About this opportunity
FTAI Aviation Ltd. lists this Principal Security Engineer opportunity in new york, New York. Review the employer’s description below for duties, qualifications and application requirements.
Job description
FTAI owns and maintains commercial jet engines with a focus on the Maintenance, Repair and Exchange (MRE) of CFM56 and V2500 engines. FTAI’s propriety portfolio of products, including The Module Factory and a joint venture to distribute engine PMA helps make CFM56 and V2500 engine maintenance simpler, more cost-effective, significantly faster, and more environmentally friendly. Additionally, FTAI owns and leases jet aircraft which often facilitates the acquisition of engines at attractive prices. FTAI invests in aviation assets and aerospace products that generate strong and stable cash flows with the potential for earnings growth and asset appreciation.
FTAI operates globally and has offices in New York, Miami, Montreal, California, Singapore, Dubai, United Kingdom and Ireland.
JOB OVERVIEW
We are seeking a Principal Security Engineer to lead the security program for a public, multi-site organization in a regulated environment. This is a hands-on individual-contributor role that both implements technical controls and drives the policies behind them. Partnering with the MSP, vCISO, IT, and Legal, you will set technical direction and execute it—tuning controls, maturing policy, and aligning the program to recognized frameworks and regulatory requirements
Responsibilities:
Drive the technical cybersecurity strategy and roadmap; report security posture and material risk to senior leadership
Design, configure, and maintain hands-on controls across network, endpoint, identity, and cloud (firewall rules, segmentation, VPNs, IDS/IPS, EDR, MFA)
Develop and maintain security policies aligned to NIST CSF, ISO 27001, and CIS and to regulatory requirements, ensuring controls actually enforce them
Manage and tune the security stack (SIEM, EDR, email security); build detection rules, alerts, and dashboards
Lead incident response end to end and drive risk-based vulnerability and patch management to closure across infrastructure, endpoints, and cloud
Own the controls framework and third-party/vendor risk program, coordinating with internal audit/GRC and the legal team
Collaborate with MSP and vCISO (managing scope, SLAs, escalation) while keeping core decisions in-house
Harden identity infrastructure (AD/Entra ID) and run the security awareness program across sites
Qualifications:
7+ years across IT and cybersecurity, including a hands-on technical foundation and 3+ years driving a security program as a senior individual contributor
Proven ability to both implement technical controls and author the policies and governance behind them
Experience securing a public and/or regulated, multi-site environment (e.g., SOX, FINRA, FAA), including audit and control ownership
Command of NIST CSF, ISO 27001, CIS, and SOX/ITGC, with experience owning control evidence through external audits
Strong cloud (Azure and/or AWS) and enterprise network security—firewalls, VPNs, segmentation, and IDS/IPS
Hands-on with SIEM (e.g., Microsoft Sentinel) and endpoint protection (e.g., SentinelOne), plus scripting (PowerShell and/or Python) and identity hardening (AD/Entra ID)
#J-18808-Ljbffr
Worksite address
new york, NY, 10261, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.