
Cybersecurity Engineering & Operations Director
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Formulate and implement the cybersecurity engineering and operations strategy in collaboration with the VP of Compliance and Security.
• Convert risk assessments and business priorities into actionable technical roadmaps, architectural standards, and quantifiable results.
• Spearhead the design and ongoing enhancement of security controls and safeguards across AWS and corporate settings.
• Provide security automation through code using Terraform, Python, CI/CD, and policy-as-code methodologies.
• Oversee technical security operations and incident response, including detection, investigation, containment, eradication, and recovery.
• Maintain and execute incident response plans, playbooks, and runbooks.
• Develop automated detection and response workflows utilizing SIEM, SOAR, EDR, and cloud-native tools.
• Facilitate executive, legal, and regulatory escalations in coordination with the VP.
• Manage vulnerability and exposure across applications, cloud environments, endpoints, and external attack surfaces.
• Establish risk-based remediation service level agreements (SLAs) and prioritize issues based on exploitability, exposure, and business impact.
• Drive root-cause solutions for systemic vulnerabilities.
• Provide security leadership for Microsoft 365, Entra ID, corporate endpoints, email security, and application/product security throughout the software development lifecycle (SDLC).
• Lead initiatives related to SAST/DAST/SCA, SBOMs, API security, threat modeling, security champions, and AI-integrated applications and solutions.
• Mentor, guide, and develop the cybersecurity manager, engineers, and security operations personnel.
• Define team structure, career pathways, and scalable operational processes.
• Manage security vendors, penetration testing, and managed security services.
• Act as the senior technical security advisor to Engineering, IT, Product, and executive leadership.
• Over 10 years of progressive experience in cybersecurity.
• A minimum of 5 years in security leadership or management roles overseeing security engineering, security operations, or cloud security functions.
• Proven experience in managing managers and technical teams.
• Extensive expertise in securing cloud-native enterprise SaaS applications.
• Strong practical experience with AWS security, including IAM, VPC, EC2, RDS, S3, EKS/ECS, logging, and monitoring.
• Comprehensive knowledge of Linux, networking, containers, and Kubernetes.
• Familiarity with SIEM, EDR, CSPM, vulnerability management, WAF, and security monitoring platforms.
• Experience in developing or enhancing incident detection and response programs.
• Proven record in securing Microsoft 365 and Entra ID environments, focusing on identity protection, MFA, Conditional Access, privileged identity management, and access governance.
• Experience in implementing privileged access management and Just-In-Time access frameworks.
• Strong grasp of application and API security, including SAST, DAST, SCA, SBOMs, secrets management, and authentication/authorization.
• Proficient in Python, Bash, Terraform, APIs, CI/CD platforms, Infrastructure-as-Code security, and policy-as-code safeguards.
• Experience in leveraging AI tools and LLM-based assistants in security operations, including crafting prompts, assessing output accuracy, and integrating AI into workflows.
• Ability to articulate complex cybersecurity risks to engineering leaders, executives, and non-technical stakeholders.
• Preferred experience in multi-tenant SaaS security, CrowdStrike, Cloudflare, DevSecOps, offensive security or red-team initiatives, SOC 2, ISO 27001, NIST, or FedRAMP technical controls.
• Preferred certifications such as CISSP, CCSP, AWS Security Specialty, or GIAC.
• Eligibility for an annual discretionary bonus.
• Three options for medical plans.
• Coverage for dental and vision.
• Employer HSA contributions for employees enrolled in HDHP plans.
• 401(k) plan with a 100% match on the first 3% and 50% on the next 2% of employee contributions.
• Flexible paid time off policy.
• 7 sick days available.
• 9 paid company holidays each year.
• Paid leave for birth parents, non-birth parents, and caregivers.
• Reimbursement for surrogacy and adoption expenses.
• 100% employer-paid life and disability insurance.
• Voluntary options for hospital indemnity, critical illness, accident, and pet insurance.
• Healthcare FSA, HSA, and dependent care FSA available.
• One paid volunteer day each year.
EverCommerce
World Vision
ALB Conciergerie
Get handpicked remote jobs straight to your inbox weekly.