Information Security Engineer Apply
Job Title: Information Security Engineer Infrastructure & Compliance
Location: King of Prussia, PA (Hybrid Onsite Preferred) locals preferred
Visa Status: GC And USC
Employment Type: Contract
Reports To: Senior Manager, IT Infrastructure & Security
Role Overview:
Clean Earth is seeking an Information Security Engineer to strengthen infrastructure and cloud security while driving compliance with enterprise security frameworks. This role sits at the intersection of IT Infrastructure, Cloud Operations, and Cybersecurity, with a strong focus on NIST 800-171 alignment, audit remediation, vulnerability management, and patch governance.
The engineer will work hands-on with Infrastructure and Cloud Operations teams to harden Azure and hybrid environments, close audit gaps, and improve security posture-without impacting operational stability.
This role is critical to establishing clear divisional ownership for infrastructure security and compliance initiatives.
Key Responsibilities:
Security & Compliance
- Act as the divisional lead for NIST 800-171 control alignment, tracking compliance status and driving remediation efforts.
- Partner with Internal Audit and Enterprise Security to review audit findings, assess risk, and ensure timely resolution of non-compliance items.
- Maintain and enhance Microsoft Defender for Cloud posture management across Azure and hybrid infrastructure.
- Identify, prioritize, and remediate security vulnerabilities across servers, networks, and cloud platforms.
- Design and implement a Linux patch management strategy, including compliance reporting and validation.
- Support SOX, NIST, and enterprise audit readiness through documentation, control evidence collection, and process improvement.
Infrastructure & Cloud Security Operations
- Collaborate closely with Infrastructure, Cloud Operations, and Application teams to assess security risk and prevent operational disruption.
- Embed security best practices into Azure, network, and datacenter operations.
- Utilize Defender for Cloud, Azure Security Center, and related tooling to monitor environment health and security posture.
- Coordinate with Systems and Cloud Engineers to validate patch success, configuration baselines, and compliance metrics.
- Automate recurring security validation and compliance tasks using PowerShell, Python, or Bash.
Governance, Reporting & Awareness
- Maintain centralized tracking of security initiatives, audit remediation activities, and policy adherence.
- Partner with Project Managers to ensure security remediation workstreams are properly planned and executed.
- Support KnowBe4 phishing campaigns through analysis and security awareness reinforcement.
- Produce and report key risk indicators (KRIs) and compliance metrics to IT and security leadership.
Required Qualifications
- 4 7 years of experience in Information Security, Infrastructure Engineering, or Cloud Operations.
- Hands-on experience with Microsoft Defender for Cloud, Azure Security Center, or comparable security platforms (Qualys, Nessus, Tanium).
- Working knowledge of NIST 800-171, NIST CSF, or ISO 27001 frameworks.
- Proven experience managing patching and vulnerability remediation across Windows and Linux environments.
- Strong scripting or automation skills using PowerShell, Python, or Bash.
- Solid understanding of Active Directory, Azure AD, and network security fundamentals.
Preferred Qualifications
- Experience with Fortify or similar static application security testing (SAST) tools.
- Familiarity with KnowBe4, VRX, or patch compliance tracking systems.
- Exposure to Azure DevOps, Infrastructure-as-Code (IaC), or configuration-as-code practices.
- Relevant certifications such as AZ-500, Security+, CISSP, or equivalent.
Success Measures
- Measurable reduction in open audit findings and non-compliant controls.
- Established and repeatable Linux and infrastructure patch compliance reporting.
- Improved Defender for Cloud secure score against baseline.
- Documented and repeatable NIST control alignment process for divisional systems.
- Improved collaboration between Infrastructure, Cloud, and Security teams during vulnerability remediation

