As a Lead Information Security Engineer, you will be critical in shaping, refining, and executing SpurSol's security strategy across our Business Units and Products, encompassing Cloud and On-Prem infrastructure. This role demands a proactive leader who is a hands-on practitioner, can drive technical initiatives to success, mentor team members, ensure alignment between security objectives and business goals, and work with urgency to drive both forward.
Here are some of the key expectations of this position:
- Strategic Security Leadership
- Define and implement advanced security strategies and frameworks for cloud and on-prem infrastructure.
- Align security operations with the company's broader business objectives and technology roadmap.
- Develop and maintain a multi-year security roadmap with measurable goals and KPIs.
- Serve as the escalation point for high-severity security incidents and own the resolution process.
- Security Operations Management
- Oversee day-to-day SecOps activities, including monitoring, threat detection, and incident response.
- Lead the deployment and configuration of security tools (SIEMs, IDS/IPS, EDR, vulnerability scanners, WAFs).
- Ensure timely investigation, escalation, and resolution of security incidents.
- Regularly review and optimize alerting mechanisms to minimize noise and focus on actionable threats.
- Risk and Vulnerability Management
- Lead periodic risk assessments and vulnerability scanning across Cloud, On-Prem, and EUC (end-user computing) environments.
- Prioritize vulnerabilities based on risk exposure and business impact, utilizing frameworks such as CVSS, EPSS, and SSVC.
- Collaborate with IT, DevOps, and Product Engineering teams (and other Departments, as needed) to ensure rapid remediation of vulnerabilities and issues.
- Implement continuous monitoring and detection strategies to address evolving threat landscapes.
- Collaboration and Cross-functional alignment
- Collaborate with Product, Engineering, DevOps, Admin, PX, and other teams to ensure security practices are embedded across all workflows.
- Advocate for and evangelize security-first principles in software development and infrastructure operations.
- Participate in design and architecture reviews to identify potential security weaknesses and gaps.
- Communicate complex security risks and strategies effectively to technical and non-technical stakeholders.
- Compliance and Governance
- Ensure adherence to compliance and regulatory requirements (e.g., ISO 27001, PCI-DSS, SOC 2, NIST CSF, GDPR, etc.).
- Lead internal and external security audits, providing required documentation and evidence and ensuring that SpurSol exceeds the requirements of key standards such as ISO 27001 and PCI-DSS.
- Maintain compliance documentation, policies, and procedures.
- Establish governance frameworks to ensure ongoing compliance across teams.
- Incident Response and Recovery
- Own and refine the organization's Security Incident Response Plan (SIRP).
- Lead tabletop exercises and simulations to ensure readiness for security incidents.
- Ensure comprehensive root cause analysis (RCA) is conducted post-incident, building a culture of continuous improvement.
- Continuously improve incident response playbooks.
- Team Leadership and Development
- Coach and mentor team members and guide their career growth.
- Conduct regular 1:1 meetings, participate in SpurSol's performance review process, and provide constructive feedback.
- Foster a culture of continuous learning & improvement, accountability, and innovation.
- Develop and oversee training programs to enhance the Team's competencies.
- Continuous Improvement and Innovation
- Stay updated on emerging cybersecurity threats, vulnerabilities, and Security best practices.
- Identify and evaluate new Security tools, apps, and technologies to enhance SpurSol's security posture and the security of our Products.
- Implement automation in security operations to improve efficiency and reduce human error.
- Regularly review and refine security policies and procedures.
- Champion the adoption and use of new Security tools, apps, and technologies to further SpurSol's business objectives.