Summary
Lead the cyber risk and security engineering function to safeguard systems and embed security across digital and physical environments. Collaborate cross-functionally to assess and prioritize risks, implement controls, and drive enterprise-wide security awareness and identity governance. Serve as a technical leader influencing security strategy, remediation, and measurable behavior change.
Responsibilities
- Lead implementation and integration of security controls across cloud, network, endpoint, and physical environments.
- Develop and operate continuous risk assessment, monitoring, and remediation programs.
- Translate technical risks into actionable requirements and influence stakeholders across engineering, operations, retail, and legal.
- Build and scale security awareness and training programs to drive measurable behavior change.
- Drive identity and access governance, ensuring appropriate access while minimizing business friction.
- Embed security into CI/CD pipelines and infrastructure through DevSecOps and infrastructure-as-code practices.
- Advise on compliance, apply industry frameworks, and act as a decisive technical leader within a matrixed organization.
Requirements
- Minimum 10 years of cyber security engineering experience with hands-on leadership in enterprise environments.
- Proven experience across cloud platforms (Azure, AWS, GCP), networks, endpoints, and security technologies such as SIEM, EDR, and PAM.
- Proficiency in secure software development, DevSecOps, and infrastructure-as-code (Terraform, Ansible).
- Deep knowledge of identity and access management, data loss prevention, encryption, and secure communications.
- Practical experience applying frameworks such as NIST 800-53, ISO 27001, and CIS; PCI DSS experience preferred.
- Bachelor’s degree in computer science or related field or equivalent experience; security certifications (CISSP, CISM, CISA) preferred.
- Strong communication skills with the ability to present technical risk to senior leadership.