freehire launches on Product Hunt on 26 August.

Follow →

Staff Information Security Engineer

Open 19d reposted 2× · 2 open copies

Summary

Lead Five9's Cyber Resiliency program, maturing cloud security tooling and processes across AWS, GCP, and Azure to identify and remediate infrastructure risks while partnering with engineering teams.

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide.

Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves.

We are seeking a Staff Information Security Engineer to join Five9's Information Security team. This role will own the operationalization and ongoing maturity of Five9's Cyber Resiliency program (the practice of using tooling to continuously identify, prioritize, and remediate infrastructure resilience issues across our AWS, GCP, Azure cloud environments). You'll be responsible for program governance, tool ownership, process development, and engineering engagement to scale the program across the organization. As secondary responsibilities, you will support the Cloud Security program as a senior technical resource.

Key Responsibilities:

Cyber Resiliency Program (Primary)

  • Own the operational lifecycle of the Cyber Resiliency program, including tool administration, system and resource mapping, criticality tiering, and issue triage workflows
  • Develop and maintain program governance: process documentation, SLAs for remediation, escalation paths, and quarterly review cadences
  • Build executive reporting for security and engineering leadership: resilience score trends, remediation velocity, IaC coverage, and risk exposure by system criticality tier
  • Drive the communication plan for the program, ensuring engineering teams understand expectations before receiving remediation tickets
  • Define and maintain issue prioritization frameworks that balance system criticality, environment, severity, and remediation effort
  • Partner with engineering leads to drive remediation of infrastructure resilience issues, removing blockers and tracking progress through Jira

Cloud Security (Supporting)

  • Partner with the Cloud Security team on architecture reviews, policy development, and strategic initiatives across GCP, AWS, and Azure
  • Develop and refine security guardrails, policy-as-code, and automated detection and response capabilities for cloud misconfigurations
  • Evaluate and improve cloud security posture including IAM architecture, network segmentation, and workload protection
  • Ensure cloud security solutions are under configuration management and deployed through CI/CD pipelines

Requirements:

  • 5+ years of experience in information security, with demonstrated experience in a senior technical role
  • Experience operationalizing a security program or service: building governance, processes, and reporting, not just executing within an existing framework
  • Deep hands-on experience with at least one major cloud platform (GCP strongly preferred), including IAM, networking, compute, and storage security
  • Strong experience with infrastructure-as-code (Terraform required) and CI/CD pipelines
  • Demonstrated ability to drive remediation and risk reduction across engineering teams without direct authority
  • Experience building executive-level security reporting and metrics
  • Excellent communication skills: able to present program status and risk to engineering leadership, security leadership, and executive audiences
  • Self-directed with the ability to manage competing priorities across program operations and supporting workstreams

Preferred Skills:

  • Experience with cyber resilience or infrastructure resilience tooling (Gambit, Wiz, or similar CSPM/CNAPP platforms)
  • Experience conducting risk assessments or security maturity assessments using frameworks such as NIST CSF, ISO 27001, or CMMI
  • Background in Kubernetes security and container workload protection
  • Experience with multi-cloud environments (GCP + AWS + Azure)
  • Python scripting for automation and tooling
  • Security certifications (CISSP, CCSP, SANS certifications, or similar)
  • Prior experience in a SaaS, contact center, or communications platform environment
  • Experience mentoring or technically leading junior engineers

Benefits:

  • Five9 Shares
  • Bonus Scheme
  • 10% Flex Benefit
  • Meal Allowance
  • Medical Insurance
  • Life Insurance
  • 25 day Annual Leave + Public Holidays

Five9 embraces diversity and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better we are. Five9 is an equal opportunity employer.


View our privacy policy, including our privacy notice to California residents here: .

Note: Five9 will never request that an applicant send money as a prerequisite for commencing employment with Five9.

What this application asks

greenhouse

First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location

  • Preferred First Name optional
  • How did you hear about opportunities at Five9?
  • If you were referred by a current Five9 employee please enter the employee's name here: optional
  • Which best describes your right to work in Portugal? choose one
  • Candidate comments: written answer · optional
  • The recruiting function, including systems and processes, for Five9 are driven out of the US office with team members in various satellite offices. It is imperative that individuals responsible for the recruiting out of their respective offices, as well as team members in the United States, have the ability to share information and data. Often, this necessity extends beyond the recruiting team, and includes hiring managers as well. The recruiting function, including systems and processes, for Five9 are driven out of the headquarters in the United States with team members in satellite offices across various countries. • The HR Operations team, based in the US, must have access to hiring data from other countries in order to complete Compliance audits. • Our compensation and Benefits team , based in the US, must share and receive data from all offices with respect to job grading and compensation. • The FP&A team, based in the US, provides headcount and must receive offer details to hired employees for reporting purposes. • Our Payroll team, based in the US, must receive and provide data in order to complete payroll activities. • For many of the roles in other countries, the hiring manager is based in the US. They must have access to the resumes for candidates for assessment and access to offer documents for hired candidates for budget purposes. • The CFO must approve all offers and offer information must be shared across offices in order for that action to be satisfied. • The recruiting team needs access to data related to recruiting functions for reporting, process enhancements, data assessments. choose one
  • Are you a current Five9 employee? If so, please apply through the Internal Job Board in Greenhouse. choose one · optional

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available