Logo for CME

Infosec / Compliance Specialist

Role overview

Qualifications

  • Bachelor’s degree in Computer Science, Software Engineering, or a related field
  • Minimum 5 years of experience in Information Security, Identity and Access Management (IAM), Compliance, DevSecOps, or a related field
  • Deep experience with Keycloak administration, realm configuration, user federation, and Identity Provider (IdP) mapping
  • Strong knowledge of Microsoft Entra ID enterprise applications and Google Identity Platform

Responsibilities

  • Architect enterprise Single Sign-On (SSO) solutions using Keycloak, SAML 2.0, and OpenID Connect (OIDC)
  • Configure Microsoft Entra ID (Azure AD) and Google Cloud Identity as identity brokers
  • Establish centralized Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), and Zero Trust security policies across all platform boundaries
  • Manage GitHub Advanced Security (GHAS) initiatives, including enforcement of Dependabot alerts, secret scanning, static code analysis (CodeQL/SAST), and branch protection rules

Key facts

Hard skills

Other skills

  • Analytical Thinking
  • Problem Solving
  • Communication
  • Teamwork

About the company

CME logo

CME

IT Services & IT Consulting

We are a multinational enterprise offering premium technology solutions and services. Over the years, we have helped more than 100 clients worldwide, including top US Fortune 500 companies, to become and remain leaders in their fields. In practice, we provide enterprise end-to-end tailor-made solutions and technology services across different disciplines, including Staff Augmentation, Custom Software Development, Smart Devices Engineering, Customer Experience, Internet of Things (IoT), Artificial Intelligence (AI), Data Management, and Process Automation. By developing scalable and forward-thinking projects, we accelerate digital transformation for businesses and organizations to achieve operational excellence, improve customer engagement, and unlock new growth opportunities. Our proven track record of success spans multiple industries, including Consumer Goods, Education, Food, Healthcare, Hospitality, Insurance, Market Research, Retail, Sustainability, Telecom, and Utilities. To date, we have contributed to 8 US patents. With 300+ delivered projects, our teams of highly skilled engineers, creative thinkers, and industry-specific experts operate from 8 locations around the world. CME serves 80 million users every day!

Company details

IndustryIT Services & IT Consulting
Company size201 - 500

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

We are seeking a Mid-Senior Infosec / Compliance Specialist to lead and strengthen security, identity, governance, and compliance initiatives across cloud-native and enterprise environments. The role focuses on identity federation, access governance, DevSecOps security controls, cloud security, and audit readiness while ensuring adherence to industry-recognized compliance frameworks and best practices.
The Key Responsibilities are:
  • Architect enterprise Single Sign-On (SSO) solutions using Keycloak, SAML 2.0, and OpenID Connect (OIDC).
  • Configure Microsoft Entra ID (Azure AD) and Google Cloud Identity as identity brokers.
  • Establish centralized Role-Based Access Control (RBAC), Multi-Factor Authentication (MFA), and Zero Trust security policies across all platform boundaries.
  • Manage GitHub Advanced Security (GHAS) initiatives, including enforcement of Dependabot alerts, secret scanning, static code analysis (CodeQL/SAST), and branch protection rules.
  • Implement portable secrets management and monitor service-to-service security mechanisms such as mutual TLS (mTLS) across Kubernetes cluster boundaries.
  • Lead audit readiness activities, vulnerability scanning programs, and compliance enforcement initiatives for frameworks such as SOC 2 and ISO 27001.
  • Collaborate with engineering, platform, and operations teams to ensure security controls are embedded throughout the software development lifecycle.
  • Support continuous improvement of organizational security posture through governance, risk management, and compliance best practices.

Requirements

  • Bachelor’s degree in Computer Science, Software Engineering, or a related field.
  • Minimum 5 years of experience in Information Security, Identity and Access Management (IAM), Compliance, DevSecOps, or a related field.
  • Deep experience with Keycloak administration, realm configuration, user federation, and Identity Provider (IdP) mapping.
  • Strong knowledge of Microsoft Entra ID enterprise applications and Google Identity Platform.
  • Experience enforcing security policies across multi-tenant Kubernetes clusters and cloud boundaries.
  • Familiarity with GitHub Advanced Security and DevSecOps automated tooling.
  • Strong understanding of SAML 2.0, OpenID Connect (OIDC), identity federation, and authentication protocols.
  • Experience implementing RBAC, MFA, Zero Trust architectures, and cloud security best practices.
  • Knowledge of vulnerability management, audit readiness processes, and compliance frameworks such as SOC 2 and ISO 27001.
  • Excellent analytical, problem-solving, and risk assessment skills.
  • Excellent English communication skills.
  • Ability to work effectively with cross-functional and globally distributed teams.
  • Availability to work from 11:00 AM to 8:00 PM.


Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Compliance Officer Related jobs

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.