Director, Cybersecurity Engineering
Location
United States
Posted
1 day ago
Salary
$205K - $290K / year
Seniority
Lead
Job Description
Director, Cybersecurity Engineering
Convera
• Lead and evolve the enterprise cybersecurity engineering program, aligning with business objectives, risk appetite, and regulatory requirements. • Define and execute security architecture, engineering standards, and roadmaps to mature cybersecurity toolsets across infrastructure, cloud, applications, and data. • Drive adoption of modern security practices including Zero Trust, secure-by-design, and automation including AI. • Lead engineering teams responsible for deploying and maintaining cybersecurity engineering controls including but not limited to endpoint detection and response (EDR), security information event management (SIEM), cloud-native application protection platform (CNAPP), firewalls, and the suite of Vulnerability Detection and Management controls • Lead engineering teams responsible for deploying and maintaining Identity & Access management controls including but not limited to directory services, privileged access management solutions, Multi-factor Authentication services, VPN, and Password Managers. • Own global Cybersecurity Engineering and Identity Management strategy. • Work across teams in Product and Tech to secure our Product Development Lifecycle • Promote engineering excellence, automation, and DevSecOps best practices. • Ensure availability, resilience, and scalability of security services globally. • Work with Cybersecurity Program management to ensure controls are followed and pass regulatory audits, and support audits, regulatory exams, and remediation efforts. • Partner closely with Risk, Audit, and Compliance teams to ensure adherence to financial regulatory requirements. • Support incident response efforts as required 24x7x365 with a globally dispersed team and operations schedule. • Work across our supply chain to ensure secure remote access for required Vendors and Contractors • Act as a trusted advisor to senior leadership on cyber risk, identity strategy, and security investments.
Job Requirements
- 10+ years of experience in security engineering and operations.
- Bachelor’s degree in Computer Science, Information Security, or related field (Master’s preferred).
- Relevant certifications such as CISSP, CISA, CEH, OSCP, or other industry recognized security certification(s) are preferred.
- Have experience with all the common cybersecurity and IAM solutions reference in the role requirements
- Have engineering leadership experience at large, complex, and regulated organizations (financial services preferred)
- Familiar working with industry-standard regulatory requirements (SOC2, PCI, ISO 27001, etc.) and technical standards (CIS, NIST, STIG, etc.)
- Proven experience managing global teams and security operations at scale.
- Deep knowledge and experience managing cybersecurity in the Cloud
- Experience deploying AI solutions automating cybersecurity operations.
- Experience implementing and leading a Zero Trust program preferred.
- Strategic thinker with the ability to translate vision into execution.
- Strong communication and executive presence.
- Proven ability to influence across technical and business stakeholders.
Benefits
- Health insurance (medical, dental, vision)
- Retirement savings plan
- Paid time off, holidays, and parental leave
- Wellness programs and mental health resources
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Director, Security Delivery – Physical Security
GeneaWelcome to Genea. Genea means Family - Where babies are made sooner.
• Own the end-to-end post-sale delivery organization for Genea’s physical security and access control business, including Security Support (L1 and L2) and Security Implementations, with planned expansion into Renewals management and a net-new Customer Success function. • Own a delivery P&L and an associated growth target; build and manage a services portfolio that balances margin-positive offerings with strategic loss-leaders that drive adoption, retention, and expansion. • Lead and mature both onshore and offshore delivery, building the staffing models, partner relationships, and follow-the-sun coverage needed to scale quality and capacity cost-effectively. • Manage implementation delivery through Genea’s partner / integration channel, holding partners accountable to scope, timeline, quality, and customer-experience standards across engagements ranging from short multi-week installs up to complex multi-month programs. • Transform and mature the post-sale organization — redesigning the operating model, roles, hand-offs, and value chain to move from reactive support toward proactive, outcome-driven delivery and customer success. • Stand up the Renewals function and, subsequently, the Customer Success function: define the charter, segmentation, health-scoring, playbooks, and the renewal and expansion motion in partnership with Sales and Operations. • Operationalize delivery, reporting, and process with AI — instrumenting the organization with dashboards, forecasting, and AI-enabled workflows that improve throughput, margin visibility, and customer outcomes. • Define and own the KPIs for the function (utilization, margin, time-to-value, CSAT, gross and net retention, on-time delivery) and report performance and risk to the executive team. • Coach and develop frontline and emerging managers, strengthening the leadership bench and elevating the team’s capability within the Director’s span of control. • Lead cross-functionally and through influence — partnering with Sales, Product, Engineering, and broader Operations to enhance the value chain inside and outside the direct reporting line. • Serve as a senior point of escalation for strategic accounts and complex delivery situations, representing the post-sale organization in executive and customer-facing forums. • Performs other related duties as assigned by management.
• Work closely with Accrete’s Manager of Cloud Security and staff to understand key dependencies • Research and communicate unique client security needs to Accrete’s CISO and Manager of Cloud Security to reduce code drift and divergent security practices • Implement compliant identity management and data handling processes using a variety of custom and off-the-shelf software • Identify and recommend base code modifications in order to meet client security requirements
Cybersecurity Executive
PartnerOneWe are the leaders in Big Data management through hyper-automation, virtualized cloud tiering, metadata and AI
• Define and execute the company’s strategic vision and growth plan. • Drive revenue growth, profitability, customer retention, and market expansion initiatives. • Evaluate evolving cybersecurity threats, market trends, competitive dynamics, and emerging technologies to inform business strategy. • Position the company as a leader in security operations, threat detection, network security, and cyber defense solutions. • Develop and execute strategic initiatives that strengthen the company’s position within enterprise, government, defense, and critical infrastructure markets. • Partner with Product and Engineering teams to deliver innovative cybersecurity solutions that address evolving threat landscapes. • Ensure continued leadership across solutions supporting: - Security Information and Event Management (SIEM) - Network Detection and Response (NDR) - Extended Detection and Response (XDR) - Threat Hunting - Threat Intelligence - Digital Forensics and Incident Response - Security Analytics - Security Operations Centers (SOC) • Support customers operating in cloud, hybrid, on-premises, and air-gapped environments. • Drive modernization initiatives while maintaining strong support for mission-critical customer deployments. • Maintain a deep understanding of advanced persistent threats, nation-state actors, ransomware, insider threats, and emerging attack techniques. • Lead organizations delivering software and appliance-based cybersecurity solutions and understand the operational requirements associated with hardware lifecycle management and supply chain considerations. • Lead global sales, customer success, channels, alliances, and professional services organizations. • Build and strengthen relationships with CISOs, CIOs, security operations leaders, government agencies, defense organizations, and strategic partners. • Expand recurring revenue streams while maximizing customer retention and expansion opportunities. • Support strategic customer engagements, executive briefings, and major commercial opportunities. • Drive growth across enterprise, public sector, federal, defense, and critical infrastructure customers. • Lead global teams across Product Management, Engineering, Sales, Marketing, Services, Customer Success, and Operations. • Establish clear performance metrics and accountability across the organization. • Optimize organizational structure and operational efficiency to support business objectives. • Foster a culture of innovation, execution, customer focus, and accountability. • Ensure operational rigor in product delivery, customer support, and service excellence. • Serve as a trusted executive partner to customers, employees, and strategic stakeholders. • Represent the company at industry conferences, customer events, analyst briefings, and executive forums. • Support strategic partnerships, acquisitions, integrations, and other corporate initiatives. • Provide leadership during major cybersecurity incidents, market disruptions, and industry developments.
Role Description The Security Engineer, Secure Development is responsible for establishing, leading, and enforcing security standards for all internally developed software, automation, and AI‑enabled solutions prior to customer delivery or internal production use. This role serves as the primary technical lead and designated expert to ensure that applications, APIs, infrastructure‑as‑code, and AI models meet security, privacy, and compliance requirements before release. This is an individual contributor role within the security organization, focused on hands‑on execution, technical depth, and influence through standards, tooling, and partnership with development teams. As a Managed Services Provider with proprietary platforms and customer‑facing systems, XTIUM requires strong governance over secure development practices. This role works closely with engineering, platform, infrastructure, and compliance teams to embed security into the software development lifecycle while maintaining delivery velocity. What You Will Do - Application & Code Security Governance - Own and enforce secure development standards for all internally built applications, platforms, automation, and tooling. - Perform and oversee manual and automated code reviews (static, dynamic, dependency, and supply‑chain analysis). - Establish clear release gates requiring security approval before software or AI systems are delivered to customers or promoted internally. - Define remediation standards and risk acceptance criteria for security findings. - Conduct secure design reviews and application threat modeling during early development phases to identify and mitigate risk before implementation. - AI & Emerging Technology Security - Review internally developed AI models, agents, prompts, integrations, and data pipelines for security, privacy, and misuse risk. - Ensure AI systems comply with internal governance, customer contractual obligations, and emerging regulatory expectations. - Partner with engineering and data teams to implement secure AI development patterns, including data protection, access controls, and auditability. - DevSecOps Enablement - Integrate security tooling into CI/CD pipelines (e.g., SAST, DAST, dependency scanning, container scanning, secrets detection). - Promote “shift-left” security practices and reduce late‑stage security blockers through developer enablement. - Collaborate with DevOps and Platform teams on secure delivery pipelines and runtime controls. - Risk, Compliance & IP Protection - Protect XTIUM’s intellectual property by ensuring secure design, code custody, and controlled access to source repositories. - Support compliance efforts across frameworks such as SOC 2, ISO 27001, and customer‑specific security requirements. - Produce audit‑ready artifacts including risk assessments, code review records, and security sign‑offs. - Leadership & Collaboration - Act as the primary application security escalation point for engineering and leadership. - Mentor developers and engineers on secure coding practices and threat modeling. - Provide executive‑level reporting on application and AI security posture, trends, and risk exposure. Qualifications - 8+ years of experience in application security, DevSecOps, or secure software development. - Strong hands‑on experience reviewing code in one or more modern languages (e.g., Python, JavaScript/TypeScript, C#, Java, Go). - Proven experience securing APIs, web applications, microservices, and cloud‑native platforms. - Experience integrating security controls into CI/CD pipelines and modern DevOps workflows. - Deep understanding of common vulnerabilities and attack patterns (OWASP Top 10, API security risks, supply chain threats). - Ability to balance security rigor with delivery velocity in a customer‑facing MSP environment. Preferred Qualifications - Experience securing AI/ML systems, automation platforms, or data‑driven applications. - Familiarity with cloud platforms (Azure, AWS) and containerized environments. - Experience in a Managed Services Provider (MSP) or SaaS organization with external customer delivery obligations. - Knowledge of regulatory and compliance frameworks impacting software and data security. Key Competencies - Secure Software Architecture - Application & API Security - AI Security & Governance - DevSecOps Tooling & Automation



