Lead Cybersecurity Engineer 🇺🇸
Apexcare Talent Solutions
Los Angeles Blvd, San Anselmo, CA 94960, USAJob Overview
We are seeking an experienced Lead Cybersecurity Engineer to oversee our enterprise security architecture, drive strategic defense initiatives, and ensure the resilience of our infrastructure and sensitive systems. In this role, you will act as a technical authority for security, designing scalable defense controls across multi-cloud environments, leading high-visibility threat modeling and incident response, and mentoring senior security engineering staff. You will work closely with executive leadership, DevOps, and software architecture teams to balance rapid technical execution with rigorous risk management and federal regulatory compliance standards.
Key Responsibilities
Security Architecture & Technical Leadership
- Lead the vision, architecture, and deployment of enterprise-wide security solutions across multi-cloud (AWS, GCP, or Azure) and hybrid environments.
- Establish architectural patterns for Zero Trust Network Access (ZTNA), Identity and Access Management (IAM), data encryption, and microsegmentation.
- Partner with engineering leadership to integrate automated security checks (SAST, DAST, SCA) into global CI/CD pipelines, driving DevSecOps maturity.
Incident Oversight & Threat Intelligence
- Oversee critical incident response operations, threat intelligence feeds, and proactive threat-hunting campaigns.
- Direct root-cause analyses and post-incident reviews following security events, authoring executive reports and establishing long-term remediation roadmaps.
- Conduct advanced risk assessments and threat modeling for new platforms, software features, and vendor integrations.
Compliance & Strategic Governance
- Ensure enterprise compliance with stringent regulatory frameworks and federal standards (e.g., NIST SP 800-53, FedRAMP, SOC 2, CMMC, ISO 27001).
- Define organizational security engineering standards, baselines, and hardening guidelines across systems, containers, and network infrastructures.
- Mentor and lead senior and mid-level cybersecurity engineers through code reviews, architectural feedback, and technical career growth.
Required Skills & Qualifications
Technical Skills & Expertise
- Cloud & Infrastructure Security: Mastery in securing enterprise public cloud platforms (AWS/Azure/GCP), container Orchestration (Kubernetes, Docker), and Infrastructure-as-Code (Terraform, CloudFormation).
- Security Operations & Tooling: Expert knowledge of SIEM/SOAR platforms (Splunk, Elastic, Datadog), EDR/XDR, and vulnerability management platforms (Tenable, Qualys).
- Scripting & Automation: High proficiency in Python, Bash, or Go to build automated security tooling, custom integrations, and incident response playbooks.
- Network & AppSec: Strong proficiency in modern cryptography, Web Application Firewalls (WAF), API security, and network protocol security (TLS, IPsec, DNSSEC).
Clearance & Compliance Requirements
- US Citizenship: Must be a US Citizen (required due to federal contract/compliance requirements).
- Active Security Clearance or ability to obtain/maintain US Government clearance (Secret/Top Secret) preferred depending on program assignments.
Soft Skills & Domain Requirements
- Executive presence with proven ability to communicate complex security risks and investment trade-offs to C-suite leadership and board members.
- Strategic, proactive mindset with exceptional crisis management capabilities during security emergencies.
Preferred Qualifications
- Education: Bachelor’s or Master’s degree in Cybersecurity, Computer Science, Information Technology, or equivalent technical experience.
- Experience: 8+ years of dedicated cybersecurity engineering experience, with 2+ years in a team lead, principal, or architectural capacity.
- Industry Certifications: CISSP, CISM, CCSP, OSCP, or specialized cloud certifications (e.g., AWS Certified Security - Specialty).
Benefits & Compensation
- Salary Range: $165,000 – $210,000 annually (commensurate with experience) + performance bonus.
- Comprehensive medical, dental, and vision health coverage.
- 401(k) retirement plan with high company match.
- Flexible paid time off (PTO) and company-paid federal holidays.
- Dedicated continuous learning stipend for security certifications, labs, and security conference attendance.