Senior IT Security Engineer

Init-Innovations-in-Transportation-In

Chesapeake (VA)

Hybrid

USD 125,000 - 150,000

Full time

11 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Vacation days 15
Holidays 11
Parental leave
Health insurance
Dental insurance
401(k) match
Life insurance
Disability insurance
Flexible Spending Accounts
Education assistance

Job summary

INIT Innovations in Transportation, Inc. is seeking a Senior IT Security Engineer to drive security controls, security operations, and GRC across INIT's internal corporate infrastructure and customer-facing transit technology deployments.

This role contributes to security architecture, operations, and control framework for PCI DSS, SOC 2, and ISO 27001, working with IT teams and reporting to the Director of IT.

Qualifications

  • 10+ years of experience in information security, risk management, or compliance with increasing responsibility.
  • Proven experience establishing and directing information security strategy, governance, and risk management programs.
  • Security certification such as CISSP, CISM, CISA, or CRISC, or actively pursuing one.
  • Experience implementing or designing systems within PCI DSS, SOC 2, ISO 27001, or NIST 800-53.
  • Experience serving as incident commander or leading incident response efforts.
  • Ability to communicate security posture, risk, and compliance status to senior management.
  • Strong leadership, problem-solving, and critical thinking abilities.
  • Ability to collaborate across IT Operations, IT Systems Engineering, and software development teams.

Responsibilities

  • Establish security vision, strategy, and roadmaps with the Director of IT.
  • Direct the selection and lifecycle of security tools and infrastructure security direction.
  • Set identity access and security hardening standards across the environment.
  • Evaluate security requirements and architecture for customer projects and proposals.
  • Identify strategic trends affecting security posture and customer trust.
  • Evaluate and guide secure adoption of AI tools balancing productivity and risk.
  • Act as incident commander or alternate during security incidents.
  • Lead tabletop exercises and translate findings into playbooks and controls.
  • Communicate security posture and incident status to senior management and customers.
  • Oversee security strategy across customer projects and contractual obligations.
  • Direct risk management program and maintain PCI DSS, SOC 2, ISO 27001 mappings.
  • Coordinate audits, remediation, and regulatory requirements.
  • Lead security policy development and third-party vendor risk management.
  • Drive security awareness training and risk-based vulnerability prioritization.

Skills

Information security
Governance
Risk management
Compliance
Incident response

Tools

Microsoft Azure
Cloudflare
Arctic Wolf
Tenable

Job description

Job Category: Network and Information Management

Requisition Number: SENIO001303

  • Posted : July 28, 2026
  • Full-Time
  • Hybrid
Locations

Showing 1 location

Chesapeake, VA 23320, USA

Description

About INIT

INIT Innovations in Transportation, Inc. is a leading provider of hardware, software, service, support, and operations management solutions for public transportation companies across North America. As a turnkey supplier, INIT develops, produces, installs, and maintains integrated hardware and software solutions for all key tasks required by transportation authorities, including fare collection systems, passenger counting, CAD/AVL systems, passenger information systems, and other Intelligent Transportation System solutions.

Our Information Technology team designs, builds, operates, and maintains infrastructure in support of INIT software solutions deployed for transit agency customers in major metropolitan areas including Atlanta, Houston, Los Angeles, San Diego, Seattle, Portland, Tampa, Honolulu, and more.

Position Summary

INIT is seeking a Senior IT Security Engineer to drive security controls, security operations, and GRC activities across INIT's internal corporate infrastructure and customer-facing transit technology deployments.

This role contributes to the security architecture, security operations and control framework across PCI DSS, SOC 2, and ISO 27001. The Senior IT Security Engineer works closely with the IT Security Administrator, IT Operations, and IT Systems Engineering teams, and reports to the Director of IT.

Security Strategy
  • Establish security vision, strategy, and roadmaps with the Director of IT, encompassing internal programs and customer-facing security commitments.
  • Direct the selection and lifecycle of security tools, architectures, and infrastructure security direction across the organization.
  • Establish identity, access, and security hardening standards, including Conditional Access, privileged access, and CIS benchmark requirements, for implementation across the environment.
  • Evaluate security requirements and architecture for customer projects and proposals, identifying gaps, strategies, and budgets needed to meet requirements, and make final decisions on customer project security architecture.
  • Identify strategic trends affecting the company's security posture and customer trust.
  • Evaluate and guide secure adoption of AI tools and platforms across IT and business functions, balancing productivity gains against data protection, compliance, and vendor risk.
Security Operations
  • Serve as incident commander or alternate incident commander during security incidents.
  • Direct threat intelligence efforts, monitoring emerging threats, vulnerabilities, and attacker techniques relevant to the transit technology industry, and translating findings into operational and architectural changes.
  • Lead the tabletop exercise program, setting cadence, scope, and participation across technical and business stakeholders, and direct post-exercise and post-incident retrospectives that translate findings into playbook and control updates.
  • Communicate security posture, risk exposure, and incident status to senior management and, as needed, to customers.
  • Oversee operational security strategy across customer projects, including contractual security and compliance obligations.
GRC (Governance, Risk, and Compliance)
  • Direct the organization's risk management program, identifying, assessing, and prioritizing information security risks and recommending treatment strategies to leadership.
  • Establish and maintain the security control framework mapping across PCI DSS, SOC 2, and ISO 27001, ensuring controls satisfy overlapping framework requirements.
  • Serve as the primary point of contact for external auditors and assessors during compliance audits and certification cycles, and direct remediation of audit findings and gap assessment outcomes.
  • Evaluate new regulatory and contractual requirements and translate them into control requirements.
  • Set direction for the organization's security policy suite, leading the creation, review, and revision of information security policies and procedures.
  • Lead third-party vendor security risk management, directing vendor risk assessments, critical vendor classification, and ongoing monitoring of vendor compliance obligations.
  • Direct the security awareness and training program, setting curriculum priorities, campaign cadence, and risk-based focus areas for the organization.
  • Set risk-based prioritization standards for the vulnerability management program and review remediation trends against risk tolerance.
Required Qualifications
  • 10+ years of experience in information security, risk management, or compliance, with increasing responsibility.
  • Proven experience establishing and directing information security strategy, governance, and risk management programs.
  • Security-relevant certification required, such as CISSP, CISM, CISA, or CRISC, or actively pursuing one.
  • Experience implementing, assessing, or designing systems within PCI DSS, SOC 2, ISO 27001, or NIST 800-53 frameworks.
  • Experience serving as incident commander or leading incident response efforts.
  • Proven ability to communicate security posture, risk, and compliance status to senior management and external stakeholders.
  • Strong leadership, problem-solving, and critical thinking abilities.
  • Ability to work collaboratively across IT Operations, IT Systems Engineering, and software development teams.
Preferred Qualifications
  • CISSP, CISM, CISA, or CRISC certification held, rather than in progress.
  • Experience directing GRC programs or serving as the primary point of contact for external auditors and QSAs.
  • Experience mapping controls across multiple compliance frameworks, including PCI DSS, SOC 2, and ISO 27001.
  • Experience owning an enterprise incident response and tabletop exercise program.
  • Familiarity with cloud security architecture in Microsoft Azure and modern security tooling such as Cloudflare, Arctic Wolf, and Tenable.
  • Experience in the transportation, transit, or critical infrastructure sector.
Work Environment and Travel
  • Hybrid position. Work from Hampton Roads, VA is preferred; remote candidates will be considered.
  • Regular travel to INIT's Hampton Roads, VA offices expected for team collaboration, audit activities, and project engagement.
  • Travel to customer sites across North America required as project and audit needs dictate.
  • Must be available to adjust work hours as needed to support incident response activities and incident command duties outside of normal business hours.
What INIT Offers
  • The opportunity to own and direct the security strategy protecting mission-critical transit technology systems deployed across major North American cities.
  • Ownership of INIT's risk management, governance, and compliance program across PCI DSS, SOC2, and ISO 27001.
  • A collaborative team environment working with IT Operations, IT Systems Engineering, and software development teams.
  • Support for professional development and advancement toward executive-level security certifications.
  • A hybrid work model with flexibility for remote work combined with meaningful in-person collaboration.
  • We offer a comprehensive benefits package designed to support your health, financial well-being, and work-life balance, including:
  • Competitive paid time off, starting with 15 days of vacation , increasing with tenure, plus 11 paid holidays , a personal day , and a community service day
  • 6 paid sick days annually
  • Paid parental leave
  • 100% employer-paid health and dental insurance for employees , with generous dependent coverage contributions
  • 401(k) with company match (currently dollar-for-dollar up to 5% of salary))
  • Company-paid life insurance , plus short-term and long-term disability insurance
  • Flexible Spending Accounts (medical, dependent care, and limited FSA options) with employer contributions for eligible medical plans
  • Annual benefit allowance for optional employee benefits
  • Continuing education assistance and support for professional development
  • Optional benefits including accident insurance, legal services, identity theft protection, adoption assistance, education assistance, and student loan repayment assistance
Compensation

The annual salary range for this position is $125,000 -$150,000 , depending on experience.

INIT Innovations in Transportation, Inc. is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status, or any other characteristic protected by law.

Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior IT Security Engineer
Senior IT Security Engineer

Socket.dev • Chesapeake (VA)

Hybrid
USD 125,000 - 150,000
Health insurance
401(k) with company match
Continuing education assistance
+1
Senior IT Security Engineer
Senior IT Security Engineer

INIT Innovations in Transportation, Inc. • Chesapeake (VA)

Hybrid
USD 125,000 - 150,000
Health insurance
Hybrid work model
401(k) match
IT Operations Engineer
IT Operations Engineer

Init-Innovations-in-Transportation-In • Chesapeake (VA)

Hybrid
USD 95,000 - 115,000
Hybrid work model
Competitive benefits
Healthy PTO and holidays
+1
IT Operations Engineer
IT Operations Engineer

INIT Innovations in Transportation, Inc. • Chesapeake (VA)

Hybrid
USD 95,000 - 115,000
Hybrid work model
Health and dental insurance
401(k) with company match
+2
Project Manager II
Project Manager II

INIT Innovations in Transportation, Inc. • Chesapeake (VA)

On-site
USD 90,000 - 115,000
Vacation and holidays
Health and dental insurance
401(k) with company match
+2
Project Manager II
Project Manager II

INIT Innovations in Transportation, Inc. • Seattle (WA)

On-site
USD 90,000 - 115,000
15 days vacation + 11 holidays + 1
Sick days (6 annually)
Parental leave
+1
Project Manager II
Project Manager II

INIT Innovations in Transportation • Chesapeake (VA), Seattle (WA)

On-site
USD 90,000 - 115,000
Health insurance
Paid time off (vacation)
13 paid holidays
+3
Project Manager II
Project Manager II

Init-Innovations-in-Transportation-In • Chesapeake (VA)

On-site
USD 90,000 - 115,000
Vacation time (15 days)
11 holidays
Personal day
+10
Senior IT Security Engineer: Strategy & GRC Lead
Senior IT Security Engineer: Strategy & GRC Lead

Init-Innovations-in-Transportation-In • Chesapeake (VA)

Hybrid
USD 125,000 - 150,000
Vacation days 15
Holidays 11
Parental leave
+7
Senior IT Security Engineer — PCI/SOC2/ISO 27001 Lead
Senior IT Security Engineer — PCI/SOC2/ISO 27001 Lead

Socket.dev • Chesapeake (VA)

Hybrid
USD 125,000 - 150,000
Health insurance
401(k) with company match
Continuing education assistance
+1