Apply Description Dizzion is seeking an experienced and proactive Security Engineer III to own and strengthen the day-to-day security posture of our cloud infrastructure, customer environments, and internal systems. This role carries hands-on accountability for identifying and addressing security risks, leading security incident response, driving vulnerability remediation, maintaining security controls, supporting compliance readiness, and continuously improving Dizzion's security program. The Security Engineer III will work closely with Engineering, Product, Support, Compliance, Operations, and external technology partners. This is a senior individual contributor role for someone who can operate independently, exercise sound judgment, take ownership of security issues from identification through resolution, and translate security requirements into practical, measurable outcomes. This role is also accountable for defined security KPIs, SLAs, scorecard metrics, and reporting. The successful candidate will not simply identify security issues, but will establish clear ownership, drive remediation, measure results, and communicate security performance and risk to company leadership. Given the nature of Dizzion's business and the customers we serve, this role requires strong attention to detail, self-direction, disciplined execution, and excellent communication. Responsibilities Security Operations & Infrastructure • Own the monitoring and maintenance of security controls across Dizzion's cloud and corporate environments. • Configure, administer, and continuously improve security technologies including SIEM, firewalls, IDS/IPS, WAF, endpoint protection, vulnerability management, and identity and access management tools. • Identify security gaps, assess business impact, and proactively drive improvements to strengthen Dizzion's security posture. • Own infrastructure hardening and secure configuration initiatives across cloud and production environments. • Partner with Engineering and IT to incorporate security best practices into infrastructure and application environments. • Establish and monitor operational security standards, including documented SOPs and SLAs, and ensure performance against those standards. Incident Response & Threat Management • Own the full incident response lifecycle, including detection, investigation, triage, containment, remediation, recovery, and post-incident review. • Lead security incident response activities and coordinate internal teams and external partners as appropriate. • Maintain and continuously improve security incident response playbooks, SOPs, runbooks, and escalation procedures. • Perform root cause analysis and ensure corrective and preventative actions are assigned, tracked, and completed. • Monitor emerging threats and assess their potential impact to Dizzion and its customers. • Establish and report incident response metrics, including response times, remediation timelines, recurring issues, and completion of post-incident actions. • Communicate clearly and consistently during security events, including status, impact, actions taken, risks, and next steps. Vulnerability & Risk Management • Own Dizzion's vulnerability management process across infrastructure, applications, endpoints, and cloud environments. • Evaluate and prioritize vulnerabilities based on severity, exploitability, business impact, customer risk, and applicable compliance requirements. • Drive remediation with Engineering, IT, and other internal teams and maintain clear ownership through resolution. • Track remediation against established SLAs, monitor aging vulnerabilities, and escalate risks when deadlines or requirements are not met. • Maintain accurate documentation of vulnerabilities, remediation activities, exceptions, and risk acceptance. • Establish and report vulnerability KPIs, including remediation performance, critical and high-risk exposure, aging, backlog, and SLA compliance. Security Engineering, Automation & Continuous Improvement • Implement and improve security controls across cloud and corporate environments. • Identify opportunities to automate repetitive security processes and improve operational efficiency, visibility, and response times. • Develop scripts, tooling, and integrations that improve security monitoring, reporting, and response. • Participate in security architecture reviews and secure implementation of new technologies. • Evaluate security tools and technologies and make recommendations based on business and technical requirements. • Maintain a security roadmap and track delivery of priority security initiatives against agreed timelines and KPIs. Vendor & Platform Security Coordination • Work closely with Omnissa on platform releases, security updates, vulnerabilities, and required remediation activities. • Coordinate with internal teams to assess the security implications of platform and infrastructure changes. • Partner with Product and Engineering to map security requirements and identified risks to the product roadmap. • Support vendor security reviews and ensure security requirements are incorporated into technology evaluations and ongoing vendor relationships. • Maintain clear documentation and follow-up on vendor-related security issues, commitments, remediation timelines, and SLAs. • Maintain visibility into third-party security risks and ensure appropriate actions are tracked to completion. Compliance & Security Assurance • Own day-to-day technical support for Dizzion's security and compliance programs, including SOC 2, HIPAA, PCI-DSS, GDPR, and other applicable requirements. • Maintain security policies, procedures, evidence, and technical documentation required for audits and compliance activities. • Coordinate technical evidence collection and respond to internal and external audit requests. • Identify gaps between security controls and compliance requirements and drive remediation with responsible teams. • Monitor compliance-related security actions and ensure commitments are completed within established timelines. • Maintain readiness for recurring audits and assessments rather than treating compliance as a point-in-time exercise. Security KPIs, Scorecard & Reporting • Own the security scorecard and maintain clear, accurate reporting on the health and performance of the security program. • Define, track, and report agreed security KPIs and operational metrics to Engineering leadership and other stakeholders. • Establish meaningful measures across incident response, vulnerability management, remediation SLAs, compliance readiness, security control coverage, and security initiatives. • Identify trends, risks, and recurring issues in security metrics and translate findings into actionable recommendations. • Escalate material risks and performance gaps with clear context, ownership, and recommended next steps. • Use metrics to prioritize security work and demonstrate measurable improvement over time. Cross Functional Partnership • Work closely with Engineering, Product, Support, Operations, Compliance, and other internal teams to identify and address security risks. • Serve as a senior security resource for technical teams and provide practical guidance on secure design and implementation. • Communicate technical security concepts, risk, and business impact clearly to both technical and non-technical stakeholders. • Build strong working relationships across teams to ensure security issues are addressed quickly and effectively. • Establish clear ownership and follow-through for cross-functional security actions. • Contribute to a culture of accountability, continuous improvement, and shared responsibility for security. Requirements • 5-8 years of experience in security engineering, cybersecurity, infrastructure security, or a related technical discipline. • Experience working in a cloud-based or SaaS environment. • Demonstrated hands-on experience owning security monitoring, vulnerability management, incident response, and security controls. • Working knowledge of cloud security principles across AWS, Azure, or GCP. • Experience with security technologies such as SIEM, firewalls, IDS/IPS, WAF, endpoint protection, vulnerability scanners, or IAM. • Strong understanding of common security threats, attack techniques, and mitigation strategies. • Demonstrated ability to work independently, prioritize competing risks, and take ownership through resolution. • Demonstrated experience tracking work against defined SLAs, KPIs, or operational metrics. • Strong written and verbal communication skills, including the ability to communicate security risk and status clearly to leadership. • Strong attention to detail and a disciplined approach to documentation, SOPs, SLAs, and follow-through. • Experience supporting security and compliance requirements in a regulated or compliance-focused environment. Preferred Qualifications Experience with one or more of the following: • Omnissa Horizon or VMware Horizon • AWS, Azure, or Google Cloud Platform • Kubernetes and container security • Infrastructure as Code, including Terraform or CloudFormation • Identity and Access Management • Security automation and orchestration • Threat intelligence or digital forensics • Python, PowerShell, Go, or similar scripting languages • MITRE ATT&CK framework • Zero Trust architecture • SOC 2, HIPAA, PCI-DSS, GDPR, or similar compliance frameworks Relevant certifications are a plus, including: • Security+ • CISSP • CCSP • CISM • AWS Security Specialty • Azure Security Engineer Associate • GIAC certifications Benefits • Comprehensive medical (including telehealth), dental, and vision plans • Employee Assistance Program • Employer-paid basic life insurance and AD&D • 401(k) retirement plan • Flexible paid time off. Work hard and take time when you need it. • Generous holiday schedule • Voluntary short and long-term disability • Collaborative teammates who enjoy solving challenging problems together Compensation Base salary $120,000-$130,000 annually. Salary will be determined by the education, experience, knowledge, skills, and abilities of the applicant, and alignment with applicable market data. Company Overview Dizzion drives productivity by delivering secure digital workspaces for the speed of modern business, allowing teams to log in to office platforms anywhere, anytime, and get to work. We ensure that IT workspaces remain scalable, costs stay predictable, and our managed services improve efficiency and mitigate risk. Dizzion digital workspace solutions are delivered as Cloud PC, App Streaming, Multi-Session, and DaaS. Dizzion was founded in 2011. For more information, please visit Dizzion.com. Dizzion is an Equal Opportunity Employer and does not discriminate against any employee or applicant based on race, creed, color, sex, gender identity, sexual orientation, national origin, age, religion, disability, veteran status, or any other characteristic protected by applicable federal, state, or local law. This position is full-time FLSA exempt.
Software Engineer, Product Security - Security Automation (Remote)
Crowdstrike
Senior Security Engineer - Enterprise Security Engineering
Aurora
Senior Security Engineer
Thehartford
Cloud Security Engineer
Gotyto
ISSM / Security Automation Engineer
Gotyto
Senior Information Security Engineer
Asrcfh