IDScan.net logo

Security Engineer

IDScan.net

On-siteNew Orleans, LAmidPosted 2h ago

Job description

Location: New Orleans, LA or remote (US) Reports to: Chief Information Security Officer Type: Full-time

About the role

You'd be joining at the start of a program to consolidate our security tooling and mature how we build software. You will help us fix, modernize, and streamline our auditing, vulnerability management, and securing the whole organization.

A DevSecOps Engineer joins alongside you to own identity, API and pipeline work. You'd own the defensive and assurance side.

What you'll own in the first year

Detection engineering. Manage our cloud native SIEM, design the log tiering, and write detections mapped to our actual control set. Own alert quality, a noisy queue is a broken control.

Vulnerability management. Stand up continuous scanning across all of our servers, our Azure configuration and our databases. Build a remediation SLA, measure against it, and report it monthly.

Compliance operations. Own our compliance automation platform end to end: control ownership, evidence collection, framework cross-mapping between SOC 2 and ISO 27001 so we collect each artifact once, and the personnel and access integrations that make joiner-leaver evidence automatic.

Asset inventory. Build an authoritative inventory and reconcile it until unknown assets reach zero.

Backup and recovery assurance. Own restore testing on a schedule. Not backup jobs succeeding, actual documented restores within our stated recovery objective.

Incident response. Help build the new runbooks so we are ready if the worst day ever comes.

What we're looking for

3+ years in security operations, detection engineering, or a blue-team role

Hands-on SIEM experience: you've written detection logic, tuned it, and killed rules that produced noise

Azure or comparable cloud security experience, cloud posture, workload protection, identity logs

Vulnerability management in practice: scanning, prioritization that accounts for exploitability rather than CVSS alone, and the harder work of driving remediation you don't control

Query and scripting fluency: KQL, SQL, Python or PowerShell

Direct SOC 2 or ISO 27001 experience, ideally including sitting in front of an auditor

Clear written communication. A large part of this job is producing evidence and explanations other people rely on

Nice to have

Compliance automation platform experience (Drata, Vanta, Scrut, Sprinto or similar)

Threat modeling or purple-team exercises

Experience with a SaaS product environment and its customer-facing security obligations

Security certifications are welcome but we care more about what you've operated

What this job is not

It isn't a SOC analyst seat watching a queue someone else built. You'd be building the queue, deciding what belongs in it, and being accountable for what it misses.

It also isn't purely technical. A real share of the work is compliance operations, and if evidence collection sounds beneath you, this will frustrate you. The best people in this role understand that provable security and actual security are different problems that both need solving.

We'd rather you tell us something is a bad idea than implement it quietly. That includes telling the CISO.

What we offer

Ownership of tooling decisions rather than inheriting them

Budget for training and certification

A small team where your work is visible

We're an equal opportunity employer. If you meet most of this and not all of it, apply anyway โ€” we'd rather read your application than guess.

About IDScan.net

IDScan.net is an identity verification technology leader, and provider of software based solutions for ID fraud prevention, document authentication, age verification, and access management. Our software centers on the identity document (ID or passport) and uses AI and machine learning to flag fraudulent documents with a high degree of accuracy. IDScan.net is a growth-focused SaaS company who provides licenses and subscriptions to software products. We pride ourselves on our customer service and flexible approach to meeting client needs.