Haystack
← Back to Jobs
Technology
ID

Cyber Security Engineer (Team Lead)-W2

Info Dinamica IncMahwah, NJ🇺🇸United StatesPosted Sep 23, 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Mahwah, NJ, United States
Posted
19 hours ago
AWSScrumSonarQubeAgileAzureGDPRGoogle CloudKubernetesPenetration TestingZero Trust

Job Description

Cyber Security Engineer (Team Lead)-W2

Mahwah, NJ (100% Onsite).

Role Overview

We are seeking an experienced Cybersecurity Engineer to implement and maintain robust cybersecurity measures across digital products and platforms. This role reports to the Head of Information Security and focuses on ensuring security and privacy-by-design principles are embedded throughout the software development lifecycle. The ideal candidate will partner with security teams, architects, developers, and business stakeholders to identify, assess, and mitigate cybersecurity risks while ensuring compliance with organizational and regulatory requirements.

________________________________________

Day to Day Job Duties:

  • Implement and maintain cybersecurity controls and secure development practices across digital products and platforms.
  • Collaborate with Information Security, Enterprise Architects, Software Engineers, and Project Managers on the design and delivery of secure solutions.
  • Ensure compliance with enterprise security architecture, governance frameworks, and industry security standards.
  • Translate cybersecurity and privacy requirements into actionable product development roadmaps.
  • Perform technical security assessments, including code reviews, static and dynamic application security testing, and penetration testing.
  • Conduct threat modeling, vulnerability assessments, and cyber risk analysis activities.
  • Recommend and implement mitigation strategies to reduce identified security risks.
  • Enforce information security and data privacy requirements related to regulations such as GDPR, CPRA, SOX, and PCI-DSS.
  • Investigate, resolve, and escalate security incidents and support requests as required.
  • Monitor emerging cybersecurity threats, vulnerabilities, and attack methodologies.
  • Deliver secure coding awareness and cybersecurity training sessions to development teams.
  • Support continuous improvement initiatives related to application security and cybersecurity governance.

________________________________________

Basic Qualifications:

  • Bachelor's degree in information technology, Cybersecurity, Computer Science, or a related field.
  • Minimum 5+ years of hands-on experience in Cybersecurity Engineering, Application Security, or Information Security.
  • At least 5+ years of experience implementing security controls and secure software development lifecycle (SSDLC) practices.
  • Experience performing threat modeling, risk assessments, vulnerability management, and penetration testing.
  • Experience conducting application security reviews, including static and dynamic code analysis.
  • Hands-on experience with security tools such as Qualys, SonarQube, Detectify, GitHub Advanced Security, or equivalent solutions.
  • Strong understanding of information security frameworks, methodologies, standards, and best practices.
  • Experience securing cloud environments, web applications, APIs, and enterprise platforms.
  • Experience implementing and maintaining regulatory compliance requirements including GDPR, CPRA, SOX, and PCI-DSS.
  • Strong understanding of secure software engineering principles and common programming languages.
  • Experience working in Agile/Scrum environments and collaborating with cross-functional teams.
  • Strong analytical, troubleshooting, risk assessment, and problem-solving skills.
  • Ability to communicate technical security concepts effectively to both technical and non-technical stakeholders.

________________________________________

Degree: Bachelor's degree in information technology, Cybersecurity, Computer Science, or a related field.

________________________________________

Certification (At least 1 Certification Mandatory)

  • CISSP (Certified Information Systems Security Professional)
  • CSSLP (Certified Secure Software Lifecycle Professional)
  • SSCP (Systems Security Certified Practitioner)
  • GWEB (GIAC Web Application Penetration Tester) or equivalent cybersecurity certification

________________________________________

Nice to Have:

  • Experience with cloud security platforms such as Microsoft Azure, AWS, or Google Cloud.
  • Experience with DevSecOps practices and CI/CD security integrations.
  • Knowledge of container security, Kubernetes security, and infrastructure-as-code security.
  • Familiarity with Zero Trust Security Architecture.

Similar jobs