Senior Information Security Engineer

Company
Description
Summary: Join Five9 as a Senior Information Security Engineer to contribute to an engineering-driven security risk management program, protecting Five9 and its customers through risk identification, assessment, and reporting. Highlights: 1. Contribute to an engineering-driven security risk management program 2. Expand beyond traditional risk management to design and automate controls 3. Collaborate with diverse teams to drive security risk resolution Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide. Living our values everyday results in our team\-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves. We are looking for a Senior Information Security Engineer to join our growing Security Risk Management team. The Security Risk Management team aims to expand beyond traditional risk management; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Five9 and our customers. As a key contributor to the program the role supports the day\-to\-day execution of risk identification, assessment, treatment, and reporting across Five9's infrastructure, services, and acquisitions. You'll work directly with engineering, operations, and business stakeholders to surface security risks, drive them toward resolution, and maintain a clear picture of Five9's risk posture for leadership. **Key Responsibilities:** * Identify, document, and assess security risks across Five9's environment, including production infrastructure, cloud services, corporate systems, and acquired platforms * Maintain the Security Risk Register in Jira, ensuring risks are accurately categorized, assigned to appropriate owners, and tracked through their lifecycle * Engage with service owners, engineering leads, and operations teams to establish risk ownership and drive remediation or mitigation plans * Facilitate the risk acceptance process, including preparing risk acceptance documentation and coordinating approval with appropriate stakeholders * Develop and deliver risk reporting for security leadership and executive audiences, including dashboards and metrics that communicate risk posture clearly * Collaborate with compliance, vulnerability management, and other Information Security functions to ensure risk findings are incorporated into the broader security program * Research and apply risk management frameworks and methodologies to continuously improve program maturity * Contribute to the development of risk management policies, procedures, and playbooks **Requirements:** * 3\+ years of experience in information security, with at least 2 years focused on security risk management or GRC * Demonstrated experience maintaining a security risk register and driving risk treatment decisions with cross\-functional stakeholders * Strong understanding of risk assessment methodologies (qualitative and quantitative) * Familiarity with security frameworks such as NIST CSF, NIST 800\-53, ISO 27001, PCI, or SOC 2 * Ability to communicate security risks clearly to both technical and non\-technical audiences * Experience with Jira or similar tools for tracking and managing risk workflows * Self\-directed and comfortable engaging directly with service owners, engineers, and leadership to resolve ambiguity around risk ownership Preferred Skills: * Experience with cloud environments (GCP, AWS, or Azure), particularly assessing risks related to cloud architecture and services * Familiarity with vulnerability management programs and how they feed into risk management * Experience supporting compliance audits or regulatory assessments (ISO 27001, SOC 2, PCI DSS) * Experience building or contributing to security metrics, KPI dashboards, or executive reporting * Prior work in a SaaS or contact center / communications platform environment * Hands\-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python * Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.) **Benefits:** * Five9 Shares * Bonus Scheme * 10% Flex Benefit * Meal Allowance * Medical Insurance * Life Insurance * 25 day Annual Leave \+ Public Holidays Five9 embraces diversity and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better we are. Five9 is an equal opportunity employer. View our privacy policy, including our privacy notice to California residents here: https://www.five9\.com/pt\-pt/legal. Note: Five9 will never request that an applicant send money as a prerequisite for commencing employment with Five9\.
Posted by

João Santos
Indeed · HR




