远程工作雷达

高级安全工程师

Senior Security Engineer

开发工程职能支持限定地区(需当地身份)
公司Fullsteam
薪资$122,254 - $140,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

在一家真正相信自己所做之事的公司工作非常有趣!
Fullsteam 是一家领先的垂直软件和嵌入式支付技术提供商,致力于通过为客户提供无缝体验来帮助 businesses 成长。我们拥有超过 1,900 名员工的充满活力且不断壮大的团队,致力于推动创新并提供一流的软件和支付解决方案,以赋能众多行业的中小企业。我们的目标是帮助客户增长业务并让客户感到满意。加入我们,成为一家重视成长、卓越和客户成功的企业的一员。

该职位属于 Fullsteam 信息安全团队,该团队直接负责与业务单元和 Fullsteam 总部合作开展安全计划和响应工作。

在 Fullsteam,我们致力于保护我们的数字资产,并在我们的业务中提供最高标准的安全性。随着我们安全计划的持续扩展,我们正在寻找一位充满热情的安全专业人员加入我们的主动安全团队。

我们是一个小型、高自主权的团队,负责处理广泛的漏洞和风险暴露;包括基础设施、应用程序、软件、AI 系统和外部攻击面。这不是一个工单处理角色;你将对整个漏洞生命周期拥有真正的责任,参与自动化和工具开发,并直接与安全领导层合作。如果你能在快节奏的环境中茁壮成长,并希望塑造一个不断发展的漏洞管理计划,我们期待你的加入。

主要职责:

  • 参与并帮助完善我们的漏洞管理计划,确保企业及各业务单元中的已识别风险按照 SLA 进行修复
  • 在基础设施(云和本地)、应用程序、软件、AI 系统和外部攻击面中识别并报告已知漏洞
  • 监控外部攻击面暴露情况,并参与修复优先级的制定
  • 为安全领导层和业务单元利益相关者生成漏洞指标、趋势报告和风险摘要
  • 支持漏洞管理计划与行业法规和标准(PCI-DSS、SOC2、NIST CSF、ISO 27001)的对齐
  • 与安全、IT 和业务单元工程团队协作,推动有效的、可衡量的漏洞和风险暴露结果
  • 参与风险管理及治理
查看英文原文

It's fun to work in a company where people truly BELIEVE in what they're doing!
Fullsteam is a leading provider of vertical software and embedded payments technology dedicated to helping businesses flourish by providing their customers with seamless experiences. With a dynamic and growing team of over 1,900 employees, we are committed to driving innovation and delivering best-in-class software and payment solutions that empower small and medium-sized businesses across numerous industries. Our purpose is to help our customers grow their businesses and delight their customers. Join us and be a part of a forward-thinking company that values growth, excellence, and the success of our clients.

​​​This position is part of the Fullsteam InfoSec Team which is directly responsible for working with Business Units and Fullsteam Corporate on security initiatives and response.​​

​​At Fullsteam, we're committed to protecting our digital assets and delivering the highest standard of security across our business. As we continue to scale our security programs, we're looking for a passionate security professional to join our Proactive Security team.

​We're a small, high-ownership team tackling vulnerability and risk exposure across a broad surface; infrastructure, applications, software, AI systems, and external attack surface. This isn't a ticket queue role; you'll have real ownership across the full vulnerability lifecycle, contribute to automation and tooling, and work directly alongside security leadership. If you thrive in a fast-paced environment and want to help shape a growing VM program, we want to hear from you.​

Primary Responsibilities:

  • ​​Contribute to and help mature our vulnerability management program, ensuring identified risks are remediated according to SLAs across the enterprise and business units
  • ​Identify and report known vulnerabilities across infrastructure (cloud and on-prem), applications, software, AI systems, and external attack surface
  • ​Monitor external attack surface exposures and contribute to remediation prioritization
  • ​Produce vulnerability metrics, trending reports, and risk summaries for security leadership and business unit stakeholders
  • ​Support alignment of the VM program with industry regulations and standards (PCI-DSS, SOC2, NIST CSF, ISO 27001)
  • ​Collaborate with Security, IT, and BU Engineering teams to drive effective and measurable vulnerability and risk exposure outcomes
  • ​Contribute to risk management and governance functions (e.g., risk register, key metrics, vulnerability reports)
  • ​Develop and contribute to AI-assisted HITL (Human in the Loop) automation and workflows for Proactive Security initiatives
  • ​Collaborate with and learn alongside other Proactive Security team members​

Skills & Competencies:

  • ​​8+ years of Information Technology / Security experiencewith2-4+ years of hands-on experience in vulnerability management, attack surface management, or related security functions
  • ​Working knowledge of security tools such as Wiz, Snyk, Qualys, Nessus, MS Defender, or similar platforms
  • ​Experience with vulnerability prioritization frameworks (CVSS, EPSS, risk-based scoring)
  • ​Experience with application security testing concepts and tools (SAST, DAST, IAST, Burp Suite, Postman, GitHub, etc.)
  • ​Basic scripting or programming experience in any language, or a strong desire to develop this skill
  • ​Ability to produce clear, actionable security reporting for both technical and non-technical audiences
  • ​Hands-on experience with AI-assisted security workflows (prompt engineering, agent development, MCP tooling)
  • ​Experience developing or contributing to process documentation
  • ​Ability to work independently in a fully remote environment while managing multiple concurrent priorities
  • ​Experience working in a multi-business-unit or enterprise environment
  • ​Genuine curiosity and desire to grow​

Minimum Qualifications:

  • ​​​CISSP or equivalent certification (GIAC, CISM, CRISC)
  • ​Bachelor’s degree in cybersecurity or equivalent work experience
  • ​Hands-on Defensive or Offensive security training or work experience
  • ​Project management knowledge, training and/or certifications

Base Salary Range: $122,254 - $140,000 USD
Fullsteam supports an inclusive workplace that values diversity of thought, experience, and background. Fullsteam is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state, or local law.
Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

高级福利分析师

FullsteamUnited States$90,000 - $103,000/年Full Time今天
职能支持限定地区(需当地身份)

← 返回全部职位