via Remote Rocketship
$200K - 300K a year
Lead enterprise cybersecurity operations and engineering strategy, governance, incident response, security technologies, risk programs, budgets, and teams.
Requires 12+ years of cybersecurity experience, 7+ years of leadership, broad enterprise security and governance expertise, and a related degree or equivalent experience.
Job Description: • Lead enterprise cybersecurity operations and engineering programs, including strategy, risk governance, roadmap development, budgeting, KPI reporting, and executive communications • Contribute to cybersecurity policies, standards, procedures, and control frameworks • Develop governance forums, steering committee materials, risk updates, and business cases for senior leadership • Partner with legal, compliance, privacy, internal audit, technology, and business stakeholders • Drive consistent security practices across corporate, cloud, application, and business environments • Translate threat, control, and assessment findings into prioritized remediation plans • Provide executive oversight for SOC/MSSP performance, alert monitoring, incident triage, escalation management, and operational readiness • Own incident response planning, runbooks, tabletop exercises, and cross-functional response coordination • Oversee threat intelligence, threat detection, threat hunting, and vulnerability management capabilities • Ensure preparedness to protect, detect, respond to, and recover from cybersecurity events • Develop and monitor operational metrics and service-level indicators • Oversee cybersecurity technology and control capabilities across on-premises, cloud, endpoint, identity, and network domains • Partner with infrastructure, platform, and software engineering teams to embed security into architecture and workflows • Support secure development lifecycle, software assurance, secure coding, and application security initiatives • Guide selection and optimization of SIEM, EDR, IDS/IPS, firewalls, vulnerability management, logging, monitoring, and protection technologies • Promote automation, orchestration, and process simplification • Lead cyber risk assessments across infrastructure, applications, vendors, business processes, and emerging technologies • Support compliance and control maturity for NIST, ISO 27001, PCI-DSS, SOC, SOX, GDPR, privacy, and other requirements • Provide security leadership for vendor reviews, architectural reviews, major initiatives, and transformation programs • Build relationships with business and technology leaders to enable growth, resilience, and informed risk-taking • Champion security awareness, education, and culture-building efforts • Lead, coach, and develop cybersecurity managers and individual contributors • Foster accountability, collaboration, continuous improvement, and service-oriented partnership • Mentor technical teams on incident response, operational excellence, architecture, and executive communication • Maintain the cyber risk register and risk governance process • Support procurement calendar, budget, actuals, strategy documents, project portfolios, roadmaps, and C-suite/IT leadership materials Requirements: • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience • 12+ years of progressive cybersecurity experience, including leadership of enterprise security programs in complex, high-growth, or globally distributed organizations • 7+ years of leadership experience managing managers, cross-functional teams, and/or external service providers across multiple cybersecurity domains • Demonstrated success building or maturing cybersecurity governance, program management, security operations, and security engineering capabilities • Strong working knowledge of cybersecurity frameworks, regulatory requirements, and assurance practices, including NIST CSF, ISO 27001, PCI-DSS, SOC, SOX, data privacy, and related standards • Experience leading or overseeing incident response, threat intelligence, vulnerability management, detection engineering, and security monitoring programs • Strong technical understanding of cloud security, identity and access management, endpoint protection, network security, logging and monitoring, system hardening, and enterprise security architecture • Experience working closely with software development and infrastructure teams to integrate security into lifecycle management, architecture, and operational processes • Proven ability to define metrics, communicate risk clearly, and present meaningful security insights to operational, technical, and executive stakeholders • Strong business judgment and ability to balance risk reduction, operational efficiency, and strategic enablement • Excellent written and verbal communication skills, with ability to influence across all levels of the organization • Must be based in one of the listed remote locations: New York, Connecticut, California, New Jersey, Texas, or Ohio Benefits: • Short- and long-term incentives • Growth and developmental opportunities • Health care • Retirement • Vacation and other paid time off • Additional offerings • Reasonable accommodations for qualified individuals with disabilities
This job posting was last updated on 10/9/2026