We are looking for a senior security professional responsible for designing, implementing, and maintaining security policies and procedures to ensure Security Compliance and protect the company from data loss and cybersecurity risks. This person will act as the top technical security authority, defining cybersecurity strategy at both the Product and Infrastructure layers
Implement strategies and define plans around cybersecurity at the Product and Infrastructure layers
Design and define long-term security architecture across systems, networks, and applications
Align security practices with enterprise-wide IT strategies and business goals
Drive secure-by-design principles and influence platform, infrastructure, and software design
Identify immediate and potential risks, and develop mitigation strategies while continually monitoring and evaluating security measures
Conduct threat modeling for new projects and high-risk services
Evaluate and prioritize security risks in both development and production environments
Collaborate with product, infrastructure, and development teams to mitigate identified risks
Lead investigations of complex security incidents, including root cause analysis and mitigation strategies
Guide post-incident reviews and ensure systemic improvements are implemented
Develop and implement automation tools for continuous security monitoring, vulnerability scanning, and compliance enforcement
Evaluate and integrate third-party security solutions
Ensure systems comply with regulatory requirements such as PCI-DSS, SOC 2, or ISO 27001
Work closely with legal and compliance teams to maintain policies and audit-readiness