
Lead, Cybersecurity
Posted Sep 18

Posted Sep 18
This is a fully remote position, open to applicants in United States.
• Define and manage Smartlinx's cybersecurity initiatives across multi-tenant SaaS offerings, cloud infrastructure, corporate technology, data platforms, integrations, and third-party services.
• Oversee SaaS product and application security, cloud and infrastructure security, identity and access management, vulnerability management, security monitoring, incident response, third-party risk, and SOC 2 Type II readiness.
• Guide threat modeling, security architecture assessments, abuse-case analysis, risk evaluations, secure coding recommendations, automated security testing, penetration testing, and remediation efforts.
• Set secure cloud baselines and regulate network security, secrets, certificates, encryption, privileged credentials, patch management, endpoint protection, vulnerability scanning, and configuration management.
• Assess the security of databases, data platforms, data exchanges, backups, and disaster recovery environments.
• Lead SOC 2 Type II readiness activities, including control design, evidence gathering, auditor collaboration, remediation, management responses, and annual attestation processes.
• Maintain security policies, standards, procedures, risk registers, evidence repositories, exception records, remediation strategies, and executive compliance reports.
• Implement HIPAA and HITECH regulations and support customer contractual security commitments.
• Establish cohesive vulnerability management and third-party security programs.
• Define security monitoring and detection use cases, incident response protocols, escalation paths, investigations, containment strategies, recovery plans, forensics, and post-incident evaluations.
• Conduct tabletop exercises and ensure corrective actions are completed.
• Create an identity-first security model incorporating least privilege, multifactor authentication, privileged access management, conditional access, and access certification.
• Govern data classification, access, encryption, masking, retention, deletion, secure disposal, and data loss prevention measures.
• Develop a comprehensive cybersecurity strategy, operational plan, budget, staffing model, roadmap, executive and Board reporting, and security scorecard.
• Choose and manage security tools, provide security training, and recruit, mentor, and develop security team members.
• Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related field, or equivalent practical experience.
• Over 8 years of progressive experience in product, application, cloud, infrastructure, or security operations disciplines.
• At least 3 years in a lead, principal, architect, or security program ownership position.
• Experience in securing multi-tenant B2B SaaS products within healthcare, payroll, HR technology, or other regulated environments.
• Proven experience in protecting PHI, PII, financial, or other sensitive information.
• Practical experience leading a successful SOC 2 Type II audit cycle.
• Strong expertise in Microsoft Azure security across cloud networking, identity, compute, storage, databases, containers, Kubernetes, infrastructure as code, secrets management, logging, monitoring, backup, and recovery.
• Extensive knowledge of secure software development, threat modeling, web, mobile, and API security, authentication, authorization, tenant isolation, OWASP risks, and DevSecOps practices.
• Hands-on experience with SAST, DAST, SCA, SBOM, secrets scanning, SIEM, EDR, DLP, WAF, CSPM, vulnerability scanning, penetration testing, and other related security capabilities.
• Experience in managing vulnerabilities, security findings, and incidents through risk assessment, containment or remediation, retesting, exception management, post-incident review, and executive reporting.
• Familiarity with SOC 2 Trust Services Criteria, NIST Cybersecurity Framework, CIS Controls, ISO 27001, and HITRUST.
• Ability to make risk-based decisions, balance security with product delivery, influence cross-functional stakeholders, and communicate technical risks clearly.
• Relevant certifications such as CISSP, CCSP, CISM, CISA, CSSLP, OSCP, GIAC, HITRUST CCSFP, or Microsoft Azure Security Engineer are preferred.
• Experience with Entra ID, Defender, Sentinel, Azure DevOps, Snowflake, or Microsoft Fabric is preferred.
• 10% bonus eligibility.
• Remote work environment.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• FSA.
• HSA.
• Life insurance.
• Pet insurance.
• 401(k).
• Opportunities for professional development and skill enhancement.
• Occasional travel up to 15%.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.