StarCompliance is seeking an Information Security Engineer to support the day-to-day operation of the company’s information security program. This role involves working closely with cross-functional partners to protect systems, data, and customers while enhancing security operations and compliance.
Responsibilities:
- Support the implementation and maintenance of information security policies, standards, and procedures
- Experience of monitoring tools security tools, alerts, and logs: SIEM Platforms
- Experience of EDR tools
- Support incident response activities, including documentation, evidence collection, and post-incident reporting
- Assist with third-party vendor security reviews and risk assessments
- Help prepare documentation and evidence for audits, customer security questionnaires, and compliance reviews
- Maintain security registers, risk logs, and control documentation
- Support employee security awareness initiatives and training programs
- Participate in continuous improvement of security processes and controls
- Produce reports for internal and external stakeholders
Requirements:
- Support the implementation and maintenance of information security policies, standards, and procedures
- Experience of monitoring tools security tools, alerts, and logs: SIEM Platforms
- Experience of EDR tools
- Support incident response activities, including documentation, evidence collection, and post-incident reporting
- Assist with third-party vendor security reviews and risk assessments
- Help prepare documentation and evidence for audits, customer security questionnaires, and compliance reviews
- Maintain security registers, risk logs, and control documentation
- Support employee security awareness initiatives and training programs
- Participate in continuous improvement of security processes and controls
- Produce reports for internal and external stakeholders
- Understanding of information security principles and risk management concepts
- Familiarity with cloud environments, SaaS applications, or enterprise IT systems
- Strong attention to detail with the ability to follow defined processes and document work clearly
- Ability to communicate effectively with technical and non-technical stakeholders
- Willingness to learn and take ownership of assigned tasks
- Strong organizational skills and ability to manage multiple priorities
- Degree in Cyber Security, Information Security, Computer Science, Information Technology, or a related field, or equivalent practical experience
- Integrity and Ethics
- CompTIA Security+
- BCS Foundation Certificate in Cyber Security
- ISO/IEC 27001 Foundation
- NCSC-aligned training or certifications