SECURITY LEAD
Indexed description
This is a remote position.
The Security Lead is responsible for defining and executing the organization’s cybersecurity strategy, leading security architecture, managing risk, and ensuring compliance with global security standards. This role works closely with engineering, DevOps, product, compliance, and leadership teams to embed security into all layers of the technology stack.
Key Responsibilities
- Define and lead enterprise-wide cybersecurity strategy and architecture.
- Oversee application, infrastructure, and cloud security across all systems.
- Lead threat modeling, risk assessments, and vulnerability management programs.
- Establish and enforce security policies, standards, and best practices.
- Monitor, detect, and respond to security incidents and breaches.
- Ensure secure software development practices (DevSecOps) are implemented.
- Conduct security audits, penetration testing coordination, and remediation tracking.
- Collaborate with Engineering and DevOps teams to embed security in CI/CD pipelines.
- Ensure compliance with regulatory and industry standards (e.g., ISO 27001, PCI-DSS, GDPR).
- Lead identity and access management (IAM) strategies and controls.
- Provide security guidance for cloud infrastructure and architecture decisions.
- Mentor and develop security engineers and analysts.
Required Qualifications
- 8–15 years of experience in cybersecurity or information security roles.
- Proven experience leading security teams in enterprise or fintech environments.
- Strong knowledge of cloud security, application security, and infrastructure security.
- Experience with incident response, threat detection, and risk management.
- Strong understanding of regulatory compliance frameworks.
- Excellent leadership, communication, and stakeholder management skills.
Technical & Functional Expertise
- Cybersecurity architecture and design
- Cloud security (AWS, Azure, or GCP)
- Identity & Access Management (IAM)
- Vulnerability management and penetration testing coordination
- Secure Software Development Lifecycle (SSDLC / DevSecOps)
- Network security and encryption protocols
- Security monitoring and SIEM tools
- Incident response and disaster recovery planning
- Compliance frameworks (ISO 27001, NIST, PCI-DSS, GDPR)
- Risk assessment and threat modeling
Originally posted on Himalayas
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search