Search Remote Jobs

Lead, Cybersecurity

🔥 1 hour ago

🇺🇸 United States – Remote

đź’µ $150k / year

⏰ Full Time

đźź  Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

đź‘» Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Smartlinx

Smartlinx

51 - 200 employees

Founded 2000

🏥 Healthcare

đź’Ľ Consulting

📦 Logistics

đź’° Private equity on 2020-04

Healthcare • Consulting • Logistics

Smartlinx is a SaaS workforce management and HR platform purpose-built for senior care providers and healthcare staffing organizations. It delivers scheduling, time & attendance, payroll, PBJ/CMS compliance reporting, workforce analytics, unified HR (recruiting, onboarding, benefits), contingent staff and vendor management, and mobile employee tools to optimize labor, maintain regulatory compliance, and improve staff engagement and retention.

đź“‹ Description

• Define and operate Smartlinx's cybersecurity program across multi-tenant SaaS products, cloud infrastructure, corporate technology, data platforms, integrations, and third-party services • Own SaaS product and application security, cloud and infrastructure security, identity and access management, vulnerability management, security monitoring, incident response, third-party risk, and SOC 2 Type II readiness • Lead threat modeling, security architecture reviews, abuse-case analysis, risk assessments, secure coding guidance, automated security testing, penetration testing, and remediation • Establish secure cloud baselines and govern network security, secrets, certificates, encryption, privileged credentials, patching, endpoint protection, vulnerability scanning, and configuration management • Review security of databases, data platforms, data exchanges, backups, and disaster-recovery environments • Lead SOC 2 Type II readiness, control design, evidence collection, auditor coordination, remediation, management responses, and annual attestation • Maintain security policies, standards, procedures, risk register, evidence repository, exception records, remediation plans, and executive compliance reporting • Apply HIPAA and HITECH requirements and support customer contractual security obligations • Establish unified vulnerability-management and third-party security programs • Define security monitoring, detection use cases, incident-response plans, escalation paths, investigations, containment, recovery, forensics, and post-incident reviews • Conduct tabletop exercises and drive corrective actions to closure • Establish identity-first security with least privilege, multifactor authentication, privileged access management, conditional access, and access certification • Govern data classification, access, encryption, masking, retention, deletion, secure disposal, and data-loss prevention • Develop cybersecurity strategy, operating plan, budget, staffing model, roadmap, executive and Board reporting, and security scorecard • Select and manage security tools, deliver security education, and recruit, coach, and develop security personnel

🎯 Requirements

• Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related field, or equivalent practical experience • 8+ years of progressive experience across product, application, cloud, infrastructure, or security-operations disciplines • 3+ years in a lead, principal, architect, or security-program ownership role • Experience securing multi-tenant B2B SaaS products in healthcare, payroll, HR technology, or another regulated environment • Experience protecting PHI, PII, financial, or other sensitive data • Hands-on experience leading at least one successful SOC 2 Type II audit cycle • Strong Microsoft Azure security experience across cloud networking, identity, compute, storage, databases, containers, Kubernetes, infrastructure as code, secrets, logging, monitoring, backup, and recovery • Deep knowledge of secure software development, threat modeling, web, mobile, and API security, authentication, authorization, tenant isolation, OWASP risks, and DevSecOps practices • Hands-on experience with SAST, DAST, SCA, SBOM, secrets scanning, SIEM, EDR, DLP, WAF, CSPM, vulnerability scanning, penetration testing, and related security capabilities • Experience managing vulnerabilities, security findings, and incidents through risk assessment, containment or remediation, retesting, exception management, post-incident review, and executive reporting • Knowledge of SOC 2 Trust Services Criteria, NIST Cybersecurity Framework, CIS Controls, ISO 27001, and HITRUST • Ability to make risk-based decisions, balance security with product delivery, influence cross-functional stakeholders, and explain technical risks clearly • Relevant certifications such as CISSP, CCSP, CISM, CISA, CSSLP, OSCP, GIAC, HITRUST CCSFP, or Microsoft Azure Security Engineer are preferred • Experience with Entra ID, Defender, Sentinel, Azure DevOps, Snowflake, or Microsoft Fabric is preferred

🏖️ Benefits

• 10% bonus eligible • Remote work environment • Medical insurance • Dental insurance • Vision insurance • FSA • HSA • Life insurance • Pet insurance • 401(k) • Professional development and skills growth opportunities • Occasional travel up to 15%

Apply Now

Similar Jobs

🔥 2 hours ago

nimble solutions

1001 - 5000

đź’Ľ Consulting

📦 Logistics

🛡️ Insurance

IT Security Manager leading Microsoft security operations, compliance, and incident response. Managing cross-border teams for a surgical revenue-cycle solutions provider.

🔥 3 hours ago

Tripoint Solutions

51 - 200

🏛️ Government

đź”’ Cybersecurity

đź’Ľ Consulting

Salesforce Security Specialist designing access controls and protecting enterprise data for Tripoint Solutions’ federal technology platforms. Supporting compliance, audits, encryption, and secure Salesforce integrations.

🔥 13 hours ago

MindSet

1 - 10

đź’Ľ Consulting

📚 Education

👥 HR Tech

Social Security Disability Hearing Attorney representing SSI/SSDI claimants for Mindset Care. Preparing applications, appeals, evidence, and legal advocacy before administrative law judges.

🔥 15 hours ago

Triumph Enterprises, Inc.

51 - 200

🎖️ Defense

📦 Logistics

🏭 Manufacturing

Configuration Management and Documentation Specialist organizing federal cybersecurity artifacts, intake workflows, and reporting. Supporting the Department of Veterans Affairs cybersecurity architecture and engineering program.

🔥 16 hours ago

Comcast

10,000+ employees

📡 Telecommunications

🏛️ Government

DevSecOps Engineer securing SAP delivery for federal clients. Automating deployments, vulnerability checks, controls, and authorization evidence.