Back to search
EngineeringHybrid

Staff Information Security Engineer

Five9 · Hybrid

Apply
Last seen by MeritLog September 10, 2026Source: GreenhouseSource version: greenhouse-job-board-v1

MeritLog read this listing from Five9's Greenhouse job board and last checked it on September 10, 2026.

Source: the employer's Greenhouse job board. Open the original listing for current details.

Job details

Work model
Hybrid
Salary
Not listed by source
Location
Porto, Portugal (Hybrid)

Hiring context

How this role compares at Five9

Five9 has 123 live roles in MeritLog’s catalog across 10 job families, and 53 of them are in engineering. 0 of those listings publish a pay range, a disclosure rate of 0%.

Counted across the job boards MeritLog tracks, at the time this page was served. Pay comparisons use only listings that publish a complete range in the same currency and period.

What the role asks for

What you'd do

  • Own the operational lifecycle of the Cyber Resiliency program, including tool administration, system and resource mapping, criticality tiering, and issue triage workflows
  • Develop and maintain program governance: process documentation, SLAs for remediation, escalation paths, and quarterly review cadences
  • Build executive reporting for security and engineering leadership: resilience score trends, remediation velocity, IaC coverage, and risk exposure by system criticality tier
  • Drive the communication plan for the program, ensuring engineering teams understand expectations before receiving remediation tickets
  • Define and maintain issue prioritization frameworks that balance system criticality, environment, severity, and remediation effort
  • Partner with engineering leads to drive remediation of infrastructure resilience issues, removing blockers and tracking progress through Jira
  • Partner with the Cloud Security team on architecture reviews, policy development, and strategic initiatives across GCP, AWS, and Azure
  • Develop and refine security guardrails, policy-as-code, and automated detection and response capabilities for cloud misconfigurations
  • Evaluate and improve cloud security posture including IAM architecture, network segmentation, and workload protection
  • Ensure cloud security solutions are under configuration management and deployed through CI/CD pipelines

What they're asking for

  • 5+ years of experience in information security, with demonstrated experience in a senior technical roleExperience
  • Experience operationalizing a security program or service: building governance, processes, and reporting, not just executing within an existing frameworkSkill
  • Deep hands-on experience with at least one major cloud platform (GCP strongly preferred), including IAM, networking, compute, and storage securitySkillPreferred
  • Strong experience with infrastructure-as-code (Terraform required) and CI/CD pipelinesSkill
  • Demonstrated ability to drive remediation and risk reduction across engineering teams without direct authoritySkill
  • Experience building executive-level security reporting and metricsSkill
  • Excellent communication skills: able to present program status and risk to engineering leadership, security leadership, and executive audiencesSkill
  • Self-directed with the ability to manage competing priorities across program operations and supporting workstreamsSkill
  • Experience with cyber resilience or infrastructure resilience tooling (Gambit, Wiz, or similar CSPM/CNAPP platforms)SkillPreferred
  • Experience conducting risk assessments or security maturity assessments using frameworks such as NIST CSF, ISO 27001, or CMMISkillPreferred
  • Background in Kubernetes security and container workload protectionSkillPreferred
  • Experience with multi-cloud environments (GCP + AWS + Azure)SkillPreferred
  • Python scripting for automation and toolingSkillPreferred
  • Security certifications (CISSP, CCSP, SANS certifications, or similar)CredentialPreferred
  • Prior experience in a SaaS, contact center, or communications platform environmentSkillPreferred
  • Experience mentoring or technically leading junior engineersSkillPreferred

Parsed by MeritLog from the employer’s own posting. The full description follows below.

Job description

Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide. Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves. We are seeking a Staff Information Security Engineer to join Five9's Information Security team. This role will own the operationalization and ongoing maturity of Five9's Cyber Resiliency program (the practice of using tooling to continuously identify, prioritize, and remediate infrastructure resilience issues across our AWS, GCP, Azure cloud environments). You'll be responsible for program governance, tool ownership, process development, and engineering engagement to scale the program across the organization. As secondary responsibilities, you will support the Cloud Security program as a senior technical resource. Key Responsibilities: Cyber Resiliency Program (Primary) • Own the operational lifecycle of the Cyber Resiliency program, including tool administration, system and resource mapping, criticality tiering, and issue triage workflows • Develop and maintain program governance: process documentation, SLAs for remediation, escalation paths, and quarterly review cadences • Build executive reporting for security and engineering leadership: resilience score trends, remediation velocity, IaC coverage, and risk exposure by system criticality tier • Drive the communication plan for the program, ensuring engineering teams understand expectations before receiving remediation tickets • Define and maintain issue prioritization frameworks that balance system criticality, environment, severity, and remediation effort • Partner with engineering leads to drive remediation of infrastructure resilience issues, removing blockers and tracking progress through Jira Cloud Security (Supporting) • Partner with the Cloud Security team on architecture reviews, policy development, and strategic initiatives across GCP, AWS, and Azure • Develop and refine security guardrails, policy-as-code, and automated detection and response capabilities for cloud misconfigurations • Evaluate and improve cloud security posture including IAM architecture, network segmentation, and workload protection • Ensure cloud security solutions are under configuration management and deployed through CI/CD pipelines Requirements: • 5+ years of experience in information security, with demonstrated experience in a senior technical role • Experience operationalizing a security program or service: building governance, processes, and reporting, not just executing within an existing framework • Deep hands-on experience with at least one major cloud platform (GCP strongly preferred), including IAM, networking, compute, and storage security • Strong experience with infrastructure-as-code (Terraform required) and CI/CD pipelines • Demonstrated ability to drive remediation and risk reduction across engineering teams without direct authority • Experience building executive-level security reporting and metrics • Excellent communication skills: able to present program status and risk to engineering leadership, security leadership, and executive audiences • Self-directed with the ability to manage competing priorities across program operations and supporting workstreams Preferred Skills: • Experience with cyber resilience or infrastructure resilience tooling (Gambit, Wiz, or similar CSPM/CNAPP platforms) • Experience conducting risk assessments or security maturity assessments using frameworks such as NIST CSF, ISO 27001, or CMMI • Background in Kubernetes security and container workload protection • Experience with multi-cloud environments (GCP + AWS + Azure) • Python scripting for automation and tooling • Security certifications (CISSP, CCSP, SANS certifications, or similar) • Prior experience in a SaaS, contact center, or communications platform environment • Experience mentoring or technically leading junior engineers Workplace location: This role is hybrid and requires 3 days a week in our Porto office. Benefits: • Five9 Shares • Bonus Scheme • 10% Flex Benefit • Meal Allowance • Medical Insurance • Life Insurance • 25 day Annual Leave + Public Holidays Five9 embraces diversity and is committed to building a team that represents a variety of backgrounds, perspectives, and skills.  The more inclusive we are, the better we are.  Five9 is an equal opportunity employer. View our privacy policy, including our privacy notice to California residents here: https://www.five9.com/pt-pt/legal. Note: Five9 will never request that an applicant send money as a prerequisite for commencing employment with Five9.

Keep exploring

More Engineering roles

Search all jobs

Privacy choices

Analytics and advertising stay off unless you allow them. Private data stays out.

Read the privacy notice