Lead Cybersecurity Engineer
The job description
Tech stack. SIEM and EDR platforms, vulnerability management tooling, Jira and runbook documentation, Python for automation, cloud security fundamentals, PCI DSS and SOC 2 controls, security metrics dashboards
About the role
You will lead a pod of security engineers at a financial services company, protecting customer data and payment systems that cannot afford downtime, breach, or regulatory failure. You stay hands-on with the hardest technical problems while owning the team's roadmap, hiring decisions, and professional growth. You will run the operating cadence: planning, on-call, incident reviews, and stakeholder updates. This role matters because you turn a group of talented individuals into a team that ships measurable security outcomes quarter after quarter, and in a regulated industry the documented evidence of that discipline is exactly what auditors, partners, and customers rely on.
What you will achieve
- Grow a pod of 3 to 5 engineers into a fully on-call-ready team with documented, practiced runbooks for every critical alert type and clean handoffs.
- Deliver the quarterly security roadmap on schedule, hitting 90 percent of committed detection engineering and hardening milestones.
- Reduce critical vulnerability dwell time to under 14 days through a prioritized, SLA-driven remediation program with unambiguous ownership for every asset group.
- Build the hiring bar and structured interview loop that doubles the team without dropping the quality standard you personally set.
- Ship a security metrics dashboard leadership genuinely uses, tracking MTTR, control coverage, and risk trends in a weekly operational review.
What you will bring
Must-haves
- 7+ years in security engineering or security operations, including 2+ years mentoring or directly leading engineers.
- Strong incident response and detection engineering fundamentals you can teach to others through pairing, review, and example.
- Experience planning and delivering a team roadmap with measurable, committed outcomes across multiple quarters.
- Ability to run on-call rotations, postmortems, and blameless reviews that genuinely improve the system instead of assigning fault.
- Working knowledge of compliance drivers such as PCI DSS and SOC 2 in a continuously audited environment.
- Direct, kind communication with engineers and executives alike, adjusting technical depth to fit the audience.
- Hiring judgment: you can assess both technical skill and team contribution in candidates.
Nice-to-haves
- Prior tech-lead experience specifically in a SOC or detection engineering team.
- Familiarity with risk-based vulnerability prioritization platforms and SLA framework design.
- A security certification such as CISSP or GSEC.
- Experience presenting security posture to non-technical boards or regulators.
Google
Microsoft
CrowdStrike
Palo Alto Networks
Cisco
Okta