via Remote Rocketship
$90K - 140K a year
Lead and operate comprehensive cybersecurity programs including SaaS product security, cloud infrastructure, incident response, and SOC 2 readiness.
Requires 8+ years experience with 3+ years in leadership roles securing SaaS products, cloud, and infrastructure with SOC 2 audit experience and relevant certifications.
Job Description: • Define and operate Smartlinx's cybersecurity program across multi-tenant SaaS products, cloud infrastructure, corporate technology, data platforms, integrations, and third-party services • Own SaaS product and application security, cloud and infrastructure security, identity and access management, vulnerability management, security monitoring, incident response, third-party risk, and SOC 2 Type II readiness • Lead threat modeling, security architecture reviews, abuse-case analysis, risk assessments, secure coding guidance, automated security testing, penetration testing, and remediation • Establish secure cloud baselines and govern network security, secrets, certificates, encryption, privileged credentials, patching, endpoint protection, vulnerability scanning, and configuration management • Review security of databases, data platforms, data exchanges, backups, and disaster-recovery environments • Lead SOC 2 Type II readiness, control design, evidence collection, auditor coordination, remediation, management responses, and annual attestation • Maintain security policies, standards, procedures, risk register, evidence repository, exception records, remediation plans, and executive compliance reporting • Apply HIPAA and HITECH requirements and support customer contractual security obligations • Establish unified vulnerability-management and third-party security programs • Define security monitoring, detection use cases, incident-response plans, escalation paths, investigations, containment, recovery, forensics, and post-incident reviews • Conduct tabletop exercises and drive corrective actions to closure • Establish identity-first security with least privilege, multifactor authentication, privileged access management, conditional access, and access certification • Govern data classification, access, encryption, masking, retention, deletion, secure disposal, and data-loss prevention • Develop cybersecurity strategy, operating plan, budget, staffing model, roadmap, executive and Board reporting, and security scorecard • Select and manage security tools, deliver security education, and recruit, coach, and develop security personnel Requirements: • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related field, or equivalent practical experience • 8+ years of progressive experience across product, application, cloud, infrastructure, or security-operations disciplines • 3+ years in a lead, principal, architect, or security-program ownership role • Experience securing multi-tenant B2B SaaS products in healthcare, payroll, HR technology, or another regulated environment • Experience protecting PHI, PII, financial, or other sensitive data • Hands-on experience leading at least one successful SOC 2 Type II audit cycle • Strong Microsoft Azure security experience across cloud networking, identity, compute, storage, databases, containers, Kubernetes, infrastructure as code, secrets, logging, monitoring, backup, and recovery • Deep knowledge of secure software development, threat modeling, web, mobile, and API security, authentication, authorization, tenant isolation, OWASP risks, and DevSecOps practices • Hands-on experience with SAST, DAST, SCA, SBOM, secrets scanning, SIEM, EDR, DLP, WAF, CSPM, vulnerability scanning, penetration testing, and related security capabilities • Experience managing vulnerabilities, security findings, and incidents through risk assessment, containment or remediation, retesting, exception management, post-incident review, and executive reporting • Knowledge of SOC 2 Trust Services Criteria, NIST Cybersecurity Framework, CIS Controls, ISO 27001, and HITRUST • Ability to make risk-based decisions, balance security with product delivery, influence cross-functional stakeholders, and explain technical risks clearly • Relevant certifications such as CISSP, CCSP, CISM, CISA, CSSLP, OSCP, GIAC, HITRUST CCSFP, or Microsoft Azure Security Engineer are preferred • Experience with Entra ID, Defender, Sentinel, Azure DevOps, Snowflake, or Microsoft Fabric is preferred Benefits: • 10% bonus eligible • Remote work environment • Medical insurance • Dental insurance • Vision insurance • FSA • HSA • Life insurance • Pet insurance • 401(k) • Professional development and skills growth opportunities • Occasional travel up to 15%
This job posting was last updated on 9/22/2026