Lead, Cybersecurity

Posted Sep 18

This is a fully remote position, open to applicants in United States.

📋 Description

• Define and manage Smartlinx's cybersecurity initiatives across multi-tenant SaaS offerings, cloud infrastructure, corporate technology, data platforms, integrations, and third-party services.

• Oversee SaaS product and application security, cloud and infrastructure security, identity and access management, vulnerability management, security monitoring, incident response, third-party risk, and SOC 2 Type II readiness.

• Guide threat modeling, security architecture assessments, abuse-case analysis, risk evaluations, secure coding recommendations, automated security testing, penetration testing, and remediation efforts.

• Set secure cloud baselines and regulate network security, secrets, certificates, encryption, privileged credentials, patch management, endpoint protection, vulnerability scanning, and configuration management.

• Assess the security of databases, data platforms, data exchanges, backups, and disaster recovery environments.

• Lead SOC 2 Type II readiness activities, including control design, evidence gathering, auditor collaboration, remediation, management responses, and annual attestation processes.

• Maintain security policies, standards, procedures, risk registers, evidence repositories, exception records, remediation strategies, and executive compliance reports.

• Implement HIPAA and HITECH regulations and support customer contractual security commitments.

• Establish cohesive vulnerability management and third-party security programs.

• Define security monitoring and detection use cases, incident response protocols, escalation paths, investigations, containment strategies, recovery plans, forensics, and post-incident evaluations.

• Conduct tabletop exercises and ensure corrective actions are completed.

• Create an identity-first security model incorporating least privilege, multifactor authentication, privileged access management, conditional access, and access certification.

• Govern data classification, access, encryption, masking, retention, deletion, secure disposal, and data loss prevention measures.

• Develop a comprehensive cybersecurity strategy, operational plan, budget, staffing model, roadmap, executive and Board reporting, and security scorecard.

• Choose and manage security tools, provide security training, and recruit, mentor, and develop security team members.


⛳️ Requirements

• Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related field, or equivalent practical experience.

• Over 8 years of progressive experience in product, application, cloud, infrastructure, or security operations disciplines.

• At least 3 years in a lead, principal, architect, or security program ownership position.

• Experience in securing multi-tenant B2B SaaS products within healthcare, payroll, HR technology, or other regulated environments.

• Proven experience in protecting PHI, PII, financial, or other sensitive information.

• Practical experience leading a successful SOC 2 Type II audit cycle.

• Strong expertise in Microsoft Azure security across cloud networking, identity, compute, storage, databases, containers, Kubernetes, infrastructure as code, secrets management, logging, monitoring, backup, and recovery.

• Extensive knowledge of secure software development, threat modeling, web, mobile, and API security, authentication, authorization, tenant isolation, OWASP risks, and DevSecOps practices.

• Hands-on experience with SAST, DAST, SCA, SBOM, secrets scanning, SIEM, EDR, DLP, WAF, CSPM, vulnerability scanning, penetration testing, and other related security capabilities.

• Experience in managing vulnerabilities, security findings, and incidents through risk assessment, containment or remediation, retesting, exception management, post-incident review, and executive reporting.

• Familiarity with SOC 2 Trust Services Criteria, NIST Cybersecurity Framework, CIS Controls, ISO 27001, and HITRUST.

• Ability to make risk-based decisions, balance security with product delivery, influence cross-functional stakeholders, and communicate technical risks clearly.

• Relevant certifications such as CISSP, CCSP, CISM, CISA, CSSLP, OSCP, GIAC, HITRUST CCSFP, or Microsoft Azure Security Engineer are preferred.

• Experience with Entra ID, Defender, Sentinel, Azure DevOps, Snowflake, or Microsoft Fabric is preferred.


🏝️ Benefits

• 10% bonus eligibility.

• Remote work environment.

• Medical insurance.

• Dental insurance.

• Vision insurance.

• FSA.

• HSA.

• Life insurance.

• Pet insurance.

• 401(k).

• Opportunities for professional development and skill enhancement.

• Occasional travel up to 15%.

People also viewed

Sony Interactive Entertainment17 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads18 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j18 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)19 hours ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting19 hours ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International20 hours ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers