management program?

Vulnerabilities are inputs to risk management, but they should not be treated as risk without context. I would incorporate asset criticality, exploitability, exposure, compensating controls, data sensitivity, and business impact to determine residual risk and remediation priority. This approach helps focus teams on meaningful risk reduction rather than vulnerability counts alone.

Opportunity details

## About this role.

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide.

Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves.

We are looking for a Senior Information Security Engineer to join our growing Security Risk Management team. The Security Risk Management team aims to expand beyond traditional risk management; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Five9 and our customers.

As a key contributor to the program the role supports the day-to-day execution of risk identification, assessment, treatment, and reporting across Five9’s infrastructure, services, and acquisitions. You’ll work directly with engineering, operations, and business stakeholders to surface security risks, drive them toward resolution, and maintain a clear picture of Five9’s risk posture for leadership.

Key Responsibilities:

* Identify, document, and assess security risks across Five9’s environment, including production infrastructure, cloud services, corporate systems, and acquired platforms
* Maintain the Security Risk Register in Jira, ensuring risks are accurately categorized, assigned to appropriate owners, and tracked through their lifecycle
* Engage with service owners, engineering leads, and operations teams to establish risk ownership and drive remediation or mitigation plans
* Facilitate the risk acceptance process, including preparing risk acceptance documentation and coordinating approval with appropriate stakeholders
* Develop and deliver risk reporting for security leadership and executive audiences, including dashboards and metrics that communicate risk posture clearly
* Collaborate with compliance, vulnerability management, and other Information Security functions to ensure risk findings are incorporated into the broader security program
* Research and apply risk management frameworks and methodologies to continuously improve program maturity
* Contribute to the development of risk management policies, procedures, and playbooks

Requirements:

* 3+ years of experience in information security, with at least 2 years focused on security risk management or GRC
* Demonstrated experience maintaining a security risk register and driving risk treatment decisions with cross-functional stakeholders
* Strong understanding of risk assessment methodologies (qualitative and quantitative)
* Familiarity with security frameworks such as NIST CSF, NIST 800-53, ISO 27001, PCI, or SOC 2
* Ability to communicate security risks clearly to both technical and non-technical audiences
* Experience with Jira or similar tools for tracking and managing risk workflows
* Self-directed and comfortable engaging directly with service owners, engineers, and leadership to resolve ambiguity around risk ownership

Preferred Skills:

* Experience with cloud environments (GCP, AWS, or Azure), particularly assessing risks related to cloud architecture and services
* Familiarity with vulnerability management programs and how they feed into risk management
* Experience supporting compliance audits or regulatory assessments (ISO 27001, SOC 2, PCI DSS)
* Experience building or contributing to security metrics, KPI dashboards, or executive reporting
* Prior work in a SaaS or contact center / communications platform environment
* Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python
* Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.)

Workplace location: This role is fully remote for candidates who reside outside Porto, Maia, Matosinhos, Gondomar, Valongo e Vila Nova de Gaia. Candidates who reside within those municipalities would be required to work in-office 3 days a week.

Benefits:

* Five9 Shares
* Bonus Scheme
* 10% Flex Benefit
* Meal Allowance
* Medical Insurance
* Life Insurance
* 25 day Annual Leave + Public Holidays

Five9 embraces diversity and is committed to building a team that represents a variety of backgrounds, perspectives, and skills.  The more inclusive we are, the better we are.  Five9 is an equal opportunity employer.

Five9 is committed to providing reasonable accommodations for qualified individuals with disabilities throughout the application and interview process. If you need assistance or an accommodation due to a disability, please contact us at accommodations@five9.com to request an accommodation. Requests will be handled confidentially and in accordance with applicable law.

View our privacy policy, including our privacy notice to California residents here: [https://www.five9.com/pt-pt/legal](https://www.five9.com/pt-pt/legal).

Note: Five9 will never request that an applicant send money as a prerequisite for commencing employment with Five9.

Show more

[Apply now >](https://jobicy.com/jobs/154681-senior-information-security-engineer.md)

>  Annual salary information is not provided for this position. Explore salary ranges for similar roles in our [Salary Directory ›](https://jobicy.com/salaries.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

*
![Beyond Finance logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/68cd015e123539d873279c7b82f1ca6a.jpg)
Beyond Finance Oct 6  New

### [Senior Application Security Engineer](https://jobicy.com/jobs/154682-senior-application-security-engineer-3.md)

At Beyond Finance, we’ve made it our mission to help everyday Americans escape the endless cycle of crippling debt and step into a brighter financial future. Through compassionate, individualized care,…

*
![Five9 logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/7c3d754e-221.png)
Five9 Oct 6  New

### [Cloud Governance Engineer](https://jobicy.com/jobs/154675-cloud-governance-engineer.md)

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide. Living our values…

*
![Collibra logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/25583c1c-221.jpg)
Collibra Oct 5  New

### [Engineer, Security Operations & Engineering](https://jobicy.com/jobs/154592-engineer-security-operations-engineering.md)

Joining Collibra’s Security Operations & Engineering team This is an opportunity to work in the Security Operations & Engineering team within the growing Collibra Security Organization.Security Engineers at Collibra design,…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne Oct 5  New

### [Senior Director, Community](https://jobicy.com/jobs/152527-senior-director-community.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

*
![HackerOne logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8937d355-221.png)
HackerOne Oct 5  New

### [Product Security Analyst](https://jobicy.com/jobs/152523-product-security-analyst.md)

HackerOne is a global leader in Continuous Threat Exposure Management (CTEM). The HackerOne Platform unites agentic AI solutions with the ingenuity of the world’s largest community of security researchers to…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK Oct 4

### [Blockchain Security Expert – AI Track](https://jobicy.com/jobs/152451-blockchain-security-expert-ai-track.md)

About the Company CertiK is the largest blockchain security auditor and provides a comprehensive suite of tools to secure the industry at scale. To date, CertiK has worked with over…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK Oct 4

### [Blockchain Security Engineer – Senior Level (Solidity / Rust / Golang )](https://jobicy.com/jobs/152447-blockchain-security-engineer-senior-level-solidity-rust-golang.md)

About the Role: We are seeking a Senior Blockchain Security Engineer with a strong security mindset and deep technical expertise across smart contracts, blockchain nodes, and decentralized infrastructure. You will…

*
![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)
1Password Oct 2

### [Senior Developer (Windows), Product Security](https://jobicy.com/jobs/154432-senior-developer-windows-product-security.md)

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up…

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius Oct 2

### [Cloud Workplace Engineer](https://jobicy.com/jobs/154423-cloud-workplace-engineer.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

*
![Keyfactor, Inc. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/ba8ae349-221.png)
Keyfactor, Inc. Oct 2

### [Information Security Engineer](https://jobicy.com/jobs/152303-information-security-engineer.md)

About Keyfactor Our mission is to securely connect the world: humans, machines, and AI. Keyfactor is the leader in trust infrastructure for AI and machines, helping the world’s largest enterprises…

[Browse all jobs](https://jobicy.com/jobs.md)