Original listing text, shown exactly as published by the company.
Key Responsibilities
- Conduct a full AWS security posture assessment - IAM, S3 bucket policies, VPC security groups, exposed endpoints, and logging gaps - and deliver a prioritized remediation roadmap
- Activate and tune AWS Security tools across all accounts and regions
- Enforce least-privilege IAM - eliminate wildcard permissions, audit all existing roles, and implement role-based access patterns
- Enable AWS Config Rules and automated remediation for common misconfigurations - public S3 buckets, unencrypted volumes, unrestricted security groups
- Design and implement a secrets management strategy
- Establish a vulnerability management program for cloud workloads
- Own cloud infrastructure incident response - detection, triage, containment, and post-incident review
- Implement DLP policies - data classification, external sharing controls, and external forwarding restrictions
- Manage and mature the Zero Trust / VPN solution
- Own SIEM selection and deployment; configure alerting and on-call
- Implement phishing-resistant MFA (hardware keys or passkeys) for privileged accounts
- Conduct annual security awareness training and quarterly phishing simulations
- Maintain security policies: Acceptable Use, Access Control, Incident Response, Vulnerability Management, and Data Classification
- Own SOC 2 Type II continuous compliance and conduct a controls gap assessment
- Partner with Engineering to implement security controls in the SDLC - SAST, dependency scanning, and secrets detection in CI/CD pipelines
- Own the vendor security review process - evaluate third-party tools for risk before procurement
- Maintain a risk register and report quarterly
- Build and own the Incident Response Plan - define severity levels, escalation paths, and communication templates
Qualifications
- 5–8 years of security engineering experience with a strong AWS focus
- Hands-on experience with AWS security services - GuardDuty, Security Hub, CloudTrail, Config, IAM, and Service Control Policies
- Demonstrated SOC 2 or ISO 27001 readiness experience - ideally as primary technical lead
- Proficiency in at least one SIEM platform - Splunk, Elastic, Panther, or equivalent
- Scripting/automation ability in Python or Bash
- Google Workspace security and administration experience
- Strong written communication - security policies, runbooks, and executive summaries
Preferred Skills
- Relevant certifications: AWS Security Specialty, CISSP, CCSP, or CISM
- Experience with IaC security scanning (Checkov, tfsec) and CI/CD pipeline security integration
- Familiarity with compliance automation platforms such as Drata or Vanta
- Experience at a startup scaling from Series A to Series C
- Familiarity with network segmentation and OT/corporate network boundary design
BRINC Culture Values
- Try the hard stuff
- Be innovative - Invent the future
- Move fast
- Listen to end-users
- Strive for excellence
- Don’t build a dystopia
- Be frugal
- Save lives through technology
If you’re interested in this role and in joining BRINC, we hope you’ll apply. We’d love to review your application and get to know more about you!
BRINC is proud to be an equal opportunity employer that is resolute in cultivating an environment that promotes safety, diversity, inclusion and equity. We’re committed to hiring the best talent — regardless of race, creed, color, ancestry, religion, sex (including pregnancy), national origin, sexual orientation, age, citizenship status, marital status, disability, gender identity, genetic information, veteran status, or any other characteristic protected by applicable laws, regulations and ordinances — and empowering every employee so they can do their best work. If you have a disability or special need, please let our recruiting team know - we strive to provide appropriate accommodation and assistance.
Benefits and perks listed below may vary based on the nature of your employment with BRINC and/or the country within which you work
- Comprehensive medical, dental and vision plans for our employees and their families
- 401K plan
- Maternity and paternity leave
- Flexible Time Off (Exempt) / Paid time off (Non-Exempt)
- Flexible work environment
- Orca pass (for those in Puget Sound)…