Leads enterprise security engineering and SecOps, directing a security team, outsourced MDR/SOC operations, incident response, and a Zero Trust transformation. Requires 10+ years in cybersecurity or cloud infrastructure security, leadership experience, and deep GCP, micro-segmentation, workload identity, and CI/CD expertise.
162k – 209k/yr
Remote10+ YOESecurity Engineering
About the role
Responsibilities
Hands-on Engineering & Operational Leadership
Direct, mentor, and grow a high-performing team of security engineers.
Conduct technical sprint planning, alignment, and coaching while maintaining the technical depth to dive into configurations alongside the team.
Zero Trust Strategy
Lead the enterprise-wide transition to Zero Trust Architecture (ZTA) across IT, corporate platforms, and cloud engineering infrastructure.
Establish identity as the perimeter, inhibit lateral movement, and prioritize data survivability.
Security Operations
Own monitoring, detection engineering, and incident response operations.
Design, deploy, and maintain blast-radius reduction solutions.
Implement micro-segmentation boundaries, including GCP VPC Service Controls.
Enforce ephemeral Workload Identity protocols using temporary tokens instead of static passwords.
Threat Defense and Containment
Maintain the Data Topology Map, Cyber Asset Attack Surface (CAA) Matrix, Workload Ledger, and technical Containment Playbooks.
Risk-Based Vulnerability Management
Evaluate legacy stacks and cloud services against the Zero Trust Maturity Model (ZTMM).
Define patching and remediation SLAs.
Partner with IT and Foundations Engineering on targeted mitigation.
Cross-Functional Collaboration
Coordinate with GRC, IT, and Product teams to integrate security policies into code pipelines.
Apply context-aware guardrails to enterprise AI tools.
90-Day Plan
First 30 days: Deep dive into GCP infrastructure and IT security tools, establish relationships with engineering, IT, GRC, and MDR partners, and assess Zero Trust Maturity Model status.
Days 30–60: Deliver the baseline Data Topology Map and CAA Matrix, audit MDR ingestion pipelines, tune high-priority alert workflows, integrate security alerting into team communication channels, and expand automated secrets detection in GitHub pipelines.
Days 60–90: Finalize the Workload Ledger, pilot micro-segmentation guardrails including GCP VPC Service Controls, standardize technical Containment Playbooks, and present Security Operations and ZTA maturity metrics to executive leadership.
Requirements
10+ years of dedicated experience in cybersecurity, cloud infrastructure security, or SecOps.
At least 3+ years managing, leading, or mentoring high-performing security teams.
Experience overseeing incident response programs and managing external vendors, including outsourced MDR/SOC partners, SIEM platforms, and EDR/XDR toolsets.
Deep technical expertise in cloud security architecture, ideally GCP.
Hands-on experience building micro-segmentation models, establishing ephemeral workload identity controls, and securing CI/CD pipelines.
Ability to map systemic relationships, formulate risk-prioritization frameworks, and apply Zero Trust Maturity Models.
Experience architecting durable AI systems or automation workflows that solve cross-functional challenges and improve operational efficiency.
Exceptional communication skills for conveying complex security strategies to non-technical business leaders and external stakeholders.
Experience designing and implementing repeatable AI-enabled workflows that address team bottlenecks and improve efficiency.
Compensation and Benefits
Compensation range: $161,500–$209,000.
Benefits information is available on the company’s Careers page.
This is a remote-first role with office hubs in Denver and San Francisco.
Leads NexHealth’s security governance, compliance, IT operations, vendor security, privacy, and incident response programs while building the security function and team. Requires 8+ years of security experience, leadership building programs from the ground up, audit ownership, and a software engineering background.
160k – 200k/yrOn-site8+ YOESecurity Engineering
Director, Trust & Safety Detection and Intelligence
FetchUnited States
Leads Fetch’s fraud detection and threat intelligence function, overseeing investigations, detection systems, risk prioritization, and anti-abuse strategy. Requires 10+ years in fraud, trust and safety, cybersecurity, or related risk work, plus 5+ years managing senior teams.
176k – 207k/yrRemote10+ YOESecurity Engineering
Head of Security & Compliance
CascaSan Francisco, CA
Lead security and compliance for an AI-native banking startup. Build security tooling, manage a team of appsec engineers, own compliance (SOC 2, ISO 27001), and secure AI agent workflows.
200k – 255k/yrOn-site5+ YOESecurity Engineering
Head of Security
TatariNew York, NY +2
Lead security engineering team and roadmap for a late-stage AdTech SaaS company. Own incident response, risk management, AWS/K8s security, and compliance programs including SOC 2.
200k – 250k/yrHybrid7+ YOESecurity Engineering
Director, Corporate Security
Komodo HealthUnited States
Director of Corporate Security responsible for building and maturing the company's internal security program, including identity/access management, endpoint protection, SaaS security, AI governance, incident response, and compliance. Requires 7+ years director-level experience, team leadership, and cross-functional partnership in regulated or healthcare environments.