
10,000+ employees
🏗️ Construction
🏭 Manufacturing
📦 Logistics
Construction • Manufacturing • Logistics
Ferguson is a leading supplier of plumbing and HVAC products for residential and commercial markets. The company offers a wide range of products including water heaters, plumbing parts, and HVAC systems, as well as various tools and cleaning supplies. Ferguson provides solutions for professionals in the plumbing and HVAC industries, ensuring they have access to the resources and expertise they need for both new construction and remodeling projects.
🔥 0 minutes ago
⚔️ Virginia – Remote
💵 $9.5k - $16.6k / month
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
👻 Ghost score 0%
Improve your chances of getting an interview by checking your resume score before you apply.

10,000+ employees
🏗️ Construction
🏭 Manufacturing
📦 Logistics
Construction • Manufacturing • Logistics
Ferguson is a leading supplier of plumbing and HVAC products for residential and commercial markets. The company offers a wide range of products including water heaters, plumbing parts, and HVAC systems, as well as various tools and cleaning supplies. Ferguson provides solutions for professionals in the plumbing and HVAC industries, ensuring they have access to the resources and expertise they need for both new construction and remodeling projects.
• Provide vision, leadership, and operational accountability for Ferguson’s enterprise security engineering capabilities • Build, lead, and develop a high-performing Security Engineering team through recruiting, hiring, coaching, mentorship, performance management, and career development • Define and maintain the operating model, service ownership, roadmap, and measurable objectives for Security Engineering capabilities • Represent Security Engineering performance, risks, resource needs, and strategic opportunities to Information Security and Technology leadership • Partner with Security Architecture, Security Operations, GRC, Identity, Infrastructure, Application Development, Cloud, and business technology teams • Assess team skills, capacity, vendor support, and tooling maturity against current and emerging threats • Establish metrics, reporting routines, and executive-ready narratives on risk posture, control effectiveness, remediation progress, service value, and investment needs • Own and mature vulnerability management, DevSecOps, penetration testing, adversarial validation, edge security, email security, endpoint security, cloud security posture, configuration risk, application security testing, and security tooling integrations • Lead risk-based vulnerability management, including asset visibility, authenticated scanning, assessment, risk contextualization, remediation tracking, exception management, and leadership reporting • Integrate security testing and guidance into development workflows, including static analysis, software composition analysis, container security, secrets protection, code signing, secure repositories, and developer remediation support • Run penetration testing, AI-enabled security testing, purple team support, and continuous adversarial validation • Protect public-facing applications and digital channels using WAF, bot management, CDN security, origin protection, API protections, and secure traffic patterns • Oversee email and endpoint security capabilities, including migration planning, policy tuning, telemetry quality, detection support, deployment health, and operational readiness • Drive enterprise configuration and posture management across cloud, infrastructure, endpoints, applications, and identity-adjacent services • Partner with identity and cryptographic services teams on PAM, SSO, certificates, non-human identities, key management, and cryptographic services • Support AI resilience, post-quantum readiness, cryptographic visibility, secrets removal, cloud posture modernization, and security tooling rationalization • Ensure security engineering platforms and services are reliable, monitored, documented, supportable, policy-aligned, and compliant with regulatory or audit obligations • Maintain runbooks, customer concern paths, operational handoffs, service ownership documentation, vendor engagement models, and cross-training practices • Prioritize engineering work based on business risk, exploitability, asset criticality, exposure, compliance requirements, operational impact, and remediation capacity • Contribute to security technology selection, proof-of-value efforts, vendor evaluations, architecture reviews, and implementation planning • Monitor emerging technologies, threats, attack patterns, regulatory expectations, and industry practices • Drive and report on service restoration activities as required • Support enterprise business and sales objectives through effective job performance
• Experience leading information security engineering, application security, vulnerability management, cloud security, endpoint security, or related technical security teams is required • Experience managing full-time associates, contractors, vendors, and multi-functional delivery partners is required • Experience building or operating risk-based vulnerability management, application security testing, DevSecOps, penetration testing, security tooling, or cloud posture management programs is strongly preferred • Experience partnering with infrastructure, application development, cloud, identity, security operations, GRC, and business technology teams to reduce enterprise technology risk is strongly preferred • Eight (8) or more years of information security, technology risk, security engineering, or related experience is strongly preferred, including demonstrated leadership accountability • Strong leadership, communication, organizational, and internal business customer leadership skills • Ability to translate technical security findings, control gaps, and threat scenarios into business risk, prioritized action, and executive-level communication • Broad knowledge of vulnerability management, exposure management, application security, DevSecOps, penetration testing, web application security, API security, cloud security, endpoint protection, email security, and configuration management practices • Solid understanding of vulnerability scanners, risk reporting platforms, SAST, SCA, container security, WAF, bot management, EDR, CSPM, SIEM integrations, secrets management, certificate management, and identity-related security platforms • Ability to lead multi-functional remediation efforts across ownership, technical complexity, business impact, and risk acceptance decisions • Knowledge of NIST CSF, ISO 27001/27002, OWASP, MITRE ATT&CK, CIS Benchmarks, secure SDLC, and IT service management • Ability to develop metrics and reporting demonstrating security posture, remediation progress, control effectiveness, service health, and business value • Ability to operate effectively in a distributed, matrixed environment • Ability to partner with architecture, delivery, operations, infrastructure, cloud, identity, and business teams • Strong vendor management, proof-of-value, requirements development, and technology evaluation skills • Fluency with Microsoft Office and collaboration tools • Certifications such as CISSP, CISM, CCSP, GIAC, Azure Security, AWS Security, or similar are preferred but not required • Ability to prioritize work, establish timelines, handle tradeoffs, and deliver outcomes by deadline
• Health insurance • Dental insurance • Vision insurance • Paid time off • Life insurance • 401(k) with a company match • Mental health coverage • Gender affirming benefits • Family building benefits • Paid parental leave • Associate discounts • Community involvement opportunities • Bonus or Incentive Plan eligibility
Apply Now🔥 1 hour ago
Endpoint Security Engineer engineering EDR/XDR protection for Dragonfli Group’s federal-agency clients. Securing massive endpoint, server, virtualization, and multi-cloud environments.
🔥 1 hour ago
Corporate Counsel advising DoorDash’s delivery marketplace on cybersecurity incidents, investigations, and enforcement. Developing legal strategies to disrupt cybercrime and protect customers, merchants, and partners.
🇺🇸 United States – Remote
💵 $183.6k - $270k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
🔥 1 hour ago
Senior AI Security Engineer securing PartsBase's global aviation marketplace, cloud infrastructure, and applications. Building AI-driven threat detection and remediation automations.
🗣️🇪🇸 Spanish Required
🔥 16 hours ago
Expert Security Engineer protecting Activision’s Call of Duty through advanced anti-cheat systems. Designing detection technology and strengthening game security for millions of players.
🇺🇸 United States – Remote
💵 $124k - $229.4k / year
⏰ Full Time
🟠 Senior
🔴 Lead
👮♂️ Cybersecurity / Security Engineer
🔥 18 hours ago
Applied AI Security Engineer securing AI tools, integrations, and workflows at Waabi, a Physical AI company. Building guardrails for autonomous trucks and robotaxis.
🇺🇸 United States – Remote
💵 $139k - $258k / year
💰 Venture Round on 2023-01
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor