Security Engineer
🏢 Coterie Insurance · all Coterie Insurance jobs
📍 United States
💰 USD 90,000 - 110,000 / annual
📅 Posted 2026-07-19 · via Himalayas
🏷 Security-Engineer,Security-Engineering,Security-Operations,Cloud-Security,Privileged-Access-Management,Cybersecurity-Engineer,IT-Security-Engineer,Information-Security-Engineer,IAM
Apply on original site ↗Who we are:
Through a partnership-based approach, Coterie helps insurance professionals unlock untapped revenue in the small commercial space. With an innovative quoting platform that delivers accurate pricing and bindable quotes in less than one minute, Coterie makes small business insurance effortless.
We are on a mission to build and foster a world-class team to bring speed, simplicity, and service to commercial insurance. We value integrity, humility, passion, and intelligence. If you want to push yourself and reshape a $200B+ market, we’re excited to talk to you!
What will the Security Engineer do?
Coterie’s Security team is hiring a Security Engineer (100% Remote!) to contribute to our identity, access, and security operations programs. Under the guidance of our Principal Security Architect, this role runs our recurring access reviews, supports evidence collection for compliance testing, and brings hands-on privileged access management experience, with an emphasis on endpoint privilege management. You’ll also help respond to security operations alerts and run our security awareness phishing simulation program. If you enjoy wearing different “hats” and want to grow in a fast-paced, cloud-native environment, then this role is for you!
As the Security Engineer, you’ll be able to:
- Run Coterie’s recurring user access reviews under the direction of the Principal Security Architect, coordinating with system owners to certify access and remove stale or over-provisioned entitlements across our environments
- Gather, organize, and validate evidence to support compliance testing and audits, following established procedures to build evidence packets that trace access and changes from request through approval
- Administer our privileged access management program with oversight, focusing on endpoint privilege management, operating local administrator elevation, least-privilege policies, and just-in-time access on endpoints within approved guardrails
- Support time-bound, approved, and reviewed privileged access through Azure Privileged Identity Management (PIM), including role assignments and periodic recertification of privileged identities
- Triage and respond to security operations alerts from our SIEM and endpoint tooling under the guidance of senior engineers, escalating, documenting, and helping close out incidents
- Run the day-to-day administration of our security awareness program, including building, scheduling, and reporting on phishing simulations and assigning follow-up training
- Follow and maintain the procedures, standards, and documentation the team has established for access reviews, privileged access, and related security operations workflows
- Utilize a risk-based approach to your day-to-day work and surface pain points and recommend continuous-improvement ideas for these programs and processes
- Partner with IT operations, engineering, and compliance teams to help close access and process gaps and mature Coterie’s security posture
- Take on other security operations tasks that support the team, such as detection tuning, vulnerability remediation tracking, and tooling evaluations, as directed and as priorities shift
What we are looking for:
- 3–5 years of experience in security operations, identity/access administration, or a related technical role
- Experience with cloud-native enterprise services
- Solid understanding of identity and access management concepts, including authentication, authorization, least privilege, and role-based access control
- Hands-on experience with privileged access management, with specific experience in endpoint privilege management (managing local administrator rights and elevation)
- Experience running or supporting access reviews and access certifications, and removing unneeded access
- Familiarity with compliance frameworks (e.g., SOC 1, SOC 2, SOX) and supporting the collection of audit evidence
- Comfortable triaging alerts from a SIEM or endpoint s