We're looking for a Security Engineer focused on designing and building scalable technical solutions. This manager role requires 8+ years of relevant experience.
About the role
Lead and develop a team of two cybersecurity professionals, providing coaching, prioritization, and performance management.
Serve as a working manager — actively participating in technical execution alongside the team, not solely in an oversight capacity.
Support the VP in shaping the cybersecurity strategy and translate it into actionable plans, priorities, and day-to-day activities.
Own the day-to-day GRC function, including cybersecurity policies, standards, procedures, and control frameworks.
Maintain the cybersecurity risk register; identify, assess, and track risks and remediation activities.
Support compliance with applicable regulations and frameworks (e.g., SOX, PCI, CMMC, NIST CSF).
Coordinate internal and external audits, evidence collection, and control testing.
Monitor regulatory and threat landscape changes and recommend policy updates.
Manage third-party and vendor cybersecurity risk assessments.
Perform software security reviews and drive remediation efforts.
Maintain the incident response plan and lead hands-on response to cybersecurity incidents.
Coordinate with internal teams, vendors, and external stakeholders during investigations.
Perform root cause analysis and drive corrective actions.
Participate directly in threat detection, monitoring, vulnerability management, and remediation activities.
Support secure design of systems, networks, and cloud environments in partnership with infrastructure and application teams.
Ensure security controls are consistently applied across the environment.
Manage the cybersecurity awareness and training program, including phishing simulations and end-user education.
Promote a culture of security awareness across the organization.
Manage cybersecurity tools, platforms, and third-party service providers (e.g., MSSP, SIEM, EDR).
Evaluate and recommend new technologies to strengthen the organization's security posture.
Provide regular updates to the VP and other stakeholders on cybersecurity posture, key risks, and initiative status.
Communicate technical concepts clearly to both technical and non-technical audiences.
Assist in developing and managing the cybersecurity budget, identifying cost-effective solutions and prioritizing spend against the highest risks.
Bachelor's degree required in Computer Science, Information Systems, or other technical discipline (or equivalent experience).