Quick Overview
Job Description
Cyber Security Engineer (Team Lead)-W2
Mahwah, NJ (100% Onsite).
Role Overview
We are seeking an experienced Cybersecurity Engineer to implement and maintain robust cybersecurity measures across digital products and platforms. This role reports to the Head of Information Security and focuses on ensuring security and privacy-by-design principles are embedded throughout the software development lifecycle. The ideal candidate will partner with security teams, architects, developers, and business stakeholders to identify, assess, and mitigate cybersecurity risks while ensuring compliance with organizational and regulatory requirements.
________________________________________
Day to Day Job Duties:
- Implement and maintain cybersecurity controls and secure development practices across digital products and platforms.
- Collaborate with Information Security, Enterprise Architects, Software Engineers, and Project Managers on the design and delivery of secure solutions.
- Ensure compliance with enterprise security architecture, governance frameworks, and industry security standards.
- Translate cybersecurity and privacy requirements into actionable product development roadmaps.
- Perform technical security assessments, including code reviews, static and dynamic application security testing, and penetration testing.
- Conduct threat modeling, vulnerability assessments, and cyber risk analysis activities.
- Recommend and implement mitigation strategies to reduce identified security risks.
- Enforce information security and data privacy requirements related to regulations such as GDPR, CPRA, SOX, and PCI-DSS.
- Investigate, resolve, and escalate security incidents and support requests as required.
- Monitor emerging cybersecurity threats, vulnerabilities, and attack methodologies.
- Deliver secure coding awareness and cybersecurity training sessions to development teams.
- Support continuous improvement initiatives related to application security and cybersecurity governance.
________________________________________
Basic Qualifications:
- Bachelor's degree in information technology, Cybersecurity, Computer Science, or a related field.
- Minimum 5+ years of hands-on experience in Cybersecurity Engineering, Application Security, or Information Security.
- At least 5+ years of experience implementing security controls and secure software development lifecycle (SSDLC) practices.
- Experience performing threat modeling, risk assessments, vulnerability management, and penetration testing.
- Experience conducting application security reviews, including static and dynamic code analysis.
- Hands-on experience with security tools such as Qualys, SonarQube, Detectify, GitHub Advanced Security, or equivalent solutions.
- Strong understanding of information security frameworks, methodologies, standards, and best practices.
- Experience securing cloud environments, web applications, APIs, and enterprise platforms.
- Experience implementing and maintaining regulatory compliance requirements including GDPR, CPRA, SOX, and PCI-DSS.
- Strong understanding of secure software engineering principles and common programming languages.
- Experience working in Agile/Scrum environments and collaborating with cross-functional teams.
- Strong analytical, troubleshooting, risk assessment, and problem-solving skills.
- Ability to communicate technical security concepts effectively to both technical and non-technical stakeholders.
________________________________________
Degree: Bachelor's degree in information technology, Cybersecurity, Computer Science, or a related field.
________________________________________
Certification (At least 1 Certification Mandatory)
- CISSP (Certified Information Systems Security Professional)
- CSSLP (Certified Secure Software Lifecycle Professional)
- SSCP (Systems Security Certified Practitioner)
- GWEB (GIAC Web Application Penetration Tester) or equivalent cybersecurity certification
________________________________________
Nice to Have:
- Experience with cloud security platforms such as Microsoft Azure, AWS, or Google Cloud.
- Experience with DevSecOps practices and CI/CD security integrations.
- Knowledge of container security, Kubernetes security, and infrastructure-as-code security.
- Familiarity with Zero Trust Security Architecture.
Similar jobs
- LT
Sr. Specialist, IT Security (Network Security Engineer) with Security Clearance
NewL3Harris Technologies
Anaheim, CA🇺🇸$96k - $178k/yrOn-site19 hours agoTechnology - LT
Senior Specialist, Information Security Systems Engineering with Security Clearance
NewL3Harris Technologies
Nashville, TN🇺🇸Hybrid19 hours agoAdministrative - KT
Network Security Risk & Compliance Analyst II
NewKforce Technology Staffing
Newport Beach, CA🇺🇸Hybrid19 hours agoStakeholder ManagementAdministrative - KS
Information Assurance Specialist
NewKonane Solutions
Washington, DC🇺🇸On-site19 hours agoActive DirectoryArticulateAzure+3 - MC
Security Engineer
NewMaven Companies
Seattle, WA🇺🇸Hybrid19 hours agoOWASPLLMPenetration TestingTechnology - VE
Senior Application Security Engineer
NewVerisign
Reston🇺🇸Hybrid8 hours agoMicroservicesRustOWASP+11Technology