Vertafore, Inc.

Information Security Engineer II

Vertafore, Inc.$110K — $135K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Master's degree in Cybersecurity, Computer Science, or related field OR equivalent experience (7+ years in security engineering or related field)
  • Security certifications such as AWS Security Specialty, Azure Security Engineer Associate, GCP Security Engineer are advantageous.
  • Strong knowledge of modern application architectures such as microservices, containers, and APIs.
  • Hands-on experience with AWS and Azure security services including IAM, Security Groups, KMS, WAF, and Defender for Cloud.
  • Proficiency in Python, Go, or PowerShell for automation purposes.

Responsibilities

  • Design and implement cloud security solutions focused on IAM, encryption, logging, and network segmentation.
  • Manage and optimize Web Application Firewalls (WAF) with custom rulesets for legacy applications.
  • Conduct detailed application security reviews and threat modeling.
  • Integrate security controls into CI/CD pipelines following a DevSecOps approach.
  • Develop and maintain security automation scripts using Infrastructure-as-Code tools like Terraform and Ansible.
  • Work with compliance teams to align security measures with SOC 2, ISO 27001, and other regulations.
  • Assess security risks and provide risk mitigation recommendations.

Benefits

  • Flexible First work environment allowing for a mix of in-office and remote work.
  • Medical, vision & dental plans with PPO and high-deductible options.
  • Health Savings Account & various Flexible Spending Accounts options.
  • 401(k) Retirement Savings Plan with employer match.
  • Education assistance including tuition reimbursement, legal assistance, and wellness programs.
  • Employee and Family Assistance Program (EFAP) available.
  • Paid parental leave and adoption assistance.
Full Job Description
$110,000 - $135,000/ annual

The Security Engineer II will play a critical role in designing, implementing, and optimizing security solutions for cloud-based and application security environments. This role focuses on advancing cloud security (AWS & Azure), securing APIs, and ensuring effective WAF deployment to protect both modern and legacy web applications.

Core Responsibilities:

- Architect and implement cloud security solutions in AWS and Azure, focusing on IAM, encryption, security logging, and network segmentation.

- Manage and optimize Web Application Firewalls (WAF), implementing custom rulesets and exception handling for legacy applications.

- Conduct in-depth application security reviews, threat modeling, and code assessments to identify vulnerabilities and enforce best practices.

- Design and integrate security controls into CI/CD pipelines, ensuring a DevSecOps-first approach.

- Develop and maintain security automation scripts and Infrastructure-as-Code (Terraform, Ansible, etc.).

- Work closely with compliance teams to align security measures with SOC 2, ISO 27001, and insurance industry regulations.

- Assess security risks in applications and cloud environments, providing recommendations that balance security with business needs.

- Support security audits and compliance initiatives by providing evidence and technical explanations for security controls.

- Act as an escalation point for Security Operations incidents and participate in an on-call Security Operations rotation every 4-6 weeks.

Knowledge, Skills, and Abilities:

- Strong knowledge of modern application architectures (microservices, containers, APIs) and their security implications.

- Hands-on experience with AWS and Azure security services, including IAM, Security Groups, KMS, WAF, and Defender for Cloud.

- Deep understanding of WAF tuning strategies for modern and legacy applications.

- Experience with securing APIs, container security (Docker, Kubernetes), and DevSecOps practices.

- Proficiency in Python, Go, or PowerShell for security automation.

- Strong ability to assess risks, propose mitigation strategies, and communicate technical security concepts to engineering teams.

Qualifications:

- Master's degree in Cybersecurity, Computer Science, or related field OR equivalent experience (7+ years in security engineering or related field).

- Security certifications are a plus (AWS Security Specialty, Azure Security Engineer Associate, GCP Security Engineer).
Skills & Requirements
Additional Requirements:

- Travel required up to 10% of the time outside of the assigned office.

- Occasional lifting and/or moving up to 10 pounds.

- Frequent repetitive hand and arm movements required to operate a computer.

- Specific vision abilities required for close vision (computer work, etc.).

- Frequent sitting and/or standing.

Is this role not an exact fit for you? Keep an eye on our Careers Page for other positions!

Why Vertafore is the place for you: *Canada Only
  • The opportunity to work in a space where modern technology meets a stable and vital industry
  • Medical, vision & dental plans
  • Life, AD&D
  • Short Term and Long Term Disability
  • Pension Plan & Employer Match
  • Maternity, Paternity and Parental Leave
  • Employee and Family Assistance Program (EFAP)
  • Education Assistance
  • Additional programs - Employee Referral and Internal Recognition


Why Vertafore is the place for you: *US Only
  • The opportunity to work in a space where modern technology meets a stable and vital industry
  • We have a Flexible First work environment! Our North America team members use our offices for collaboration, community and team-building, with members asked to sometimes come into an office and/or travel depending on job responsibilities. Other times, our teams work from home or a similar environment.
  • Medical, vision & dental plans
    • PPO & high-deductible options
  • Health Savings Account & Flexible Spending Accounts Options:
    • Health Care FSA
    • Dental & Vision FSA
    • Dependent Care FSA
    • Commuter FSA
  • Life, AD&D (Basic & Supplemental), and Disability
  • 401(k) Retirement Savings Plain & Employer Match
  • Supplemental Plans - Pet insurance, Hospital Indemnity, and Accident Insurance
  • Parental Leave & Adoption Assistance
  • Employee Assistance Program (EAP)
  • Education & Legal Assistance
  • Additional programs - Tuition Reimbursement, Employee Referral, Internal Recognition, and Wellness
  • Commuter Benefits (Denver)


The Professional Services (PS) and Customer Success (CX) bonus plans are a quarterly monetary bonus plan based upon individual and practice performance against specific business metrics. Eligibility is determined by several factors including: start date, good standing in the company, and actives status at time of payout.

The Vertafore Incentive Plan (VIP) is an annual monetary bonus for eligible employees based on both individual and company performance. Eligibility is determined by several factors including: start date, good standing in the company, and actives status at time of payout.

Commission plans are tailored to each sales role but common components include quota, MBO's and ABPMs. Salespeople receive their formal compensation plan within 30 days of hire.

About Vertafore, Inc.

Vertafore, Inc. is a software company that provides insurance technology solutions. The company was founded in 1969 and is headquartered in Bothell, Washington. Vertafore operates in the technology sector and has a workforce of over 1700 employees. The company's products and services are designed to help insurance agencies and carriers manage their operations more efficiently. Vertafore's solutions include agency management, rating and connectivity, content management, and compliance and licensing. The company has a strong presence in the United States and serves over 20,000 customers.
Learn more about Vertafore, Inc.
Size
1,700 employees
Industry
Founded
1969

Similar Jobs

More Jobs at Vertafore, Inc.

More Information Technology Jobs

Find similar Information Security Engineer II jobs: