Cybersecurity Engineering & Operations Director

New
O
OnitLegal operations SaaS
Remote - USAFull-TimeDirector
Salary150,000 - 190,000 USD per year
Apply NowOpens the employer's application page

Job Details

Experience
10+ years of progressive cybersecurity experience, including 5+ years in security leadership or management roles
Required Skills
PythonKubernetesTerraform

Requirements

  • 10+ years of progressive cybersecurity experience, including 5+ years in security leadership or management roles.
  • Experience leading security engineering, security operations, or cloud security functions, including managing managers and technical teams.
  • Deep expertise securing cloud-native enterprise SaaS applications and hands-on AWS security experience with IAM, VPC, EC2, RDS, S3, EKS/ECS, logging, and monitoring.
  • Strong knowledge of Linux, networking, containers, and Kubernetes.
  • Experience with SIEM, EDR, CSPM, vulnerability management, WAF, and security monitoring platforms, and building or improving incident detection and response programs.
  • Experience securing Microsoft 365 and Entra ID, including identity protection, MFA, Conditional Access, privileged identity management, and access governance.
  • Understanding of application and API security, including SAST, DAST, SCA, SBOMs, secrets management, and authentication and authorization.
  • Experience with security automation and scripting using Python, Bash, Terraform, APIs, and CI/CD platforms, including Infrastructure-as-Code security and policy-as-code guardrails.
  • Experience using AI tools and LLM-based assistants in security work, including evaluating output accuracy and integrating AI into security workflows.
  • Ability to communicate cybersecurity risks to technical and non-technical stakeholders and balance risk reduction with business objectives and engineering velocity.
  • Preferred: multi-tenant SaaS security, CrowdStrike, Cloudflare, DevSecOps, offensive security or red-team programs, and familiarity with SOC 2, ISO 27001, NIST, or FedRAMP technical controls.
  • Preferred certifications: CISSP, CCSP, AWS Security Specialty, or GIAC.

Responsibilities

  • Develop and execute cybersecurity engineering and operations strategy, translating risk and business priorities into technical roadmaps, architecture standards, and measurable outcomes.
  • Lead the design and improvement of security controls across AWS and corporate environments, including cloud identity, networks, workloads, containers, and data protections.
  • Deliver security automation as code using Terraform, Python, CI/CD, and policy-as-code.
  • Own security operations and incident response, including detection, investigation, containment, eradication, and recovery.
  • Maintain and exercise incident response plans, playbooks, and runbooks, and build automated detection and response workflows across SIEM, SOAR, EDR, and cloud-native tools.
  • Own vulnerability and exposure management across applications, cloud, endpoints, and external attack surfaces; set risk-based remediation SLAs and drive root-cause fixes.
  • Provide security leadership for Microsoft 365, Entra ID, corporate endpoints and email, and application and product security across the SDLC.
  • Lead and develop the cybersecurity manager, engineers, and security operations staff; define team structure, career paths, and operating processes.
  • Manage security vendors, penetration testing, and managed security services, and advise Engineering, IT, Product, and executive leadership.
View Full Description & ApplyYou'll be redirected to the employer's site
150,000 - 190,000 USD per year
Apply Now