Keeper Security

Information Security Engineer

Keeper Security
Apply
3 months ago
Remote, United StatesSenior

Responsibilities

  • Support incident response activities including triage, investigation, containment coordination, lessons learned, and corrective action tracking.
  • Develop and maintain incident response playbooks, runbooks, and escalation paths, and participate in tabletop exercises.
  • Operate and improve endpoint, SaaS, email, access control, and other enterprise security controls and tooling.
  • Partner with Observability Engineering to ensure security telemetry supports investigations without owning SIEM or telemetry platform administration.
  • Coordinate vulnerability remediation, validate fixes where appropriate, and reduce repeat findings through hardening and control improvements.
  • Coordinate investigations with DevOps, IT, and Engineering teams and track actions through closure.
  • Support access reviews, privileged access workflows, least-privilege initiatives, and secure authentication controls.
  • Maintain security process, control, and operational documentation across teams and geographies.
  • Assist with compliance evidence collection and operational readiness for SOC 2, ISO 27001, FedRAMP, GovRAMP, and NIST 800-53.
  • Identify and implement automation for ticketing workflows, control checks, integrations, and scripting.

Requirements

  • At least 5 years of experience in information security, security engineering, or security operations within a SaaS or cloud-centric environment.
  • Hands-on experience supporting incident response and investigations, including runbooks and post-incident reviews.
  • Experience implementing and operating security controls across endpoints, SaaS applications, and cloud environments.
  • Working knowledge of AWS, Azure, or GCP, as well as SSO, MFA, RBAC, and modern security practices.
  • Ability to collaborate with DevOps, Engineering, Observability, and Application Security teams to drive remediation and measurable risk reduction.
  • Familiarity with CVEs, vulnerability prioritization, and remediation tracking.
  • Strong documentation habits and an operational mindset focused on repeatability and auditability.
  • Must be a U.S. Person due to FedRAMP requirements.
  • Preferred: experience with FedRAMP, GovRAMP, SOC 2, ISO 27001, NIST 800-53, EDR, email security, SaaS security controls, identity security workflows, scripting and automation, APIs, detection engineering, threat intelligence, or SOAR-style automation.

Benefits

  • 100% remote position, with hybrid scheduling available for candidates in the El Dorado Hills, California or Chicago, Illinois metro areas.
  • Medical, dental, and vision insurance, including domestic partnerships.
  • Employer-paid life insurance and supplemental life insurance for employees, spouses, and children.
  • Voluntary short- and long-term disability insurance.
  • 401(k) retirement plan with Roth and traditional options.
  • Generous paid time off, including paid bereavement and jury duty leave.
  • Above-market annual bonuses.

Tech Stack

Categories

Keeper Security

About Keeper Security

501-1,000 employees

Keeper Security is transforming cybersecurity for millions of individuals and thousands of organizations globally. Built to protect against today’s threats and tomorrow’s challenges, our unified, cloud-native cybersecurity platform is trusted by Fortune 100 companies to protect every user, on every device, in every location. Keeper is a pioneer of zero-knowledge and zero-trust security built for any IT environment. Our core offering, KeeperPAM®, is an AI-enabled, cloud-native platform that protects all users, devices and infrastructure from cyber attacks. Recognized in the Gartner Magic Quadrant for Privileged Access Management (PAM), Keeper continues to lead in cybersecurity innovation, securing passwords and passkeys, infrastructure secrets, remote connections and endpoints with role-based enforcement policies, least privilege and just-in-time access. As threats evolve and environments scale, Keeper is redefining modern cybersecurity to deliver the visibility, control and intelligence organizations need to operate confidently and securely. Our security and compliance standards include: - The longest-standing SOC 2 and ISO 27001 certifications in the industry - FedRAMP and GovRAMP Authorization - FIPS 140-3 validation - SOC 3, PCI DSS and ISO 27001, 27017 and 27018 certification Learn more at keepersecurity.com.