Information Security Engineer
Job Description
<div class="content-intro"><p><strong>It's a new day with a new opportunity at 8am! </strong></p></div><p><strong>About the role:</strong></p> <p>The Information Security Engineer ensures the security and integrity of 8am’s systems, with a focus on cloud security operations, detection engineering, incident response, and data protection. This role is the hands-on technical backbone of the security program: you will operate and improve our detection and response stack, lead technical investigation of security events, and partner with engineering teams to embed security across our platforms.</p> <p>Location: Czech Republic (Remote). Working hours for this role are aligned to U.S. Central Time (Austin) core business hours to ensure real-time collaboration with the U.S.-based security leadership and compliance team.</p> <p><em>This role is hired through an Employer of Record (EOR) partner in the Czech Republic.</em></p> <p><strong>About us:</strong></p> <p>8am builds software that helps professionals run stronger businesses. Our platform powers payments, client experience, and operational workflows for legal, accounting, and other service-based businesses. U.S. based professionals count on our purpose-built solutions to simplify operations, ensure compliance, and fuel profitable growth, so they can focus on their clients and do more of the work that matters.</p> <p><strong>More than 250,000 professionals across the U.S. rely on our products every day. As we continue to grow, we’re investing in the next generation of our platform and are looking for experienced engineers who want to help shape its future.</strong></p> <p><strong>What you'll do:</strong></p> <ul> <li><strong>AWS security operations</strong>: Manage AWS security posture — identify vulnerabilities, triage findings (GuardDuty, Security Hub), drive remediation with owning teams</li> <li><strong>Detection engineering</strong>: Operate/extend EDR and SIEM — maintain endpoint coverage, author detection queries/dashboards, tune alerts, investigate suspicious activity</li> <li><strong>Incident response & forensics</strong>: Lead hands-on IR — investigation, containment, forensic analysis, remediation, and post-incident reviews</li> <li><strong>Vulnerability management</strong>: Run operational cadence — scanner curation, severity SLAs, remediation tracking, code/secret scanning triage</li> <li><strong>Security awareness & internal ops</strong>: Manage KnowBe4 phishing tests/training with Compliance</li> <li><strong>Platform security</strong>: Support WAF monitoring, IaC security review, and cloud account hygiene across multi-account environment</li> <li><strong>Data privacy & compliance support</strong>: Collaborate on data mapping/DLP/classification, and on compliance controls (PCI ASV scans, Vanta tests)</li> <li><strong>Product security & documentation</strong>: Advise on customer-facing/product security questions; maintain runbooks so work is reproducible by any teammate</li> </ul> <p><strong>About you:</strong></p> <ul> <li><span style="font-weight: 400;">4+ years in security engineering or security operations, with real incident response experience.</span></li> <li><span style="font-weight: 400;">Strong AWS security knowledge (IAM, logging, GuardDuty/Security Hub, multi-account patterns).</span></li> <li><span style="font-weight: 400;">Proficiency with SIEM query languages, detection tuning, and at least one scripting language (Python<br>preferred).</span></