Haystack
← Back to Jobs
Technology
KJ

Cybersecurity Leader

kjohn@samrusystems.comBoston, MA🇺🇸United StatesPosted 8 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Boston, MA, United States
Posted
Yesterday
AWSSOC 2AzureGDPRGoogle CloudHIPAA

Job Description

Experience: 12+ Years

Visa: EAD, TN, L2, E2, (No H1B & OPT)

Job Summary

We are seeking an experienced Cybersecurity Leader to oversee our organization's cybersecurity strategy, threat management, and compliance operations. This role is responsible for driving the security roadmap, leading incident response, ensuring regulatory compliance, and embedding a strong security culture across engineering, operations, and business units.

Key Responsibilities

  • Strategic Leadership & Risk Management: Define and execute the enterprise cybersecurity vision, aligning security controls with strategic business goals and risk tolerance.
  • Security Operations & Incident Response: Oversee Security Operations Center (SOC) activities, threat hunting, vulnerability management, and breach response protocols.
  • Governance, Risk & Compliance (GRC): Ensure continuous compliance with frameworks and standards (e.g., ISO 27001, NIST, SOC 2, GDPR, HIPAA) through regular audits and risk assessments.
  • Security Engineering & Architecture: Partner with engineering teams to integrate security controls into product lifecycles, continuous deployment pipelines, and cloud environments.
  • Team Management & Culture: Lead, mentor, and build high-performing security teams while promoting security awareness across all staff levels.
  • Executive Communication: Report risk metrics, security posture updates, and incident post-mortems to executive leadership and board members.

Required Skills & Qualifications

  • Experience: 8–12+ years in information security, with at least 3–5 years in a leadership or managerial capacity.
  • Certifications: CISSP, CISM, CCISO, or CRISC preferred.
  • Technical Proficiency: Hands-on expertise with SIEM, EDR, IAM, firewalls, threat intelligence platforms, and cloud platforms (AWS, Azure, or Google Cloud Platform).
  • Framework Mastery: Deep understanding of NIST CSF, ISO 27001, SOC 2 Type II, and local privacy regulations.
  • Core Competencies: Strategic risk management, crisis leadership, budget management, and vendor negotiation.

Similar jobs