Lead Security Engineer
New
J
JobgetherSaaS, Hospitality, Fintech
BrazilFull-TimeLead
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 8+ years of experience in security engineering or a closely related security discipline; 2+ years of experience leading a security team.
- Required Skills
- AWSRisk Management
Requirements
- 8+ years of experience in security engineering or a closely related security discipline.
- 2+ years of experience leading a security team as a manager or technical lead.
- Demonstrated experience owning compliance programs end to end, with expertise in frameworks such as SOC 2 Type II, PCI DSS, ISO 27001, or similar.
- Strong hands-on technical foundation in cloud security, particularly AWS.
- Strong knowledge of identity and access management, application security, and vulnerability management.
- Experience with vendor and third-party risk management.
- Experience reviewing security requirements and contractual security terms with customers and vendors.
- Proven ability to build pragmatic, risk-based security programs within a growth-stage SaaS organization.
- Exceptional written and verbal communication skills, with the ability to translate technical security concepts for both technical and executive audiences.
- Strong leadership, coaching, prioritization, and stakeholder-management skills.
- Ability to balance strategic security leadership with hands-on technical execution.
- Strong judgment and ability to assess security risks in the context of business objectives.
Responsibilities
- Lead, coach, and develop a team of security engineers, including hiring, performance management, prioritization, and career development.
- Own the security and compliance program end to end, including SOC 2, PCI DSS, GDPR/CCPA, and other applicable security and privacy frameworks.
- Establish, maintain, and continuously improve the organization’s security control framework, policies, standards, and overall risk posture.
- Serve as the primary security point of contact for customers, partners, auditors, and internal stakeholders.
- Communicate the organization’s security posture effectively to audiences ranging from customer CISOs and security teams to executive leadership.
- Manage vendor and third-party security risk, including evaluating security practices and requirements.
- Review security terms and requirements within customer and vendor contracts.
- Develop, maintain, and communicate security policies and standards across the organization.
- Lead security awareness and training initiatives to strengthen security practices company-wide.
- Set the technical direction for security tooling and capabilities.
- Remain hands-on with security architecture assessments, threat modeling, and technical reviews alongside engineering teams.
View Full Description & ApplyYou'll be redirected to the employer's site