Назад
Company hidden
8 дней назад

Lead Security Engineer

Формат работы
remote (Global)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Lead Security Engineer (Cloud Security/Compliance): Leading the security team and owning the end-to-end security and compliance program for a SaaS platform handling guest data and payments, with an accent on SOC 2, PCI DSS, GDPR/CCPA, cloud security, and risk management. Focus on building risk-based security programs, reviewing threat models and architecture, managing audits and third-party risk, and communicating security posture to customers, partners, and executives.

Location: Remote in the United States or LATAM

Company

hirify.global provides an agentic AI platform for hotel and guest management, supporting digital infrastructure for more than 20,000 hotels in 125+ countries.

What you will do

  • Lead, coach, and grow a small Security team, including hiring, performance management, prioritization, and career development.
  • Own the security and compliance program across SOC 2, PCI DSS, GDPR/CCPA, and other applicable frameworks.
  • Act as the primary security point of contact for customers, partners, auditors, and internal executives.
  • Manage vendor and third-party risk, including reviewing security terms in contracts.
  • Write, maintain, and communicate security policies and standards, and run security awareness training.
  • Set technical direction for security tooling while staying hands-on with architecture and threat-model reviews.

Requirements

  • 8+ years of experience in security engineering, including 2+ years leading a team as a manager or technical lead.
  • End-to-end ownership of compliance programs such as SOC 2 Type II, PCI DSS, or ISO 27001.
  • Hands-on experience with AWS cloud security, identity and access management, application security, and vulnerability management.
  • Experience with vendor risk management and security reviews of customer and vendor contracts.
  • Track record of building pragmatic, risk-based security programs at a growth-stage SaaS company.
  • Exceptional written and verbal communication skills.

Nice to have

  • Experience in hospitality, fintech, or payments.
  • CISSP, CISM, or CISA certification.

Culture & Benefits

  • Unlimited paid time off, standard holidays, monthly company-wide Canary Days, and a birthday holiday.
  • Travel stipend for office exchanges at hubs in San Francisco, New York, or Dallas.
  • Hotel stay credit at Canary hotels and discounts at selected partner hotels.
  • Monthly self-improvement budget and a professional development stipend.
  • Referral bonus program.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →