Senior Information Security Engineer
Quick Summary
Identify, document, and assess security risks across Five9's environment, including production infrastructure, cloud services, corporate systems,
3+ years of experience in information security,
Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide.
Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves.
We are looking for a Senior Information Security Engineer to join our growing Security Risk Management team. The Security Risk Management team aims to expand beyond traditional risk management; we are building an engineering driven program that designs, automates, and scales the controls, workflows, and tooling that protect Five9 and our customers.
As a key contributor to the program the role supports the day-to-day execution of risk identification, assessment, treatment, and reporting across Five9's infrastructure, services, and acquisitions. You'll work directly with engineering, operations, and business stakeholders to surface security risks, drive them toward resolution, and maintain a clear picture of Five9's risk posture for leadership.
Responsibilities
~1 min read- →Identify, document, and assess security risks across Five9's environment, including production infrastructure, cloud services, corporate systems, and acquired platforms
- →Maintain the Security Risk Register in Jira, ensuring risks are accurately categorized, assigned to appropriate owners, and tracked through their lifecycle
- →Engage with service owners, engineering leads, and operations teams to establish risk ownership and drive remediation or mitigation plans
- →Facilitate the risk acceptance process, including preparing risk acceptance documentation and coordinating approval with appropriate stakeholders
- →Develop and deliver risk reporting for security leadership and executive audiences, including dashboards and metrics that communicate risk posture clearly
- →Collaborate with compliance, vulnerability management, and other Information Security functions to ensure risk findings are incorporated into the broader security program
- →Research and apply risk management frameworks and methodologies to continuously improve program maturity
- →Contribute to the development of risk management policies, procedures, and playbooks
Requirements
~1 min read- 3+ years of experience in information security, with at least 2 years focused on security risk management or GRC
- Demonstrated experience maintaining a security risk register and driving risk treatment decisions with cross-functional stakeholders
- Strong understanding of risk assessment methodologies (qualitative and quantitative)
- Familiarity with security frameworks such as NIST CSF, NIST 800-53, ISO 27001, PCI, or SOC 2
- Ability to communicate security risks clearly to both technical and non-technical audiences
- Experience with Jira or similar tools for tracking and managing risk workflows
- Self-directed and comfortable engaging directly with service owners, engineers, and leadership to resolve ambiguity around risk ownership
Preferred Skills:
- Experience with cloud environments (GCP, AWS, or Azure), particularly assessing risks related to cloud architecture and services
- Familiarity with vulnerability management programs and how they feed into risk management
- Experience supporting compliance audits or regulatory assessments (ISO 27001, SOC 2, PCI DSS)
- Experience building or contributing to security metrics, KPI dashboards, or executive reporting
- Prior work in a SaaS or contact center / communications platform environment
- Hands-on experience using agentic coding tools (Cursor, Claude Code, Copilot, etc.) and a working knowledge of Python
- Professional certification in Information Security or Risk Management (such as CISSP, CISM, CISA, CRISC, etc.)
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- July 28, 2026
- First seen
- July 28, 2026
- Last seen
- July 29, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 70%
- Scored at
- July 28, 2026
Signal breakdown
Please let Five9 know you found this job on Jobera.
3 other jobs at Five9
View all →Explore open roles at Five9.
Similar Information Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.