Senior Information Security Engineer

Information Technology Romania


Description

About Payscale
Payscale stands at the forefront of compensation data technology, pioneering an innovative approach that harnesses advanced AI and up-to-date and reliable market data to align employee and employer expectations. With its suite of solutions—Payfactors, Marketpay, and Paycycle—Payscale empowers 65% of Fortune 500 companies to make strategic compensation decisions. Organizations like Panasonic, ZoomInfo, Chipotle, AccentCare, University of Washington, American Airlines, and Rite Aid rely on its unique combination of actionable data and insights, experienced compensation services, and scalable software to drive business success. By partnering with Payscale, businesses can make confident compensation decisions that fuel growth for both their organization and their people.

Create confidence in your compensation. Payscale.
To learn more, visit www.payscale.com.
Location
Payscale Romania has an employee centric hybrid model that provides you the flexibility to do your best work in a space that supports you, while also finding time to collaborate in person in our office for the moments that matter.
In our hybrid model, employees can work from the location that works best for them when not in the office.
When you work from home, we recommend ensuring that you can meet the following technology, equipment and workspace requirements:
  • High-Speed Internet - A stable broadband or fiber connection (satellite is highly discouraged) with a minimum speed of 100 Mbps in a dedicated workspace that has a reliable Wi-Fi signal.
  • Device for Multifactor Authentication (MFA/2FA) - smartphone, tablet, etc.
When it matters (usually no more than a few times a year) we take the time to gather in larger groups for in-person events.
Payscale has employees across the US, Canada, UK, The Philippines and Romania however we are currently unable to hire in the Quebec Province, Northern Ireland, and Hawaii.
We are seeking a proactive and skilled Information Security Engineer to focus on the security of our cloud and datacenter hosting environments. In this role, you will collaborate with cross-functional teams to implement and maintain security controls, monitor vulnerabilities, and support efforts to ensure our infrastructure is secure and compliant with industry standards. This position is ideal for someone with hands-on experience in cloud and datacenter security who is eager to take their expertise to the next level.


Key Responsibilities:
  • Implement and maintain security measures across cloud and datacenter environments, including AWS, Azure, and on-premises hosting platforms.
  • Manage and optimize the organization’s EDR/XDR platform, including policy creation, tuning, and rule maintenance.
  • Lead efforts to review and deploy unused or underutilized features of the EDR/XDR product to improve threat detection and response capabilities.
  • Collaborate with Infrastructure and DevOps teams to secure hybrid workloads, including virtual machines, containers, and serverless environments.
  • Configure and manage cloud-native security tools, firewalls, and WAFs to protect applications and networks.
  • Harden operating systems, networks, and applications using industry standards such as CIS Benchmarks.
  • Conduct regular vulnerability assessments and support remediation efforts for cloud and datacenter assets.
  • Manage and enhance key and secrets management tools (e.g., HSM, KMS, Azure Key Vault).
  • Automate security processes using scripting languages like Python, PowerShell, or Ansible.
  • Assist in the development and enforcement of security policies, procedures, and best practices.
  • Implement cloud and server security standards and configurations.
  • Support cloud hosting environment monitoring using asset and configuration management tools to ensure comprehensive coverage.
  • Participate in security incident response processes, including investigation and root cause analysis of hosting-related incidents.
  • Stay up-to-date with the latest threats, vulnerabilities, and security technologies, and recommend improvements / new approaches to the security posture.
Requirements and Skills:
  • Bachelor’s degree in Computer Science, Information Security, or a related field (or equivalent work experience).
  • 5+ years of hands-on experience in information security, with a focus on cloud and datacenter hosting environments.
  • Strong knowledge of cloud platforms (AWS, Azure) and their security configurations.
  • Experience with cloud-native security tools and frameworks, such as IAM, WAFs, and security monitoring solutions.
  • Hands-on experience with EDR/XDR platforms (e.g., CrowdStrike, Microsoft Defender for Endpoint, SentinelOne), including policy configuration and feature enablement
  • Ability to evaluate, test, and roll out new EDR/XDR functionalities in a production environment.
  • Familiarity with hardening techniques for operating systems (Windows, Linux), networks, and applications.
  • Experience with key and secrets management tools and processes.
  • Knowledge of scripting languages like Python, PowerShell, or Ansible for automating security tasks.
  • Understanding of security frameworks such as CIS, NIST, or ISO 27001.
  • Strong analytical and troubleshooting skills, with the ability to assess risks and recommend mitigation strategies.
  • Excellent communication and collaboration skills for working with cross-functional teams.
Preferred Qualifications:
  • Relevant certifications such as AWS Certified Security Specialty, Microsoft Certified: Azure Security Engineer, or equivalent.
  • Experience in regulated environments (e.g., SOC2, PCI, HIPAA).
  • Familiarity with containerization security (e.g., Docker, Kubernetes).
  • Experience securing AI/ML environments, including protecting training data, securing AI models, and mitigating AI-specific threats such as model poisoning or prompt injection.
  • Hands-on involvement in implementing and improving Secure Software Development Life Cycle (SSDLC) practices, including integrating security reviews and testing into CI/CD pipelines
Why Join Us?
  • Work on cutting-edge technologies in a collaborative and forward-thinking environment.
  • Play a key role in securing mission-critical infrastructure and applications.
  • Grow your career with opportunities for learning, certification, and professional development.
Benefits and Perks
All around awesome culture where together we strive to live our 5 values:
  • Data informed decision making.
  • Customer first. Always.
  • Succeed together.
  • Relentless about results. Obsessed with excellence.
  • Lead the change. Shape the standard.
An open and inclusive environment where you’ll learn and grow through programs and resources like:
  • Monthly company All Hands meetings
  • Regular opportunities for executive leadership exposure through things like AMAs
  • Access to continued learning & development opportunities
  • Our commitment to a continuous feedback culture which allows us to drive performance and career growth
  • A growing network of Employee Resource Groups
  • Company sponsored volunteer hours
  • And more!
Our more standard benefits:
  • 15 paid Romania public holidays + 2 additional Payscale holidays (Global Mental Health Day & US Independence Day)
  • 25 paid days of additional leave
  • Supplemental medical covered by Payscale for employees
  • Employees can add supplemental for family/spouse/dependents at their own expense
  • Additional days of per RO Labor Code that are not included in holidays & additional leave days
Equal Opportunity Employer
We embrace equal employment opportunity. Payscale is committed to a policy of equal employment opportunity for all applicants and employees. It is our policy that employees will not be subjected to unlawful discrimination on the basis of race, color, religion, sex, age, national origin, or ancestry, physical or mental disability, veteran or military status, marital status, sexual orientation, political ideology, and any other basis protected by federal, state, or local laws. This policy applies to all terms and conditions of employment, including but not limited to: recruitment, hiring, transfers, promotions, training, discipline, termination, compensation and benefits, performance appraisals, education, and social and recreational programs.
We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates, so please don’t hesitate to apply — we’d love to hear from you.
If you have a disability or impairment and need assistance with the application process, please email [email protected] for support.
Fraud Alert
Payscale values security and privacy. During your job application and interview process, we will never ask for your personal banking or financial information, social security number, or other sensitive information, if you are unsure if a message is from Payscale, please email [email protected].