Sr. Security Engineer
Summary
Senior Security Engineer who owns the day-to-day security posture of Velocitor Solutions' fleet-management platform from their Charlotte, NC office: running vulnerability management, coordinating penetration tests, hardening Azure/AKS, tightening IAM on Entra ID and Auth0, and maintaining SOC 2 and GDPR compliance.
Sr. Security Engineer
Type: Full-time
Location: Charlotte, NC (Onsite)
Team: IT / Information Security
About Velocitor Solutions
Velocitor Solutions is a leader in enterprise fleet management and mobile innovation, celebrating over 25 years of profitably growing technology. We go beyond standard telematics by offering a comprehensive, managed ecosystem—managing over 200,000 mobile assets for Fortune 500 clients across North America. Our V-Track platform integrates GPS tracking, AI-powered video telematics, and real-time data to drive safety and efficiency. We are in a pivotal phase of growth and looking to expand technology team.
Why Join Velocitor Solutions
You will own security for a platform that runs mission-critical fleet operations for national enterprise clients. The work is visible, the stakes are concrete, and the roadmap is active. You will have the mandate to fix what you find.
Role Summary
We are hiring a Senior Security Engineer in IT to own the day-to-day security posture of Velocitor's infrastructure and application platform. You will drive vulnerability management, lead and coordinate penetration testing, harden our Azure and AKS environments, and tighten identity and access controls across the organization. You will work closely with the platform, DevOps, engineering, and client-facing teams, and you will translate findings into fixes that ship. This is a hands-on role for someone who can both run the assessment and shape the remediation of the environment.
Key Responsibilities
- Own vulnerability management across Azure, AKS, on-premises systems, and client-facing applications. Prioritize by real risk and client impact, not raw CVE counts.
- Lead and coordinate penetration testing engagements, including scoped tests against client UAT and production environments. Manage internal testers and third-party firms, track findings to closure, and produce client-ready results.
- Harden our identity stack on Entra ID and Auth0. Drive least-privilege access, reduce standing Domain Admin exposure through Restricted Management Administrative Units, and close IAM gaps as access volume scales.
- Secure the AKS platform and CI/CD pipelines. Review container images, cluster configuration, secrets management, and network policy.
- Build and maintain security runbooks, incident response procedures, and detection logic.
- Participate in the security on-call rotation and lead incident response when events occur.
- Own compliance and audit readiness end to end, including SOC 2 and GDPR. Manage relationships with external auditors and security vendors, coordinate evidence collection, and drive remediation of findings.
- Own client security requirements and questionnaires. Lead RCAs and remediation plans when incidents touch client environments.
- Partner with DevOps and engineering to embed security into the delivery pipeline rather than gating it at the end.
- Track and report platform security posture to leadership with clear metrics and recommendations.
