Security Engineer II
Listed on 2026-02-01
-
IT/Tech
Cybersecurity, Systems Engineer
AXS connects fans with the artists and teams they love. Each year we sell millions of tickets to thousands of incredible events – from concerts and festivals to sports and theater – at some of the most iconic venues in the world. Since our founding in 2011, we’ve consistently pushed the industry forward and improved experiences for fans, making it easier than ever to discover events, find the perfect seats, and enjoy unforgettable live entertainment, and we continue to lead the evolution of our industry today.
We’re passionate about improving the fan experience and providing game-changing solutions for our clients, and we’re always looking for smart, motivated people to help make it happen. Bring your enthusiasm, your big ideas, and your desire to team up with some of the best and brightest in technology and entertainment.
The Role
We are looking for our next Security Engineer II to be responsible for designing, implementing, and maintaining technical security measures, focusing on vulnerability management, threat detection, and infrastructure protection. This role will secure cloud/on-prem environments using automation (Python, Terraform) and tools like SIEM or EDR, often collaborating with Dev Ops to remediate security risks and strengthen security posture.
What Will You Do?
- Develop and maintain security policies, guidelines, and lead implementation in all systems, including AWS and in particular Cloud Trail, EKS, AWS Inspector, EC2, EMR, S3, AWS Identity Center, RDS, Security Hub, Guard Duty
- Architect, design, implement, support, and evaluate security-focused tools and controls to meet security and compliance needs.
- Integrate security checks into the CI/CD pipelines to ensure continuous compliance and shift left security practice.
- Utilize tools like Terraform or Cloud Formation to build, deploy and enforce compliance and secure cloud infrastructure.
- Utilize networking (VPC, Firewall, Transit Gateways), container security and encryption.
- Build scripts (Python, Bash) and serverless functions (AWS Lambda) for alerting on anomalies, misconfigurations and threats including automations to auto respond to such threat actors/findings.
- Oversee threat management and security incident handling, including the coordination of investigations and reporting of security incidents to management, in alignment with business.
- Work with the team and QSA on PCI (level 1 & level 2 service provider) & SOC initiatives for the company.
- Ensure that security is factored into the evaluation, selection, and configuration of hardware, applications and software.
- Ensure audit trails, systems logs and other monitoring data sources are reviewed periodically and are in compliance with policies and audit requirements. Provide support and guidance for legal and regulatory compliance efforts, including audit support.
- Promote information security awareness throughout the company. Stay current with security technologies and threats by monitoring vendor and industry publications and attending training.
- Secure sensitive data, manage user credentials through the principle of least privileges, track user activity.
- Proactively identify security risks and implement practices that meet standards for information security, by analyzing current systems, and working with IT and the business. Partner with development and infrastructure teams to identify and remediate vulnerabilities and develop mitigation plans.
What Will You Bring?
- BA/BS in computer science or related technical field
- 3-5 years of cybersecurity experience in a professional environment
- Experience with IDS/IPS, file integrity, internal/external penetration & vulnerability tests, FIM, SIEM, and log aggregation tools
- Development and scripting experience to build automation:
Lambda, Terraform, Cloud Formation, API integrations - Understanding of the software development life cycle and CI/CD pipelines
- Ability to execute process and standards around code quality and the deployment lifecycle including SAST and DAST
- Experience in SIEM, MDR, EDR, DLP Identity Management, WAF, WAS, Incident Response, attack surface management
- Proactively find weaknesses in applications and network through audits, penetration…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).