We are seeking an Information Security Engineer to help design, operate, and continuously improve Trupanionโs security controls and tooling across our Microsoft 365/Azure environment and supporting onโprem systems. This role balances handsโon ownership of core security platformsโparticularly the Microsoft Defender suite and Privileged Access Management (CyberArk)โwith strong security engineering practices such as automation, integrations, hardening, and detection and response improvements. The ideal candidate is proactive, detailโoriented, and comfortable partnering with IT and engineering teams to reduce risk, respond to incidents, and deliver practical, measurable security outcomes. Candidates located in the Seattle area are preferred, however strong remote candidates may be considered. If you are based in the Seattle area, you will have a hybrid remote/inโoffice schedule where you will work from our casual, petโfriendly office at least 3 days a week.
Key Responsibilities:
- Engineer, operate, and continuously improve the Microsoft Defender security stack (e.g., Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender Vulnerability Management) to protect endpoints, identities, email, and cloud applications.
- Own and administer Privileged Access Management tool, including onboarding/offboarding privileged accounts, policy and workflow configuration, vault health, upgrades, and integrations.
- Integrate Defender and PAM signals with SIEM/SOAR and ITSM workflows to improve detection fidelity, reduce false positives, and accelerate response and remediation.
- Design and implement security engineering solutions across cloud and onโprem environments (primarily Azure/M365), including baseline hardening, configuration standards, and security control automation.
- Develop and maintain security tooling lifecycle management (health, licensing, capacity, performance, roadmap, and upgrades), ensuring resilient and supportable operations.
- Create and maintain detection engineering content: analytic rules/use cases, alert tuning, threat hunting queries, and automated response playbooks.
- Perform security assessments and vulnerability management, including scanning, prioritization, remediation tracking, and validation of fixes in partnership with IT and engineering teams.
- Partner with infrastructure, identity/IAM, and application teams to embed security controls into designs and delivery (secureโbyโdefault patterns, CI/CD security checks, and leastโprivilege access).
- Respond to security incidents as an engineering escalation pointโtriage alerts, contain threats, coordinate remediation, and drive rootโcause fixes and preventive controls.
- Produce clear, accurate, and upโtoโdate runbooks, procedures, and reference architectures for security tooling and operational processes.
- Support audits and regulatory exams by providing evidence, control narratives, and technical subjectโmatter expertise for implemented security controls.
- Stay current with emerging threats and Microsoft security capabilities; recommend and implement pragmatic improvements to Trupanionโs security posture.
Qualifications:
- Bachelorโs degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).
- 5+ years of handsโon security engineering experience supporting enterprise security platforms in Microsoft 365/Azure environments.
- Relevant certifications (one or more preferred): Microsoft Security (e.g., SCโ200/SCโ300/SCโ100), AZโ500, CISSP, CISM, GIAC, or equivalent.
Skills:
- Deep expertise securing Microsoft 365 and Azure, including identity, endpoint, email, and cloud security controls.
- Demonstrated experience administering Microsoft Defender components and/or XDR/SIEM platforms, including alert tuning, detection engineering, and incident response collaboration.
- Experience implementing or operating Privileged Access Management (CyberArk preferred) and integrating PAM with identity and security monitoring systems, including policy configuration, privileged session controls, onboarding/ offboarding, and operational troubleshooting.
- Strong handsโon experience with the Microsoft Defender stack (Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender Vulnerability Management) and associated investigation workflows.
- Experience with XDR/SIEM operations and integration (e.g., Microsoft Sentinel or equivalent): alert triage, tuning, threat hunting, and automation/playbooks.
- Strong identity and access management knowledge, including Entra ID (Azure AD), conditional access, MFA, least privilege, and roleโbased access control.
- Security engineering fundamentals across Windows, macOS, and Linux, plus network and cloud concepts (TLS, DNS, routing, segmentation, logging).
- Proficiency in scripting and automation (PowerShell and/or Python) to operationalize controls, integrate platforms, and improve reliability.
- Experience with vulnerability management and remediation workflows, including scanning, prioritization, validation, and reporting.
- Working knowledge of secure SDLC and DevSecOps practices, including CI/CD security checks, secrets handling, and infrastructureโasโcode security.
- Familiarity with security frameworks and controls (NIST, CIS, ISO 27001) and translating requirements into implementable technical standards.
- Strong communication skills with the ability to explain security issues, tradeoffs, and remediation steps to both technical and nonโtechnical stakeholders.
- Excellent problemโsolving, analytical skills, and the ability to prioritize and deliver across multiple concurrent initiatives.
- Experience developing and maintaining runbooks, technical documentation, security guidelines, and reference architectures.
The base pay range for this position is $140,000-$160,000, on a fullโtime schedule. Along with base compensation, Trupanion employees are currently eligible for monthly bonuses. We want all employees to be invested in Trupanionโs success, so we grant Restricted Stock Units to all new team members. Our new hire grants vest over 4 years.
#J-18808-Ljbffr