Avatar for Savers
Savers
Actively Hiring
Sells used clothes, accessories, & household goods in retail thrift stores

Sr. IT Security Engineer

  • |8 years of exp
  • |Full Time
Posted: 6 days ago• Recruiter recently active
Job Location
Remote Work Policy

In office - WFH flexibility

Visa Sponsorship

Not Available

RelocationAllowed
Skills
Python
Javascript
Ruby
Cryptography
Automation
Risk Analysis
Cloud Security
Identity and Access Management
Network Security
Security Operations
Threat Modeling
Security Engineering
PowerShell
Iso 27001
Application Security
PCI DSS
CIS
NIST
Authentication Protocols
SOC 2
Application Security Testing
Security Assessment and Testing
Security Risk and Compliance
Mitigation Strategies
Risk Assessment Methodologies
Security Vulnerabilities
Security Tooling
Enterprise Governance
Control Monitoring
Network and System Security
Control Validation
Risk Treatment Plans
Compensating Control Strategies

About the job

Description

Job Description

Sr. IT Security Engineer

Location: Boise, Idaho

Travel: 10% or less

Summary:

The Sr. IT Security Engineer is an internal security engineering role supporting business stakeholders and IT technical teams in developing, maintaining, and operating secure, compliant line-of-business systems and processes across Savers. This position plays a dual role—providing deep technical security expertise while ensuring alignment with enterprise risk management, governance, and compliance frameworks. This is a hands-on and analytical role requiring broad knowledge across multiple security disciplines, including Cloud Security, Application Security, Security Engineering, Network Security, Identity and Access Management, Security Assessment and Testing, Security Operations, and Security Risk and Compliance.

Successful candidates will have a demonstrable record of applying security principles, controls, and frameworks (NIST, ISO 27001, CIS, SOC 2, PCI) in planning, implementation, maintenance, and monitoring of security technologies and practices, while creating policies and documentation to uphold frameworks. The role reports to the Director of IT Security and contributes directly to Savers’ risk-based approach to sustainable security.

Essential Job Functions:

  • Collaborate with cross-functional teams to drive internal security, privacy, and risk governance initiatives across the enterprise.
  • Creating and maintain Enterprise Policies, Standards, and Guideline documentation to support alignment of Industry Frameworks
  • Serve as a trusted security and risk advisor to stakeholders, offering actionable guidance that balances technical controls with business priorities.
  • Provide continuous security and compliance guidance for internal projects, technology evaluations, and daily operational issues.
  • Conduct detailed security and risk assessments of business applications, cloud workloads, and critical processes to identify control gaps, residual risks, and mitigation plans.
  • Communicate security risks, vulnerabilities, and recommended treatments to both technical and non-technical teams, ensuring clear risk awareness and accountability.
  • Partner with Solutions Delivery and Engineering teams to embed secure-by-design principles, risk controls, and governance checkpoints throughout the SDLC.
  • Participate in project teams and initiatives as a dedicated Security Advisor and risk representative from planning through operationalization.
  • Monitor and analyze emerging threats, regulatory changes, and vendor advisories, and assess their relevance to Savers’ risk posture.
  • Establish and manage risk and threat metrics, control scorecards, and compliance health monitoring to measure and communicate program effectiveness to varying levels of leadership.
  • Collaborate closely with IT, Audit, Legal, and Business teams to ensure consistent governance, risk, and compliance alignment across the organization.
  • Maintain deep industry expertise and contribute to policy updates, control documentation, and audit readiness activities.

Required Knowledge, Skills and Abilities:

  • Strong experience ensuring security, privacy, and risk governance for Internet-facing systems, SaaS applications, and cloud services.
  • Comprehensive understanding of Internet security issues, risk assessment methodologies, and mitigation strategies.
  • Experience with security tooling, automation, and control monitoring to improve visibility and reduce operational risk.
  • Technical expertise in security engineering, network and system security, authentication protocols, cryptography, and application security testing.
  • Practical experience in threat modeling, risk analysis, and control validation.
  • Knowledge of security vulnerabilities, risk treatment plans, and compensating control strategies.
  • Familiarity with security frameworks, standards, and protocols relevant to enterprise governance (e.g., NIST, ISO 27001, SOC 2, PCI DSS).
  • Excellent written and verbal communication skills, with the ability to translate technical findings into risk-based business context.
  • Analytical, resourceful, and organized, with a proactive approach to identifying and mitigating potential security risks.
  • Strong collaboration skills with a willingness to provide clear, actionable feedback in complex or sensitive governance discussions.
  • Proficiency with one or more interpreted programming or scripting languages (Python, JavaScript, Ruby, PowerShell, etc.) to support security automation and compliance evidence collection.

Minimum Required Education, Training and Experience:

  • 8+ years’ experience in information security.
  • Industry certifications such as CISSP, CCSP, CISM and CRISC preferred
  • B.S. or M.S. in computer science or related field or equivalent professional experience

Physical Requirements:

  • Ability to lift and carry up to 30 lbs.
  • Ability to express or exchange ideas by means of the spoken word.
  • Ability to receive detailed information through verbal communication, and to make the discriminations in sound.
  • Ability to receive detailed information visually through written communication (both physical and electronic).

FLSA Status

  • Exempt

Tools and Equipment Used:

  • Laptop or desktop computer, phone, copy machine, etc.

Travel:

  • 10 % or less

Work Address:

  • SSC Boise, ID

Page 1 of 2

This job description is not intended to be all-inclusive. Employee may perform other related duties as assigned to meet the ongoing needs of the organization.

About the company

Savers company logo

Savers

Actively Hiring
Sells used clothes, accessories, & household goods in retail thrift stores5000+ Employees
Learn more about Savers image

Funding

AMOUNT RAISED
$138.8M
FUNDED OVER
1 round
Round
S
$138750000
Seed - May 2025