Information Security Engineer
Jobgether
$136,400–$149,429from the description
Jul 14, 2026
—
Jul 21, 2026
What this job asks for AI summary
An Information Security Engineer role focused on designing, automating, and operating security controls across cloud and traditional infrastructure environments. Day-to-day work spans threat detection, vulnerability management, incident response, security monitoring, and embedding security practices into development workflows, with additional involvement in compliance frameworks and bug bounty programs. Suited to someone with hands-on security engineering experience who can work independently and collaborate across technical teams.
Mid level · 3+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 3,650 people nationally plausibly meet what this posting asks for (information security analysts). range 2,200–6,500
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role is posted via Jobgether on behalf of an unnamed partner company; the actual employer is not disclosed.
The 3–6 year experience range maps to Mid seniority; the title 'Information Security Engineer' carries no explicit level word, so advertised seniority is Unspecified.
Python/Bash/Go are listed as interchangeable scripting options under requirements; Python is used as the primary name with Bash and Go as alternatives.
CrowdStrike and Obsidian are listed as examples of enterprise security platforms under requirements ('such as … or similar'); CrowdStrike is the primary name with Obsidian as an alternative. The 'or similar' qualifier means the specific tool is interchangeable, not that the capability is optional.
SOC 2, ISO 27001, C5, and GDPR are all cited as compliance frameworks under requirements. C5 and GDPR are not representable as named tool skills and are captured via SOC 2 / ISO 27001 as proxies for the compliance requirement.
CTI (Cyber Threat Intelligence) is listed alongside SIEM/EDR/SAST/SOAR under required security technologies but names no specific product; omitted as a standalone skill since it is a capability category rather than a named tool.
HashiCorp Vault, cloud security certifications, and threat modeling background appear under the 'Nice to have' section.
Caller marked this a fully-remote role — scored against the national candidate pool.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.