freehire launches on Product Hunt on 26 August.

Follow →

Senior Information Security Engineer

Open 19d reposted 2× · 2 open copies

Summary

Senior Information Security Engineer at Five9 in Porto, Portugal, responsible for identifying, assessing, and managing security risks across cloud infrastructure and services while driving remediation and reporting risk posture to leadership.

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide.

Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves.

We are looking for a Senior Information Security Engineer to join our growing Security Risk Management team. The Security Risk Management team aims to expand beyond traditional risk management; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Five9 and our customers.

As a key contributor to the program the role supports the day-to-day execution of risk identification, assessment, treatment, and reporting across Five9's infrastructure, services, and acquisitions. You'll work directly with engineering, operations, and business stakeholders to surface security risks, drive them toward resolution, and maintain a clear picture of Five9's risk posture for leadership.

Key Responsibilities:

  • Identify, document, and assess security risks across Five9's environment, including production infrastructure, cloud services, corporate systems, and acquired platforms
  • Maintain the Security Risk Register in Jira, ensuring risks are accurately categorized, assigned to appropriate owners, and tracked through their lifecycle
  • Engage with service owners, engineering leads, and operations teams to establish risk ownership and drive remediation or mitigation plans
  • Facilitate the risk acceptance process, including preparing risk acceptance documentation and coordinating approval with appropriate stakeholders
  • Develop and deliver risk reporting for security leadership and executive audiences, including dashboards and metrics that communicate risk posture clearly
  • Collaborate with compliance, vulnerability management, and other Information Security functions to ensure risk findings are incorporated into the broader security program
  • Research and apply risk management frameworks and methodologies to continuously improve program maturity
  • Contribute to the development of risk management policies, procedures, and playbooks

Requirements:

  • 3+ years of experience in information security, with at least 2 years focused on security risk management or GRC
  • Demonstrated experience maintaining a security risk register and driving risk treatment decisions with cross-functional stakeholders
  • Strong understanding of risk assessment methodologies (qualitative and quantitative)
  • Familiarity with security frameworks such as NIST CSF, NIST 800-53, ISO 27001, PCI, or SOC 2
  • Ability to communicate security risks clearly to both technical and non-technical audiences
  • Experience with Jira or similar tools for tracking and managing risk workflows
  • Self-directed and comfortable engaging directly with service owners, engineers, and leadership to resolve ambiguity around risk ownership

Preferred Skills:

  • Experience with cloud environments (GCP, AWS, or Azure), particularly assessing risks related to cloud architecture and services
  • Familiarity with vulnerability management programs and how they feed into risk management
  • Experience supporting compliance audits or regulatory assessments (ISO 27001, SOC 2, PCI DSS)
  • Experience building or contributing to security metrics, KPI dashboards, or executive reporting
  • Prior work in a SaaS or contact center / communications platform environment
  • Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python
  • Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.)

Benefits:

  • Five9 Shares
  • Bonus Scheme
  • 10% Flex Benefit
  • Meal Allowance
  • Medical Insurance
  • Life Insurance
  • 25 day Annual Leave + Public Holidays

Five9 embraces diversity and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better we are. Five9 is an equal opportunity employer.


View our privacy policy, including our privacy notice to California residents here: .

Note: Five9 will never request that an applicant send money as a prerequisite for commencing employment with Five9.

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location

  • Preferred First Name optional
  • How did you hear about opportunities at Five9?
  • If you were referred by a current Five9 employee please enter the employee's name here: optional
  • Which best describes your right to work in Portugal? choose one
  • Candidate comments: written answer · optional
  • The recruiting function, including systems and processes, for Five9 are driven out of the US office with team members in various satellite offices. It is imperative that individuals responsible for the recruiting out of their respective offices, as well as team members in the United States, have the ability to share information and data. Often, this necessity extends beyond the recruiting team, and includes hiring managers as well. The recruiting function, including systems and processes, for Five9 are driven out of the headquarters in the United States with team members in satellite offices across various countries. • The HR Operations team, based in the US, must have access to hiring data from other countries in order to complete Compliance audits. • Our compensation and Benefits team , based in the US, must share and receive data from all offices with respect to job grading and compensation. • The FP&A team, based in the US, provides headcount and must receive offer details to hired employees for reporting purposes. • Our Payroll team, based in the US, must receive and provide data in order to complete payroll activities. • For many of the roles in other countries, the hiring manager is based in the US. They must have access to the resumes for candidates for assessment and access to offer documents for hired candidates for budget purposes. • The CFO must approve all offers and offer information must be shared across offices in order for that action to be satisfied. • The recruiting team needs access to data related to recruiting functions for reporting, process enhancements, data assessments. choose one
  • Are you a current Five9 employee? If so, please apply through the Internal Job Board in Greenhouse. choose one · optional

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available