Five9
Staff Information Security Engineer
Porto, Portugal (Hybrid)
Apply through hirly
Upload your resume and get a version tailored to this job, plus a cover letter, in about thirty seconds — before you create an account.
Apply with hirlyhirly's read of this role
- Role family
- Engineering
- Seniority
- Lead / management
- Country
- PT
- Work mode
- Remote-friendly
- First seen by hirly
- 4 Sept 2026
Derived automatically from the posting. Sign up to see how the role scores against your own resume.
the posting
Join us in bringing joy to customer experience. Five9 is a leading provider of cloud contact center software, bringing the power of cloud innovation to customers worldwide.
Living our values everyday results in our team-first culture and enables us to innovate, grow, and thrive while enjoying the journey together. We celebrate diversity and foster an inclusive environment, empowering our employees to be their authentic selves.
We are seeking a Staff Information Security Engineer to join Five9's Information Security team. This role will own the operationalization and ongoing maturity of Five9's Cyber Resiliency program (the practice of using tooling to continuously identify, prioritize, and remediate infrastructure resilience issues across our AWS, GCP, Azure cloud environments). You'll be responsible for program governance, tool ownership, process development, and engineering engagement to scale the program across the organization. As secondary responsibilities, you will support the Cloud Security program as a senior technical resource.
Key Responsibilities:
Cyber Resiliency Program (Primary)
Own the operational lifecycle of the Cyber Resiliency program, including tool administration, system and resource mapping, criticality tiering, and issue triage workflows
Develop and maintain program governance: process documentation, SLAs for remediation, escalation paths, and quarterly review cadences
Build executive reporting for security and engineering leadership: resilience score trends, remediation velocity, IaC coverage, and risk exposure by system criticality tier
Drive the communication plan for the program, ensuring engineering teams understand expectations before receiving remediation tickets
Define and maintain issue prioritization frameworks that balance system criticality, environment, severity, and remediation effort
Partner with engineering leads to drive remediation of infrastructure resilience issues, removing blockers and tracking progress through Jira
Cloud Security (Supporting)
Partner with the Cloud Security team on architecture reviews, policy development, and strategic initiatives across GCP, AWS, and Azure
Develop and refine security guardrails, policy-as-code, and automated detection and response capabilities for cloud misconfigurations
Evaluate and improve cloud security posture including IAM architecture, network segmentation, and workload protection
Ensure cloud security solutions are under configuration management and deployed through CI/CD pipelines
Requirements:
5+ years of experience in information security, with demonstrated experience in a senior technical role
Experience operationalizing a security program or service: building governance, processes, and reporting, not just executing within an existing framework
Deep hands-on experience with at least one major cloud platform (GCP strongly preferred), including IAM, networking, compute, and storage security
Strong experience with infrastructure-as-code (Terraform required) and CI/CD pipelines
Demonstrated ability to drive remediation and risk reduction across engineering teams without direct authority
Experience building executive-level security reporting and metrics
Excellent communication skills: able to present program status and risk to engineering leadership, security leadership, and executive audiences
Self-directed with the ability to manage competing priorities across program operations and supporting workstreams
Preferred Skills :
Experience with cyber resilience or infrastructure resilience tooling (Gambit, Wiz, or similar CSPM/CNAPP platforms)
Experience conducting risk assessments or security maturity assessments using frameworks such as NIST CSF, ISO 27001, or CMMI
Background in Kubernetes security and container workload protection
Experience with multi-cloud environments (GCP + AWS + Azure)
Python scripting for automation and tooling
Security certifications (CISSP, CCSP, SANS certifications, or similar)
Prior experience in a SaaS, contact center, or communications platform environment
Experience mentoring or technically leading junior engineers
Workplace location : This role is hybrid and requires 3 days a week in our Porto office.
Benefits:
Five9 Shares
Bonus Scheme
10% Flex Benefit
Meal Allowance
Medical Insurance
Life Insurance
25 day Annual Leave + Public Holidays
Five9 embraces diversity and is committed to building a team that represents a variety of backgrounds, perspectives, and skills. The more inclusive we are, the better we are. Five9 is an equal opportunity employer.
View our privacy policy, including our privacy notice to California residents here: https://www.five9.com/pt-pt/legal .
Note: Five9 will never request that an applicant send money as a prerequisite for commencing employment with Five9.
Similar jobs
- Devoteam Cyber Trust | Tech Lead — Network Security Engineer | Banking SectorDevoteam · Porto, , PortugalFirst seen 4d ago
- Devoteam Cyber Trust | Network Security Engineer | Banking SectorDevoteam · Porto, , PortugalFirst seen 4d ago
- Principal Security Engineer Talkdesk2 · PortugalFirst seen 10d ago
- Principal Cloud Security EngineerLastpass · Remote - PortugalFirst seen 18d agoremote
- Senior Security EngineerFarfetch · PortoFirst seen 24d ago
Browse similar roles
Want this one?
Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.
Tailor my resume for this job