Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Boston, MA, United States
Posted
Yesterday
AWSSOC 2AzureGDPRGoogle CloudHIPAA
Job Description
Experience: 12+ Years
Visa: EAD, TN, L2, E2, (No H1B & OPT)
Job Summary
We are seeking an experienced Cybersecurity Leader to oversee our organization's cybersecurity strategy, threat management, and compliance operations. This role is responsible for driving the security roadmap, leading incident response, ensuring regulatory compliance, and embedding a strong security culture across engineering, operations, and business units.
Key Responsibilities
- Strategic Leadership & Risk Management: Define and execute the enterprise cybersecurity vision, aligning security controls with strategic business goals and risk tolerance.
- Security Operations & Incident Response: Oversee Security Operations Center (SOC) activities, threat hunting, vulnerability management, and breach response protocols.
- Governance, Risk & Compliance (GRC): Ensure continuous compliance with frameworks and standards (e.g., ISO 27001, NIST, SOC 2, GDPR, HIPAA) through regular audits and risk assessments.
- Security Engineering & Architecture: Partner with engineering teams to integrate security controls into product lifecycles, continuous deployment pipelines, and cloud environments.
- Team Management & Culture: Lead, mentor, and build high-performing security teams while promoting security awareness across all staff levels.
- Executive Communication: Report risk metrics, security posture updates, and incident post-mortems to executive leadership and board members.
Required Skills & Qualifications
- Experience: 8–12+ years in information security, with at least 3–5 years in a leadership or managerial capacity.
- Certifications: CISSP, CISM, CCISO, or CRISC preferred.
- Technical Proficiency: Hands-on expertise with SIEM, EDR, IAM, firewalls, threat intelligence platforms, and cloud platforms (AWS, Azure, or Google Cloud Platform).
- Framework Mastery: Deep understanding of NIST CSF, ISO 27001, SOC 2 Type II, and local privacy regulations.
- Core Competencies: Strategic risk management, crisis leadership, budget management, and vendor negotiation.
Similar jobs
- AL
Software Engineer Consultant II
NewAllstate
Chicago, Illinois🇺🇸Hybrid22 minutes agoScrumAgileC#+2Technology - GO
ServiceNow Developer
NewGovcio LLC
San Antonio, Texas🇺🇸Hybrid22 minutes agoSOAPScrumAgile+4Technology - AL
Senior AI Engineer
NewAllstate
Chicago, Illinois🇺🇸Hybrid22 minutes agoGCPMicroservicesSQL+7Technology - AL
Cloud Services Lead Software Engineer
NewAllstate
Chicago, Illinois🇺🇸Hybrid22 minutes agoDockerGCPMicroservices+12Technology - AL
Quantum Algorithm Developer Expert
NewAllstate
Chicago, Illinois🇺🇸Hybrid22 minutes agoQuantum ComputingTechnology - AL
Neo4J Database Administrator
NewAllstate
Houston, Texas🇺🇸Hybrid22 minutes agoNeo4jBashGrafana+2Technology