Senior IT Security Engineer

SIMPRO•Miami, FL
•Onsite

About The Position

Simpro Group is seeking a Senior IT Security Engineer to sustain and strengthen its certification posture, covering frameworks such as SOC 2 and ISO 27001, while owning the day-to-day security of its internal IT environment. This is a senior individual contributor role based onsite in downtown Miami, reporting to the IT Director. The role involves owning IT security and compliance end to end, with autonomy in day-to-day execution and strategy shaped jointly with IT leadership. On the product engineering side, this role acts as a technical sounding board, providing advisory rather than ownership of engineering processes. Protecting customer data, meeting compliance obligations, and safeguarding core systems are paramount. The role requires sound judgment on where security efforts deliver the most protection without hindering business operations.

Requirements

  • Hands-on technical depth in identity and access architecture, not just policy writing.
  • Experience selecting and standing up EDR/MDR.
  • Experience maintaining endpoint and group policy standards.
  • Experience across both logical security (IAM, network segmentation, cloud config) and physical security practices.
  • Comfortable advising engineering teams you don't manage, credible enough that they value your input even without formal authority.
  • Strong communicator who can explain risk and tradeoffs to non-security stakeholders.
  • Solid working understanding of how SOC 2 and ISO 27001 programs run, close enough to the process to have done real work in it, not just relaying auditor requests.
  • 6+ years in information security or a closely related IT discipline.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or an equivalent combination of professional experience and industry certifications.

Nice To Haves

  • CISSP, CISA, or ISO 27001 Lead Implementer/Auditor certification.
  • Experience with GRC tooling such as Vanta, Drata, or Secureframe.
  • Background in vendor risk management or third-party due diligence.
  • Owning a certification cycle start to finish.

Responsibilities

  • Sustain and strengthen certification posture across frameworks such as SOC 2 and ISO 27001.
  • Lead new certification initiatives as needed.
  • Select and implement a Governance, Risk, and Compliance (GRC) platform.
  • Manage prospect and customer security questionnaires.
  • Build and maintain the risk register across physical, logical, and systems-level exposure.
  • Prioritize remediation of identified risks.
  • Audit and remediate shared credential and generic account exposure.
  • Improve identity architecture, including SSO consolidation and network authentication.
  • Select and stand up EDR/MDR capability.
  • Maintain group policy and endpoint standards.
  • Secure remote connectivity.
  • Own data protection practices.
  • Address physical security risks tied to IT-managed systems like door access technology.
  • Serve as a sounding board to product engineering on secure configuration, secrets handling, and vulnerability management.
  • Assess new and existing SaaS vendors.
  • Review security posture and trust documentation of vendors on a recurring basis.
  • Build incident response playbooks.
  • Run incident response tabletop exercises.
  • Lead incident response when incidents occur.

Benefits

  • Best-of-class onboarding program
  • Supportive team environments
  • Opportunities to develop your career
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service