Cape logo

Security Engineer (Corporate Security)

Cape

On-siteUnited States {{REMOTE}}entry$200k–$255kPosted 2d ago

Job description

  • We are seeking an experienced Security Engineer with expertise in corporate security to join our team

  • As a strategic partner, you will make an immediate impact by leveraging your expertise across identity, endpoint, network, and information security alongside IT, engineering, and business teams

  • This role is pivotal in reducing risk across our corporate environment, covering employee-facing systems, internal infrastructure, and third-party risk, and will be responsible for designing, implementing, and maintaining security measures that comply with regulatory standards, enhance internal processes, and minimize data security risks

  • Through developing ongoing security strategies, technologies, and a strong security culture, you will support the organization’s business objectives and daily operations

  • Design, implement, and manage security controls and policies across corporate IT systems, focusing on the confidentiality, integrity, and availability of employee, customer, and business data

  • Own and mature identity and access management (IAM/SSO/MFA), endpoint security (EDR, MDM), and email/network security (phishing defense, DLP, firewalls, VPN) across the organization

  • Perform comprehensive security assessments of corporate systems and vendors to identify vulnerabilities, assess risk, and recommend actionable mitigation strategies

  • Establish governance, guardrails, and monitoring for emerging employee tooling, including the associated data-handling, access, and third-party risks

  • Own the vulnerability management lifecycle across the corporate fleet: scanning, risk-based prioritization, remediation and patch SLAs, and closure tracking across endpoints and internal systems

  • Lead security awareness and phishing simulation programs to build an organization-wide culture of security

  • Contribute to compliance and audit efforts as needed, lending security context where it helps the business move faster

  • Assess and manage third-party/vendor security risk, including security questionnaires, contract reviews, and ongoing vendor monitoring

  • Assist in running and addressing findings from penetration tests, red team exercises, and internal audits, ensuring prompt and effective remediation

  • Stay informed about the latest security threats, vulnerabilities, and compliance mandates affecting corporate environments; provide strategic guidance on technologies and best practices

  • Investigate security incidents and insider-threat concerns in partnership with HR, Legal, and IT as needed

  • Raise the security bar across the company by mentoring engineers and partners on secure practices, fostering a culture of security awareness and continuous improvement

  • Collaborate with stakeholders to integrate security requirements effectively into IT projects and broader business initiatives

Benefits

  • Commuter benefits

  • Disability insurance

  • Medical insurance

  • Vision insurance

  • 401(k)

  • Dental insurance

  • Paid maternity leave

  • Paid paternity leave- Exposure to secure software development lifecycle (SSDLC) practices and partnering with engineering on secure design reviews

  • Familiarity with vendor/third-party risk management processes and tooling

  • Bachelor’s degree in Computer Science, Information Security, or a related field or equivalent experience. Advanced degrees or certifications (e.g., CISSP, GIAC, Security+, CISM) are advantageous

  • Strong communication and leadership abilities, capable of working collaboratively across teams and effectively conveying technical information to non-technical stakeholders

  • Working knowledge of consumer privacy regulations (GDPR, CCPA, and other regional privacy laws) as they apply to handling customer data

  • Solid knowledge of network security, encryption technologies, and secure business-system configuration

  • Deep understanding of enterprise identity providers and SSO/MFA platforms, endpoint/EDR tooling, MDM platforms, and email security tooling

  • Excellent analytical skills for identifying and mitigating complex security vulnerabilities and risks

  • Familiarity with government/public-sector security frameworks (FedRAMP, FISMA, NIST SP 800 series, CJIS) is a plus, given Cape’s government-facing customer base

  • Proficiency in scripting or automation (Python, shell scripting, or similar) to streamline security operations and reporting

  • A minimum of 2 years of experience in information security, with meaningful experience across corporate/IT security domains (identity, endpoint, network, GRC)

  • Organized and able to manage multiple priorities in a dynamic, fast-paced environment

  • Working knowledge of common compliance frameworks (e.g., SOC 2, ISO 27001)

  • Respect The Opportunity (each other, the user)

  • Do Excellent Work

  • Planning & Organization – Manages multiple projects, determines project urgency in a meaningful and practical way, uses goals to guide actions, creates detailed action plans, and organizes tasks

  • Communication – Presents information through verbal and written communication; reads and interprets complex information; listens well. Develops and delivers multi-mode communications that convey clear understanding of unique audiences

  • Analytical – Collects data and information; uses critical thinking to solve problems and make sound decisions

  • Decision-Making – Acts quickly to solve problems and exercises good judgment by making sound and well-informed decisions. Perceives the impact and implications of decisions; makes effective and timely decisions, even when data is limited

  • Flexibility / Adaptability – Adjusts quickly to changing priorities, conditions, and challenges. Copes effectively with complexity and change. Is comfortable navigating ambiguity. Can handle business changes with ease and without frustration or a feeling of defeat. Feels comfortable dealing with limited unknowns in an area they are well versed in

  • Customer Centric – Values the importance of delivering high quality, innovative service to employees; understands the needs of the client; responds promptly and is accessible to them; follows through on commitments in a timely manner; maintains positive, long-term working relationships; assumes ownership of process issues and takes appropriate steps to mitigate problems. Gets consistently high feedback from stakeholders. Raises hand to help

  • Collaboration & Teamwork – Builds partnerships with others to reach common goals. Able to share credit with coworkers, display enthusiasm and promote a friendly group-working environment. Works closely with other departments as necessary, supports group decisions and solicits opinions from coworkers

  • Dependability/Self-Management – Possesses the personal discipline and diligence necessary to keep commitments and to complete tasks. Is accountable for actions and outcomes. Makes effort to improve situations without explicit instructions; a self-starter who consciously manages his/her own time and resources

  • Bias Towards Action

  • Security Expertise – Experience identifying and resolving security issues across corporate systems (identity, endpoint, network, and data). Secure-by-design principles, and partnering with IT/engineering during design time

  • Overshare- Click the link below to apply