Linux Security Lead
Indexed description
Location: New York, NY or Stamford, CT
Work Arrangement: Hybrid — 3 days per week in office
Base Salary: $225,000–$300,000
Total Compensation: Approximately $375,000–$500,000, depending on experience and qualifications
Employment Type: Full-Time
Position Overview
A leading global financial services and investment organization is seeking an experienced Linux Security Lead to help advance the security of its enterprise Linux infrastructure.
This is a highly technical, hands-on security role for someone with deep Linux engineering expertise combined with a strong offensive security, penetration testing, or red-team background. The successful candidate will help identify real-world attack paths, strengthen Linux environments against sophisticated threats, and build scalable security controls across complex production infrastructure.
You will work closely with security operations, infrastructure, cloud, and engineering teams to develop hardened Linux standards, automate security validation and remediation, investigate threats, and continuously improve the organization's security posture.
What You'll Do
- Advance the organization's Linux security strategy by designing and implementing resilient security controls across enterprise infrastructure.
- Lead adversary-informed security assessments of Linux systems to identify vulnerabilities and emerging risks to critical business platforms.
- Design and maintain hardened Linux build standards that reduce attack surface while supporting reliable, high-performance technology environments.
- Develop automated security checks and remediation workflows to continuously validate configuration, access, patching, and hardening practices at scale.
- Partner with Security Operations and Infrastructure teams to investigate Linux-focused threats and strengthen detection and incident-response playbooks.
- Analyze privilege paths, authentication flows, permissions, and service configurations to identify opportunities for containment and least-privilege enforcement.
- Perform and support penetration testing, vulnerability validation, attack-path analysis, and adversary simulation against Linux infrastructure.
- Advise engineering teams on secure deployment patterns for Linux workloads across both data center and cloud environments.
- Develop practical security guidance, threat models, technical standards, and documentation to support secure infrastructure decisions.
- Translate emerging Linux threat intelligence into proactive hardening and remediation priorities.
- Help continuously improve security automation, monitoring, and engineering practices across a large-scale technology environment.
What We're Looking For
- 5+ years of hands-on experience securing and engineering enterprise Linux environments in complex production settings.
- Strong offensive security or red-team experience, including hands-on exploitation, adversary simulation, and attack-path analysis against Linux systems.
- Deep understanding of Linux security, including:
- System hardening
- Privilege and identity management
- Authentication and authorization
- Access controls
- Secure configuration
- Logging and monitoring
- Patch and vulnerability management
- Experience with penetration testing, vulnerability validation, threat modeling, and remediation planning for Linux infrastructure.
- Strong scripting or automation skills for assessing configurations, enforcing security baselines, and supporting repeatable security operations.
- Ability to analyze system logs, process behavior, network activity, and endpoint telemetry during security investigations.
- Understanding of container, virtualization, and cloud-based Linux security within enterprise environments.
- Strong analytical and problem-solving skills with the ability to think from both an attacker and defender perspective.
- Excellent communication and collaboration skills, with the ability to influence infrastructure, security, and engineering stakeholders.
- Ability to work from either the New York City or Stamford, Connecticut office 3 days per week.
- Commitment to high ethical and professional standards.
Ideal Candidate Profile
The strongest candidates will combine deep Linux engineering expertise with offensive security experience. This role is particularly well suited for someone who has worked hands-on with enterprise Linux infrastructure and understands how attackers exploit misconfigurations, privilege paths, authentication weaknesses, exposed services, and other infrastructure vulnerabilities.
Experience within financial services, investment management, trading, fintech, or another highly regulated and security-sensitive environment is highly valuable.
Compensation
The anticipated base salary range for this position is $225,000–$300,000, depending on experience, qualifications, and location.
The role also includes a significant performance-based bonus opportunity, with anticipated total compensation generally ranging from approximately $375,000–$500,000 for the right candidate.
Work Arrangement
This is a hybrid position based in either:
New York, NY
or
Stamford, CT
Candidates must be able to work in office 3 days per week.
Confidential Search: Additional information regarding the organization will be shared with qualified candidates as they progress through the recruitment process.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search