Information Security Engineer

1 week ago


Atlanta, United States Brightwell Full time

What We Do Brightwell is a pioneering payments company dedicated to providing innovative solutions and technology for global money transfers while navigating the intricate landscape of regulatory requirements. Through strategic partnerships and technological advancements, Brightwell facilitates cross-border payments, offering a range of options including bank transfers, mobile wallets, and cash transactions, empowering businesses and individuals to seamlessly manage and move money worldwide.  Who We Need We're searching for a senior Information Security Engineer to play a key role in our security and compliance programs. You'll balance hands-on security engineering with compliance program management, working closely with our Chief Compliance Officer and General Counsel on risk decisions and audit matters.  You'll lead SOC2 Type II and PCI DSS program execution (~50% of your time) while conducting security assessments, penetration testing, and vulnerability management across our applications and Azure infrastructure (~50% of your time). You should be the security subject matter expert who can independently drive programs while partnering with our CCO on compliance strategy.  This role is perfect for a seasoned security professional who thrives at balancing compliance rigor with hands-on security work.  You'll write control narratives for auditors in the morning and pentest APIs in the afternoon. Reporting to the VP of Engineering within IT Operations, you'll have direct access to our Chief Compliance Officer and General Counsel for compliance matters and risk decisions.    **This is a HYBRID position based in Atlanta, GA. Candidates will be expected in the office a minimum of two days per week.    What You’ll Do SOC2 & PCI Compliance Programs (~50%):   Own SOC2 Type II program execution including control design, audit preparation, and evidence collection in partnership with our Chief Compliance Officer  Develop and maintain information security policies, procedures, and control narratives aligned with SOC2 Trust Services Criteria and PCI DSS requirements  Lead risk assessments and security audits, ensuring documentation meets industry and regulatory requirements  Create and maintain technical documentation (network diagrams, system architecture, data flows) and conduct internal control testing  Serve as primary technical liaison with external auditors and manage PCI vulnerability scans and penetration testing  Application & Infrastructure Security (~50%):  Conduct threat modeling, security assessments, and penetration testing of Azure-based applications and APIs, including code reviews focused on authentication, authorization, and data protection  Review, validate, and design security controls across Azure infrastructure, including Network Security Groups, firewalls, Azure AD/Entra ID, and Key Vault  Manage and optimize security tools (endpoint protection, SIEM, vulnerability scanners, automated testing platforms) and coordinate continuous vulnerability scanning and remediation with development and infrastructure teams  Investigate and respond to security incidents with root cause analysis and implement preventive measures  Partner with DevOps to integrate security into CI/CD pipelines  Evaluate and implement new security and automation technologies  Provide security training and guidance to promote a strong security culture  As an Information Security Engineer, you have Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience)   7+ years of hands-on information security experience, preferably in financial services or highly regulated environments  Proven experience managing SOC2 Type II and PCI DSS compliance programs, including control design, policy development, and audit coordination  Strong technical skills in penetration testing, vulnerability assessments, and security code reviews  Experience with Azure security (Network Security Groups, Azure AD, Key Vault, Security Center) and security tooling (SIEM, vulnerability scanners, endpoint protection)  Experience investigating and responding to security incidents with strong analytical and problem-solving skills  Excellent communication skills with the ability to explain technical security concepts to both technical and non-technical stakeholders  Proven ability to work independently as a security subject matter expert  Security certifications (CISSP, OSCP, CEH, GIAC, or Azure Security) are preferred but not required  What We’re Offering in Return  Empowered Work: Own your work and grow your career with real autonomy and impact  Hybrid Flexibility: 3 days remote, 2 days in our Atlanta office at the Battery  Global Impact: Join a passionate team building mission-critical tools for people around the world  Great Benefits: Medical, dental, vision, disability, 401(k), paid parental leave, PTO, and more  Supportive Environment: Thrive in a collaborative, inclusive workplace that values innovation and continuous learning      Brightwell is an equal opportunity employer (EOE) committed to employing a diverse workforce and sustaining an inclusive culture.  Powered by JazzHR



  • Atlanta, United States Franklin Fitch Full time

    Infosec Engineer - GRC FocusHybrid - Atlanta, GAContract - 6-month + extensionsWe're looking for a hands-on Information Security Engineer with deep GRC expertise to join a leading financial organization. This role combines technical security engineering with governance, risk, and compliance, supporting enterprise-wide compliance initiatives and automation...


  • Atlanta, United States Franklin Fitch Full time

    Infosec Engineer - GRC FocusHybrid - Atlanta, GAContract - 6-month + extensionsWe’re looking for a hands-on Information Security Engineer with deep GRC expertise to join a leading financial organization. This role combines technical security engineering with governance, risk, and compliance, supporting enterprise-wide compliance initiatives and automation...


  • Atlanta, United States Brightwell Full time

    Company Overview Brightwell is a pioneering payments company dedicated to providing innovative solutions and technology for global money transfers while navigating the intricate landscape of regulatory requirements. Through strategic partnerships and technological advancements, Brightwell facilitates cross‑border payments, offering a range of options...


  • Atlanta, GA, United States Brightwell Full time

    What We Do Brightwell is a pioneering payments company dedicated to providing innovative solutions and technology for global money transfers while navigating the intricate landscape of regulatory requirements. Through strategic partnerships and technological advancements, Brightwell facilitates cross-border payments, offering a range of options including...


  • Atlanta, GA, United States Brightwell Full time

    What We Do Brightwell is a pioneering payments company dedicated to providing innovative solutions and technology for global money transfers while navigating the intricate landscape of regulatory requirements. Through strategic partnerships and technological advancements, Brightwell facilitates cross-border payments, offering a range of options including...


  • Atlanta, GA, United States Brightwell Full time

    What We Do Brightwell is a pioneering payments company dedicated to providing innovative solutions and technology for global money transfers while navigating the intricate landscape of regulatory requirements. Through strategic partnerships and technological advancements, Brightwell facilitates cross-border payments, offering a range of options including...


  • Atlanta, GA, United States Brightwell Full time

    What We Do Brightwell is a pioneering payments company dedicated to providing innovative solutions and technology for global money transfers while navigating the intricate landscape of regulatory requirements. Through strategic partnerships and technological advancements, Brightwell facilitates cross-border payments, offering a range of options including...


  • Atlanta, United States MerchantE Full time

    Essential Duties and Responsibilities:Working with security tools and API integration work including writing scripts and development of automation around detection and remediation activities.Given the growing nature of the organization, you will work closely with other internal and external groups and may also assist in other security activities as necessary...


  • Atlanta, United States MerchantE Full time

    Essential Duties and Responsibilities:Working with security tools and API integration work including writing scripts and development of automation around detection and remediation activities.Given the growing nature of the organization, you will work closely with other internal and external groups and may also assist in other security activities as necessary...


  • Atlanta, United States Tata Consultancy Services Full time

    Experience in many of the following areas: Experience with incident management, problem management, and change management Interacting with development teams to articulate security requirements and processes while collaborating on architecture and engineering design options, implementation, testing, and user acceptance. ·Strong proficiency with common...