We are looking for an experienced Cyber Security Team Lead with strong hands-on experience in Cybersecurity Engineering, Application Security, SSDLC, threat modeling, vulnerability management, and security assessments.
Day to Day Job Duties: (what this person will do on a daily/weekly basis)
- Implement and maintain cybersecurity controls and secure development practices across digital products and platforms.
- Collaborate with Information Security, Enterprise Architects, Software Engineers, and Project Managers on the design and delivery of secure solutions.
- Ensure compliance with enterprise security architecture, governance frameworks, and industry security standards.
- Translate cybersecurity and privacy requirements into actionable product development roadmaps.
- Perform technical security assessments, including code reviews, static and dynamic application security testing, and penetration testing.
- Conduct threat modeling, vulnerability assessments, and cyber risk analysis activities.
- Recommend and implement mitigation strategies to reduce identified security risks.
- Enforce information security and data privacy requirements related to regulations such as GDPR, CPRA, SOX, and PCI-DSS.
- Investigate, resolve, and escalation security incidents and support requests as required.
- Monitor emerging cybersecurity threats, vulnerabilities, and attack methodologies.
- Deliver secure coding awareness and cybersecurity training sessions to development teams.
- Support continuous improvement initiatives related to application security and cybersecurity governance.
Basic Qualifications: (what are the skills required to this job with minimum years of experience on each)
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field.
- Minimum 5+ years of hands-on experience in Cybersecurity Engineering, Application Security, or Information Security.
- At least 5+ years of experience implementing security controls and secure software development lifecycle (SSDLC) practices.
- Experience performing threat modeling, risk assessments, vulnerability management, and penetration testing.
- Experience conducting application security reviews, including static and dynamic code analysis.
- Hands-on experience with security tools such as Qualys, SonarQube, Detectify, GitHub Advanced Security, or equivalent solutions.
- Strong understanding of information security frameworks, methodologies, standards, and best practices.
- Experience securing cloud environments, web applications, APIs, and enterprise platforms.
- Experience implementing and maintaining regulatory compliance requirements including GDPR, CPRA, SOX, and PCI-DSS.
- Strong understanding of secure software engineering principles and common programming languages.
- Experience working in Agile/Scrum environments and collaborating with cross-functional teams.
- Strong analytical, troubleshooting, risk assessment, and problem-solving skills.
- Ability to communicate technical security concepts effectively to both technical and non-technical stakeholders.