I

Information Security Engineer III

InComm Payments

Remote · Full Time

Be the first to apply

Experience
Any
Salary
—
Openings
1
Posted
1 day ago
Work mode
Work from home
Resume
Required to apply

Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.

Job description

Company Overview

InComm Payments is a pioneer in innovative payment technology with over 30 years of experience in the FinTech industry. The company boasts a global presence with more than 3,000 employees in 35 countries, owning over 400 technical patents and operating a vast network of more than 525,000 retail distribution points. InComm partners with leading global merchants and values its employees' growth, fostering a culture centered on innovation, quality, passion, integrity, and responsibility.

Role Summary

The Information Security Engineer III will be responsible for securing InComm's applications by embedding security solutions into CI/CD pipelines, conducting threat modeling, supporting incident response, and leading security initiatives. The ideal candidate will have 5+ years of application security expertise and be proficient with scripting, cloud security across Azure, AWS, and OCI, and various security testing tools.

Key Responsibilities

  • Implement and integrate SAST tools within CI/CD workflows, ensuring seamless compatibility and efficient scanning.
  • Support development teams of varying maturity levels by customizing SAST integrations to meet their distinct toolsets and security needs.
  • Analyze application logs for unusual activities, report findings to leadership, and advocate for necessary actions.
  • Participate in on-call rotations to support Web Application Firewall (WAF) incident response.
  • Validate vulnerabilities identified by automated tools, tuning configurations to reduce false alarms and noise.
  • Create threat models collaboratively with development teams to identify and mitigate risks.
  • Evaluate security configurations and controls regularly across Azure, AWS, and OCI cloud platforms.
  • Assist the Cyber Security Operations Center (CSOC) in investigating security incidents and executing corrective measures.
  • Engage in design and architectural reviews of applications to ensure security compliance.
  • Organize and lead security exercises such as blue/red team events and bug bounty initiatives.
  • Drive prioritization of critical security issues through effective discussions and collaboration.
  • Liaise with external vendors conducting vulnerability scans and penetration tests to verify findings and set remediation priorities.
  • Develop, assess, and monitor adherence to application and development security standards.
  • Ensure development teams incorporate OWASP Top 10 guidelines and apply leading industry application security practices.

Qualifications and Skills

  • Minimum 5 years’ experience in application security.
  • Proficient with CI/CD tooling such as Jenkins, GitHub Actions, Azure Pipelines, or equivalents.
  • Strong scripting skills in PowerShell, Python, or similar languages.
  • Deep familiarity with SAST and DAST tools and OWASP security methodologies.
  • Hands-on experience with high-level programming languages including Java, C, C++, C#, VB, .NET, ASP.NET, ASP, PHP, J2EE, JSP.
  • Experience with container technologies like Docker, Docker Swarm, and Kubernetes.
  • Cloud security expertise in Azure, AWS, and OCI, particularly in multi-cloud environments within FinTech or related sectors.
  • Knowledge of Web Application Firewalls (WAF) and Identity and Access Management protocols (SAML, OpenID, OAuth).
  • Skilled in manual penetration testing of web, API, and mobile applications; preparing detailed reports and communicating findings effectively.
  • Understanding of regulatory requirements and industry best practices such as HIPAA, PCI, HiTrust, and NIST.
  • Strong communication skills for developing documentation, training materials, and conducting training sessions.
  • Ability to manage multiple responsibilities and meet deadlines in a virtual work setting.
  • Capability to collaborate effectively with IT teams on security projects and maintain up-to-date knowledge of emerging technologies.

Diversity and Equal Opportunity

InComm offers equal employment opportunities without discrimination based on race, color, religion, gender, sexual orientation, gender identity, national origin, citizenship, veteran status, age, disability, genetics, or any other protected category defined by law.

Additional Information

  • This role is eligible for the Employee Referral Bonus Program Tier III.

Industry

FinTech

Tools & software

Docker required Kubernetes required

How they work

Communication Teamwork & Collaboration Time Management

Leave it if you'd like a reply — we won't use it for anything else.

Click to browse, drag & drop, or paste a screenshot

PNG, JPG, GIF, MP4, WebM, MOV · Max 20MB each · Up to 5 files

🤖
Online · instant AI help
Broxer