Accountabilities
Lead the implementation and maintenance of enterprise cybersecurity programs across cloud and corporate environments.
Manage compliance initiatives aligned with frameworks such as NYDFS Cybersecurity Regulation 500, ISO 27001, and other industry standards.
Conduct vulnerability assessments, coordinate penetration testing activities, and drive timely remediation of identified risks.
Monitor, investigate, and respond to security events using AWS security services, SIEM platforms, and security monitoring tools.
Develop and enhance incident response procedures, identity and access management (IAM) controls, and security governance practices.
Partner with software engineering teams to integrate security into the software development lifecycle through secure coding guidance, threat modeling, and application security reviews.
Support security audits, vendor risk assessments, client security reviews, and the preparation of technical security documentation.
Serve as a trusted advisor on cloud security, API security, and OWASP Top 10 best practices.
Requirements
7+ years of experience in cybersecurity engineering or information security, ideally within SaaS, cloud, or fintech environments.
Strong expertise in AWS cloud security, IAM, security monitoring, logging, and security operations.
Experience working with compliance frameworks such as NYDFS, ISO 27001, SOC 2, PCI DSS, or similar regulatory standards.
Hands-on experience with SIEM platforms, vulnerability management, penetration testing, and incident response.
Deep understanding of application security, API security, secure SDLC practices, and OWASP Top 10 principles.
Excellent communication and collaboration skills, with experience supporting audits and cross-functional security initiatives.
Professional certifications such as CISSP, CISM, CEH, or equivalent are highly desirable.
Strong analytical mindset with the ability to solve complex security challenges in fast-paced environments.
Benefits
Competitive compensation package.
Fully remote work environment.
Opportunity to work with modern cloud technologies and enterprise-scale security programs.
Exposure to complex security, compliance, and engineering initiatives.
Collaborative and supportive team culture.
Professional growth through challenging projects and ongoing learning opportunities.
Opportunity to influence security strategy and engineering best practices across the organization.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1