Information Security Engineer P3
Verifone
Why Verifone
For more than 30 years Verifone has established a remarkable record of leadership in the electronic payment technology industry. Verifone has one of the leading electronic payment solutions brands and is one of the largest providers of electronic payment systems worldwide.
Verifone has a diverse, dynamic and fast paced work environment in which employees are focused on results and have opportunities to excel. We take pride in the fact that we work with leading retailers, merchants, banks, and third party partners to invent and deliver innovative payments solution around the world. We strive for excellence in our products and services, and are obsessed with customer happiness. Across the globe, Verifone employees are leading the payments industry through experience, innovation, and an ambitious spirit. Whether it’s developing the next platform of secure payment systems or searching for new ways to bring electronic payments to new markets, the team at Verifone is dedicated to the success of our customers, partners and investors. It is this passion for innovation that drives each one of our employees for personal and professional success.
What's exciting about the role
The Information Security Engineer plays a pivotal role in safeguarding the integrity of our transaction-based systems. This is a high-impact position where the work directly contributes to the security posture of the organization. The Information Security Engineer will be part of a collaborative and forward-thinking team that values innovation, precision, and continuous improvement.
Key Responsibilities
- Participate in security audits and compliance assessments (PCI SSF, PCI DSS, ISO 27001 or similar).
- Perform penetration testing and vulnerability assessments using tools such as Burp Suite, OWASP ZAP, Metasploit, Nmap, and Nessus.
- Analyze and report code vulnerabilities using SonarQube or similar static analysis tools.
- Support security monitoring and network traffic analysis with Wireshark, tcpdump, and other diagnostic tools.
- Configure and analyze encryption mechanisms (AES, RSA) and digital certificates (TLS/SSL).
- Collaborate with development and infrastructure teams to ensure compliance with cybersecurity standards.
- Support Linux-based environments and network configurations (intermediate level).
- Develop and maintain Shell scripts for process automation, tool development, and test execution.
- Assist in root-cause analysis and prepare detailed incident or compliance reports.
Required Skills and Experience
- Minimum 2 years of hands-on experience in penetration testing, security audits, or vulnerability management.
- Intermediate knowledge of Linux and networking (TCP/IP, firewalls, VPNs, routing).
- Experience with encryption and key management (AES, RSA, PKI, HSMs or similar).
- Experience with SonarQube, Wireshark, and other analysis tools.
- Strong teamwork, communication, and analytical skills.
- Experience in financial or transaction systems is desirable but not mandatory.
- Preferred Tools and Technologies: Burp Suite, OWASP ZAP, Metasploit, Nessus, Nmap, Wireshark, SonarQube, OpenSSL, tcpdump, Git, Linux, Shell Script
Our commitment
Verifone is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. Verifone is also committed to compliance with all fair employment practices regarding citizenship and immigration status.