SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
IRALOGIX is a high-growth institutional technology platform serving IRA providers, 401(k) recordkeepers, retirement advisors, and banks. The company builds proprietary, ground-up technology to expand retirement services access while reducing administration costs and improving efficiency.
You'll join a lean, collaborative security function reporting to the Director of Security. This role is ideal for a broad generalist who thrives in modern cloud environments and wants to develop expertise across multiple security domains: cloud infrastructure, application security, DevSecOps, endpoint security, and compliance.
Key responsibilities include:
**Cloud Security & IAM**: Support secure AWS configuration, develop identity and access guardrails across AWS and SaaS tools, and partner with DevOps on container security and image lifecycle hygiene.
**CI/CD Security**: Work with engineering and platform teams to define security gates, standardize secure build practices, and manage secrets and artifacts.
**Vulnerability & Threat Management**: Triage and remediate vulnerabilities from cloud and endpoint scanners; engage with the SOC on security event response across cloud, identity, endpoint, and application layers.
**Application Security**: Help developers address legacy library vulnerabilities, integrate secure coding practices, and participate in threat modeling and secure SDLC planning.
**Governance & Compliance**: Maintain SOC 2 Type II posture, map controls to frameworks (CSA CCM, CIS AWS), and collaborate with auditors.
**Endpoint & SaaS Security**: Support Mac and Windows laptop security, enforce device compliance, and govern secure SaaS usage.
**Education & Culture**: Contribute to internal security training, awareness campaigns, and foster a secure-by-default culture.
The role is hybrid (3–4 days/week in Charlotte, NC or Pittsburgh, PA office) with 0–5% travel. The environment emphasizes learning, adaptability, and cross-functional collaboration with high autonomy. No formal on-call, but expectation to assist during major incidents.
**Requirements:**
- 2–4 years of hands-on security, DevOps, or cloud engineering experience in modern environments
- Familiarity with AWS IAM, containers (ECS, EKS), Terraform, SSO (Okta), and CI/CD workflows
- Practical understanding of vulnerability management, secure coding, and cloud-native security tooling
- Experience working in small teams or startups where everyone wears multiple hats
- Comfort collaborating with developers, auditors, and cross-functional stakeholders
- Eagerness to learn, especially around AppSec, cloud IAM, and CI/CD security
- Strong written and verbal communication skills
**Bonus:**
- Familiarity with Java, Python, Go, or Rust
- Experience securing GitHub Enterprise, Argos, Trivy, or other DevSecOps tools
- Prior exposure to SOC 2, CIS, or CSA CCM compliance frameworks
- Open source or personal security project contributions