waypointjobs

Aspenware

Lead InfoSec Engineer

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Who We Are:

Aspenware empowers mountain resorts and ski areas to deliver the ideal digital guest experience. Our guest-facing e-commerce and registration software is the most capable in the industry and is used by millions of skiers worldwide to process over a billion dollars in annual sales. The resorts we work with trust the innovation and thought leadership that Aspenware provides, and they leverage the operational advantages of our platform to grow their businesses.

We are a talented and high-performing team and welcome the opportunity to learn from one another.

Aspenware makes hiring decisions based on how well candidates align with our Core Values. Aspenware employees are…

Dependable: We take ownership. We are accountable and adaptable. We have a can-do attitude and are willing to pivot.

Caring: We care about our co-workers and our clients. We are mindful of and inspired by the impact our work has on our communities.

Innovative: We are thought leaders who bring creativity and a desire for innovation to everything we do. We are continually improving ourselves and our surroundings.

Curious: We challenge default processes while assuming best intent, seeking to understand before judging. We ask good questions to spark learning, better decisions, and smarter outcomes. We make the extra effort to gain a deeper understanding of a situation so we can provide better solutions.

The Role:

The Lead Infosec Engineer will be responsible for leading Aspenware’s existing security program and optimizing it to be even more robust.

You will manage Aspenware’s security operations including IT vendor and MSSP relationships. You will lead efforts to mitigate existing and emerging cybersecurity threats. You will assess, prioritize, and remediate security risks to improve Aspenware’s overall cybersecurity posture.

This is a key role at Aspenware and reports to the Director of Technology Operations & Security. You will work closely with the VP of Technology, other engineering leaders, and business stakeholders to represent the security needs of our platform and hold the enterprise to a rigorous standard of security. Finally, you will collaborate with the Infosec teams at our parent company, Alterra Mountain Co. You will be responsible for sharing strategies, roadmap progress, and incident retrospectives wherever the larger enterprise is impacted.

What You Will Do:

Partner with engineering teams and systems architects to ensure the security of our products, cloud infrastructure, and technical platform

Be the champion of rigorous security standards when debating resource allocation tradeoffs

Improve Aspenware’s AppSec and SDLC security

Understand key security attack vectors and protect Aspenware from malicious actors who wish to abuse our system.

Manage our security vendor relationships with respect to requirements and technical support

Lead the company from its recently earned Type I SOC 2 accreditation through Type 2 accreditation.

Assist end users to remediate security issues.

Work with external vendors to provide oversight for computers, devices, and networks in a remote work environment

Manage and evaluate external vendors to conduct pen testing, endpoint testing, purple team testing, and PCI scans

Develop and document network security reference architectures, design patterns, roadmaps, and other architectural artifacts aligned with policies, standards, and industry best practices

Work closely with our DevOps team to manage cloud security in Azure:

Evaluate Azure cloud and hybrid security services, tools, and appliances in the areas of (but not limited to): intrusion detection, intrusion prevention, packet capture, and quarantine

Assess network/cloud security posture and recommend modifications for enhancements, improvements, and mitigations

Collaborate with enterprise partners and incident response teams regarding requirements and deployment of security services, tools, and appliances

Review access control policies and assist in Identity and Access Management through MS Entra

Ensure compliance with NIST CSF or similar frameworks and meet disclosure obligations

Identify opportunities to improve existing security processes, policies, and tooling

Help cultivate and foster a culture of security across the entire organization by driving awareness and promoting a cohesive narrative around security

Perform in-depth investigations when the suspicion of a threat emerges.

Coordinate mitigation and remediation plans to address critical risks

Who You Are:

You are passionate about cybersecurity and have a track record in improving the security posture of software engineering organizations. You are a proud advocate of rigorous security standards. You take pride in staying on top of and ahead of information security techniques, standards, and trends. You are a lifelong learner who is constantly educating and challenging yourself to stay ahead of the cybersecurity curve. You thrive in small to mid-size companies where you can take ownership and practice a blend of strategic planning, communication, and individual contribution. You are skilled at communicating with peers, leadership, and clients. You can define and execute on a complex department roadmap and proactively update stakeholders on the status of each of your parallel initiatives.

You Ideally Have:

Experience owning the Infosec strategy for SaaS companies, especially in ecommerce

Expert knowledge of AppSec, Infrastructure security, access control, and GRC

4+ years of experience in a cybersecurity role within a software development organization

8+ years in technical roles – as a software engineer, information security analyst or similar

Masters or bachelor's degree in Information Systems with a focus in cyber security or equivalent experience / certifications

Experience with NIST CSF, ISO27001, PCI, SOC2 or similar standards/certifications

Experience with OWASP or similar standards.

Experience with DevSecOps

Direct experience with Azure cloud security

Hands-on experience establishing and configuring security controls for Microsoft Azure and Microsoft 365 components

Understanding of DDOS and other infrastructure threats at the edge

Strong understanding of security as it relates to CDN, API management, and load balancing technologies

Strong understanding of Azure monitoring capabilities

Willingness to jump into a complex, fast-paced environment.

What’s In It for You:

4 weeks of PTO to start and increases with seniority

11 paid holidays

6 days of sick time

Paid parental leave for both primary and secondary parents

Medical, dental, and vision insurance

Life insurance

401k plan with a 5% match

Annual all-company ski day

Seasonal Ski Pass – Ikon Pass

National Park Pass

Annual Wellness Stipend

Flexible work environment

Salary: $145,000.00-$175,000.00Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job