Cybersecurity Lead Engineer /Architect
Indexed description
This individual operates as a highly self-directed contributor within a team responsible for cybersecurity and enterprise risk. The role requires independent assessment of emerging threats, evaluation of control effectiveness, prioritization of initiatives, and ownership of security-focused projects and architectural roadmaps from concept through execution. The Cybersecurity Lead Engineer/Architect regularly collaborates with infrastructure, software engineering, and service desk teams to drive measurable improvements in the firm’s security posture.
As an onsite/hybrid employee, you are expected to be in the office on Tuesdays, Wednesdays and Thursday.
Responsibilities
- Architect, design, implement, and continuously enhance security controls across endpoint, network, cloud, identity, and SDLC, operating hands-on from design through deployment and tuning.
- Lead security-focused projects, including scoping, planning, execution, stakeholder communication, and documentation.
- Own and optimize core security tooling (Application security, AI security, endpoint protection, IDS/IPS, SIEM, vulnerability management, cloud security, etc.), ensuring effective configuration and continuous improvement.
- Develop and implement automation to enhance threat detection, alerting, response workflows, ticket creation, and reporting metrics.
- Partner with cross-functional technology teams to embed secure design principles and hardening standards into infrastructure, cloud platforms, and application development (DevSecOps).
- Lead the firm’s AI security program, establishing governance, guardrails, and technical controls that secure the enterprise’s adoption and use of AI
- Partner with product and software engineering teams to enable secure AI engineering and development, embedding threat modeling, secure-by-design patterns, and safeguards.
- Monitor compliance with cybersecurity policies and regulatory requirements; identify gaps and drive remediation efforts.
- Serve as a technical escalation point during incident response and contribute to post-incident analysis and control improvements.
- Identify emerging threats, tools, and technologies and recommend strategic direction for the cybersecurity program.
- Bachelor’s Degree in Computer Science, Information Technology, or equivalent practical experience.
- 8+ years of progressive experience in cybersecurity or information security engineering roles, including time in a lead, principal, or security architect capacity.
- Demonstrated experience implementing and engineering security controls in enterprise environments.
- Experience leading or independently managing technical security projects.
- Strong familiarity with CIS Framework and system hardening standards.
- Hands-on experience securing and monitoring cloud platforms (AWS, Azure, etc.).
- Deep understanding of common security controls including DLP, MFA, encryption, intrusion detection, and mobile device/application management.
- Strong scripting and automation skills (PowerShell, Python, or similar) with software engineering experience preferred
- Experience designing and maintaining centralized logging and SIEM solutions.
- Ability to independently assess risk, define problems, and implement practical, scalable solutions.
- Strong communication skills with the ability to influence stakeholders and represent the security function effectively.
- Proven experience designing enterprise security architecture and reference architectures, balancing strategic, roadmap-level direction with hands-on implementation.
- Experience securing AI/ML systems and enterprise AI adoption, including familiarity with AI-specific risks (e.g., prompt injection, data leakage, model abuse) and frameworks such as the NIST AI Risk Management Framework and the OWASP Top 10 for LLM Applications.
- Experience threat modeling and partnering with software and product engineering teams to enable secure AI and application development.
- Experience in financial services or investment management preferred.
- Relevant security certifications (CISSP, CISM, GIAC, AWS Security, etc.) are a plus.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search