HamburgerMenu
hirist

Job Description

Role Overview :

Are you a hands-on cybersecurity expert who thrives on turning security policies into robust, enforceable defenses?

We are seeking a Senior Cyber Security Specialist to implement, operate, and mature enterprise-grade security controls across our global infrastructure. In this high-impact role, you won't just write policiesyou will lead real-world execution across DevSecOps, EDR/XDR, SIEM tuning, Incident Response, PCI-DSS compliance, and cutting-edge AI Governance.

If you have deep operational experience protecting sensitive PII/HSPII data and securing cloud/hybrid environments, we want you on our team.

What Youll Do :

1. Hands-On Security Architecture & Control Execution :

- DevSecOps & Secure SDLC : Integrate automated security checks (SAST, DAST, SCA) into modern CI/CD pipelines and team up with developers to fix code-level vulnerabilities.

- Endpoint & Asset Security : Deploy, manage, and harden EDR/XDR solutions across all endpoints, ensuring full encryption, automated patching, and continuous asset discovery.

- Identity & Access Management (IAM) : Enforce zero-trust architectures, RBAC, least-privilege access, MFA, continuous PAM monitoring, and lifecycle access reviews.

2. Threat Management, AI Governance & Incident Response :

- AI Governance & Emerging Tech : Safeguard sensitive datasets in AI/ML pipelines, enforce AI model risk controls, and monitor responsible AI usage.

- Vulnerability & Threat Management : Lead continuous scanning, prioritization, penetration testing, and remediation workflows.

- SOC & Monitoring : Tune SIEM alerts to eliminate noise, write threat detection playbooks, and optimize incident alert coverage.

- Incident Response (IR) : Act as a key responder during live incidentsleading containment, root-cause analysis, drills, and recovery.

3. Data Protection & Vendor Oversight :

- PCI-DSS & Data Privacy : Build and maintain operational controls for PII/HSPII data protection, encryption, retention, and strict PCI-DSS audit readiness.

- Third-Party Risk (TPRM) : Conduct risk assessments for vendors, manage high-risk vendor compliance, and track technical remediations.

- Security Culture : Coordinate security awareness training, launch phishing simulations, and cultivate a security-first engineering culture.

What Were Looking For :

Core Requirements :

- 8+ Years of Practical Experience : Proven track record of implementing cybersecurity controls in active enterprise environments.

- Hands-on Tooling Knowledge : Direct expertise with EDR/XDR platforms, Vulnerability Management tools, SIEM solutions, IAM/PAM platforms, and CI/CD security integrations.

- Compliance Expertise : In-depth knowledge of PCI-DSS, PII/HSPII protection, and frameworks like ISO 27001, NIST CSF, and NIST 800-53.

- Cloud Security : Practical understanding of native security controls in AWS, Azure, or GCP.

- Education : Bachelors degree in Computer Science, Cybersecurity, or equivalent technical experience.

Preferred Certifications :

- CISSP, CISM, or CISA

- AWS Certified Security Specialty or Microsoft Certified: Azure Security Engineer Associate (AZ-500)

- GIAC, CEH, or CompTIA Security+

info-icon

Did you find something suspicious?

Similar jobs that you might be interested in

Loading chat...