Coterie Logo

Coterie

Security Engineer

Posted 8 Hours Ago
Remote
Hiring Remotely in United States
90K-110K Annually
Mid level
Remote
Hiring Remotely in United States
90K-110K Annually
Mid level
Administer identity and access security programs, including access reviews, privileged access management, endpoint privilege controls, and Azure PIM. Support compliance audits through evidence collection, triage SIEM and endpoint alerts, manage phishing simulations, document procedures, and track vulnerability remediation. Partner with IT, engineering, and compliance teams to improve security processes and posture in a cloud-native environment.
The summary above was generated by AI

Who we are:
Through a partnership-based approach, Coterie helps insurance professionals unlock untapped revenue in the small commercial space. With an innovative quoting platform that delivers accurate pricing and bindable quotes in less than one minute, Coterie makes small business insurance effortless.  
We are on a mission to build and foster a world-class team to bring speed, simplicity, and service to commercial insurance. We value integrity, humility, passion, and intelligence. If you want to push yourself and reshape a $200B+ market, we’re excited to talk to you!


What will the Security Engineer do?

Coterie’s Security team is hiring a Security Engineer (100% Remote!) to contribute to our identity, access, and security operations programs. Under the guidance of our Principal Security Architect, this role runs our recurring access reviews, supports evidence collection for compliance testing, and brings hands-on privileged access management experience, with an emphasis on endpoint privilege management. You’ll also help respond to security operations alerts and run our security awareness phishing simulation program. If you enjoy wearing different “hats” and want to grow in a fast-paced, cloud-native environment, then this role is for you!

As the Security Engineer, you’ll be able to: 

  • Run Coterie’s recurring user access reviews under the direction of the Principal Security Architect, coordinating with system owners to certify access and remove stale or over-provisioned entitlements across our environments
  • Gather, organize, and validate evidence to support compliance testing and audits, following established procedures to build evidence packets that trace access and changes from request through approval
  • Administer our privileged access management program with oversight, focusing on endpoint privilege management, operating local administrator elevation, least-privilege policies, and just-in-time access on endpoints within approved guardrails
  • Support time-bound, approved, and reviewed privileged access through Azure Privileged Identity Management (PIM), including role assignments and periodic recertification of privileged identities
  • Triage and respond to security operations alerts from our SIEM and endpoint tooling under the guidance of senior engineers, escalating, documenting, and helping close out incidents
  • Run the day-to-day administration of our security awareness program, including building, scheduling, and reporting on phishing simulations and assigning follow-up training
  • Follow and maintain the procedures, standards, and documentation the team has established for access reviews, privileged access, and related security operations workflows
  • Utilize a risk-based approach to your day-to-day work and surface pain points and recommend continuous-improvement ideas for these programs and processes
  • Partner with IT operations, engineering, and compliance teams to help close access and process gaps and mature Coterie’s security posture
  • Take on other security operations tasks that support the team, such as detection tuning, vulnerability remediation tracking, and tooling evaluations, as directed and as priorities shift

What we are looking for:  

  • 3–5 years of experience in security operations, identity/access administration, or a related technical role
  • Experience with cloud-native enterprise services
  • Solid understanding of identity and access management concepts, including authentication, authorization, least privilege, and role-based access control
  • Hands-on experience with privileged access management, with specific experience in endpoint privilege management (managing local administrator rights and elevation)
  • Experience running or supporting access reviews and access certifications, and removing unneeded access
  • Familiarity with compliance frameworks (e.g., SOC 1, SOC 2, SOX) and supporting the collection of audit evidence
  • Comfortable triaging alerts from a SIEM or endpoint security tooling and following documented response procedures
  • Experience administering or supporting a security awareness or phishing simulation platform
  • Comfortable operating established programs and processes under direction, while contributing ideas to improve them
  • Self-motivated, detail-oriented, organized, and able to manage recurring deadlines across multiple workstreams
  • Exceptional written and verbal communication, with the ability to document processes clearly

What will make you stand out:

  • Experience with Azure Privileged Identity Management (PIM) and Azure RBAC
  • Experience with an endpoint privilege management solution (e.g., CyberArk EPM, Admin By Request, BeyondTrust)
  • Experience administering Okta and Microsoft 365 / Entra ID
  • Familiarity with Microsoft Sentinel (or another SIEM) and basic KQL
  • Experience with a security awareness platform
  • Security certifications (e.g., Security+, SC-900, SC-300, CySA+) or cloud certifications (e.g., AZ-500)

Our interview process:

Our hiring process generally consists of 4 phases. The goal is to provide an opportunity for us to learn more about our candidates while allowing them to get to know us as well!

  • Phase 1: Qualified candidates will first meet with a member of our People Operations team for a phone interview.  This discussion is a high-level conversation to understand more about your background and interests and for us to share more about Coterie and the position.
  • Phase 2: Selected candidates will be invited to meet with our Hiring Manager for a 2nd interview via Teams video. This interview is designed to be more detail oriented and allows you to learn more about the role and expected to be 30 minutes in length.
  • Phase 3: Top candidates will be invited to participate in an experiential exercise and team member interviews. This will include a project provided in advance along with a 1-hour project deep dive interview conducted with our hiring manager and additional team members. This series is expected to be 1.5 hours in total.
  • Phase 4: Final candidates will be invited to the final interview. This interview will include 1:1 meeting with a member of our senior leadership team and is expected to be 30 minutes in length.


What's in it for you:

Coterie has excellent benefits for all full-time employees. We offer the following:

  • 100% remote
  • Health insurance through Aetna (we pay 100% of premiums)
  • Dental and vision insurance through Guardian (we pay 100% of premiums)
  • Basic life insurance (we pay 100% of premiums)
  • Access to flexible spending account (FSA) or health savings account (HSA) (for those using HSA eligible plans)
  • 401K plan (up 4% match with immediate vest). Must be 21 years of age or older to participate
  • Flexible PTO policy offering employees up to 4 weeks of PTO in their first 12 months. Thereafter, PTO usage aligns with company standards and typically does not exceed 5 weeks per calendar year.
  • 12 company-paid holidays each year
  • Continuing education annual stipend
  • Annual salary estimated between 90,000-110,000 based on national data. Candidates who meet all the minimum requirements and possess additional relevant experience, as outlined in the job description, may be considered for a salary above the midpoint of the above range. Salary is based on internal equity; internal salary ranges; market data/ranges; applicant’s skills; prior relevant experience; degrees or certifications, etc. 

Work Authorization:
At this time, Coterie Insurance is unable to consider candidates who require current or future visa sponsorship. Applicants must have authorization to work in the United States without the need for sponsorship now or in the future. Falsification of an application, including work authorization status, is immediate grounds for dismissal from consideration.

Similar Jobs

2 Days Ago
In-Office or Remote
141K-176K Annually
Senior level
141K-176K Annually
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Lead secure design reviews, threat modeling, and security risk assessments for products and features. Partner with engineers, product managers, and designers to develop secure architectures, provide remediation guidance, promote security culture through training and mentoring, oversee vulnerability management, and explain security events. Build security tooling, automate secure development practices, and establish architectural patterns and processes that reduce security risk across DigitalOcean’s engineering organization.
Top Skills: CContainerizationContinuous DeliveryContinuous IntegrationGoJavaScriptOwasp Top TenRustVirtualization
2 Days Ago
Remote
United States
141K-176K Annually
Senior level
141K-176K Annually
Senior level
Artificial Intelligence • Cloud • Software • Infrastructure as a Service (IaaS)
Assess product and application architectures, develop threat models, identify security risks, and guide engineering teams on remediation. Promote security culture through training, mentoring, vulnerability management, and internal security initiatives. Build security tooling, automation, patterns, and workflows that embed secure-by-design practices across engineering. Partner with product managers, designers, and engineers to secure complex, large-scale cloud systems.
Top Skills: CContainerizationContinuous DeliveryContinuous IntegrationGoJavaScriptOwaspRustVirtualization
2 Days Ago
Easy Apply
Remote or Hybrid
USA
Easy Apply
134K-168K Annually
Senior level
134K-168K Annually
Senior level
Cloud • Information Technology • Security • Software • Cybersecurity
Protect corporate data through DLP implementation, tuning, alert review, false-positive reduction, and control optimization across web, endpoint, email, cloud, and SaaS environments. The engineer will review data protection programs, improve monitoring and blocking controls, collaborate with business partners, and use automation and emerging AI tools to strengthen security operations.
Top Skills: Ai ToolsCloud Data StoresData Loss Prevention (Dlp)SaaSZscaler DspmZscaler Zero Trust ExchangeZscaler Zia

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account