About The Position

We are seeking a Security & Infrastructure Engineer with information security experience to help protect our systems, data, and customers. In this role, you will own our external penetration testing program and SOC 2 audit process end-to-end, building the processes and controls needed to meet security standards and maintain compliance. You will also manage identity and access across Microsoft 365, AWS, and third-party applications, strengthen AWS and end-user compute security posture, and partner closely with DevOps to secure infrastructure. The ideal candidate is comfortable operating as a hands-on generalist across security, compliance, and cloud infrastructure, at home writing an audit-ready policy, and experienced managing identity and access management across the organization. This role is critical to improving Janus’ security program and offers the opportunity to build scalable, well-documented processes from the ground up while working closely with engineering, DevOps, and leadership teams.

Requirements

  • 3-5 years of experience in information security, IT security, or a closely related field.
  • Hands-on experience administering Microsoft 365 identity and access management, including Entra ID (Azure AD), conditional access, and MFA.
  • Experience configuring and managing SSO/SAML/OIDC integrations with third-party SaaS applications.
  • Working knowledge of security frameworks and controls (e.g., NIST, CIS Controls, SOC 2).
  • Experience building or documenting repeatable security processes and procedures.
  • Highly motivated self-starter with a strong team orientation.
  • Outstanding verbal and written communication skills.
  • Flexibility and comfort working in a dynamic, constantly evolving startup environment.
  • Commitment to contributing to a positive, collaborative culture.
  • Must be located in the United States; sponsorship is not available at this time.

Nice To Haves

  • Experience securing AWS environments (IAM, GuardDuty, Security Hub, CloudTrail, VPC security, etc.).
  • Familiarity with DevOps practices and infrastructure-as-code
  • Networking fundamentals: DNS, VPNs, firewalls, routing basics
  • SIEM or observability platform experience (Datadog, Splunk, or similar)
  • Security certifications (CISSP, CISM, AWS Security Specialty, or CompTIA Security+)

Responsibilities

  • Manage Microsoft 365 identity and access, including user lifecycle, conditional access policies, MFA, and role-based permissions.
  • Design and automate processes for provisioning and deprovisioning of user accounts and service accounts across cloud and SaaS environments
  • Extend coverage to application-layer vulnerabilities, working in close coordination with development teams to surface and track findings
  • Own and manage external security and penetration testing engagements end-to-end, including scoping, coordinating with vendors, tracking remediation, and validating fixes through retesting.
  • Design, document, and implement the security processes, policies, and controls required to achieve and maintain SOC 2 (and other applicable control frameworks) compliance on an ongoing basis.
  • Continuously assess and improve our AWS security posture, including IAM, network security, and configuration hardening, and build ongoing security reporting and dashboards to track risk and compliance status.
  • Partner with the DevOps team on infrastructure security and secure provisioning for cloud resources and CI/CD pipelines.
  • Monitor for vulnerabilities and emerging threats across the environment, and maintain clear documentation of security policies, procedures, and audit evidence.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service