Lead Security Engineer

New
J
JobgetherSaaS, Hospitality, Fintech
BrazilFull-TimeLead
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
8+ years of experience in security engineering or a closely related security discipline; 2+ years of experience leading a security team.
Required Skills
AWSRisk Management

Requirements

  • 8+ years of experience in security engineering or a closely related security discipline.
  • 2+ years of experience leading a security team as a manager or technical lead.
  • Demonstrated experience owning compliance programs end to end, with expertise in frameworks such as SOC 2 Type II, PCI DSS, ISO 27001, or similar.
  • Strong hands-on technical foundation in cloud security, particularly AWS.
  • Strong knowledge of identity and access management, application security, and vulnerability management.
  • Experience with vendor and third-party risk management.
  • Experience reviewing security requirements and contractual security terms with customers and vendors.
  • Proven ability to build pragmatic, risk-based security programs within a growth-stage SaaS organization.
  • Exceptional written and verbal communication skills, with the ability to translate technical security concepts for both technical and executive audiences.
  • Strong leadership, coaching, prioritization, and stakeholder-management skills.
  • Ability to balance strategic security leadership with hands-on technical execution.
  • Strong judgment and ability to assess security risks in the context of business objectives.

Responsibilities

  • Lead, coach, and develop a team of security engineers, including hiring, performance management, prioritization, and career development.
  • Own the security and compliance program end to end, including SOC 2, PCI DSS, GDPR/CCPA, and other applicable security and privacy frameworks.
  • Establish, maintain, and continuously improve the organization’s security control framework, policies, standards, and overall risk posture.
  • Serve as the primary security point of contact for customers, partners, auditors, and internal stakeholders.
  • Communicate the organization’s security posture effectively to audiences ranging from customer CISOs and security teams to executive leadership.
  • Manage vendor and third-party security risk, including evaluating security practices and requirements.
  • Review security terms and requirements within customer and vendor contracts.
  • Develop, maintain, and communicate security policies and standards across the organization.
  • Lead security awareness and training initiatives to strengthen security practices company-wide.
  • Set the technical direction for security tooling and capabilities.
  • Remain hands-on with security architecture assessments, threat modeling, and technical reviews alongside engineering teams.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now