This job is closed
Applications are no longer available for this announcement. Explore current related opportunities below.
Job description
This is a remote position.
The Security Lead is responsible for defining and executing the organization’s cybersecurity strategy, leading security architecture, managing risk, and ensuring compliance with global security standards. This role works closely with engineering, DevOps, product, compliance, and leadership teams to embed security into all layers of the technology stack.
Key Responsibilities
Define and lead enterprise-wide cybersecurity strategy and architecture.
Oversee application, infrastructure, and cloud security across all systems.
Lead threat modeling, risk assessments, and vulnerability management programs.
Establish and enforce security policies, standards, and best practices.
Monitor, detect, and respond to security incidents and breaches.
Ensure secure software development practices (DevSecOps) are implemented.
Conduct security audits, penetration testing coordination, and remediation tracking.
Collaborate with Engineering and DevOps teams to embed security in CI/CD pipelines.
Ensure compliance with regulatory and industry standards (e.g., ISO 27001, PCI-DSS, GDPR).
Lead identity and access management (IAM) strategies and controls.
Provide security guidance for cloud infrastructure and architecture decisions.
Mentor and develop security engineers and analysts.
Required Qualifications
8–15 years of experience in cybersecurity or information security roles.
Proven experience leading security teams in enterprise or fintech environments.
Strong knowledge of cloud security, application security, and infrastructure security.
Experience with incident response, threat detection, and risk management.
Strong understanding of regulatory compliance frameworks.
Excellent leadership, communication, and stakeholder management skills.
Technical & Functional Expertise
Cybersecurity architecture and design
Cloud security (AWS, Azure, or GCP)
Identity & Access Management (IAM)
Vulnerability management and penetration testing coordination
Secure Software Development Lifecycle (SSDLC / DevSecOps)
Network security and encryption protocols
Security monitoring and SIEM tools
Incident response and disaster recovery planning
Compliance frameworks (ISO 27001, NIST, PCI-DSS, GDPR)
Risk assessment and threat modeling
Originally posted on Himalayas
Who can apply
Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.