CyberSecurity Manager @Lean Solutions Group
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 1mth ago

[Hiring] CyberSecurity Manager @Lean Solutions Group

1mth ago - Lean Solutions Group is hiring a remote CyberSecurity Manager. πŸ’Έ Salary: unspecified πŸ“Location: Colombia

Role Description

You will be the first dedicated security hire and the single owner of our security posture. Nobody else is going to do this for you, and nobody else is going to do it for you, you set the program, you run it, you maintain compliance, you’re accountable for it.

Your first-year headline objective: get the company to a clean SOC 2 Type II certification report. Everything else supports that or protects the company while you do it. Once certification is achieved, you will be fully responsible for always maintaining it.

This is a hands-on role. You will:

  • Write Terraform
  • Tune AWS security controls
  • Build policies
  • Run tabletops
  • Enforce personnel compliance
  • Chase evidence
  • Sit on customer security calls

If you want to build a real security program from scratch and own the outcome, it is.

Qualifications

  • 5 – 7 years in security, with meaningful hands-on ownership rather than pure oversight
  • Degree in computer science or related field
  • Deep, practical AWS security experience in a production environment
  • You have taken at least one compliance audit (SOC 2, ISO 27001, HITRUST, or similar) from gap assessment through to issued report
  • Working knowledge of HIPAA and handling PHI in a SaaS environment
  • Comfort in infrastructure as code (Terraform preferred) and scripting to automate controls
  • Ability to write clearly β€” policies, customer responses, and executive updates all land on your desk
  • Judgment about risk. You can tell a real threat from an audit artifact and prioritize accordingly

Requirements

  • SOC 2 certification (the priority)
  • Define scope and trust services criteria; run the readiness/gap assessment
  • Close control gaps across engineering, AWS Cloud, IT, HR, and operations
  • Select and manage the audit firm; own the relationship and timeline
  • Drive Type I, then manage the observation window through to Type II
  • Build the program so year-two renewal is routine, not a fire drill
  • Full ownership as administrator: control mapping, monitoring coverage, and evidence automation
  • Policy lifecycle β€” author, version, publish, and enforce annual attestation
  • Personnel onboarding/offboarding controls, enforcing personnel compliance, access reviews, and background check tracking
  • Vendor and risk registers kept genuinely current, not backfilled the week before an audit
  • AWS cloud security
  • IAM least privilege, role hygiene, and elimination of long-lived credentials
  • AWS Organizations, SCPs, and account separation between environments
  • GuardDuty, Security Hub, Config, CloudTrail, and centralized log retention
  • Encryption at rest and in transit; KMS key management and rotation
  • VPC design, network segmentation, security group review, WAF
  • Secrets management, S3 and RDS access controls, and public-exposure prevention
  • Backup, restore testing, and disaster recovery with defined RTO/RPO
  • Patch and vulnerability management with remediation SLAs that are actually met
  • Application security (with Engineering)
  • Owning Aikido for repository scanning and vulnerability resolution with engineering
  • Bi-annual pentesting with Aikido
  • Embed SAST, DAST, dependency, and IaC scanning into CI/CD
  • Secure SDLC standards, security review of designs, and developer guardrails
  • Coordinate annual penetration testing and drive remediation to closure
  • Audit logging and monitoring of PHI access inside our products
  • HIPAA and healthcare-specific compliance
  • Serve as our designated HIPAA Security Official
  • Maintain the HIPAA Security Rule risk analysis and risk management plan
  • BAA governance in both directions β€” customers and subprocessors
  • 42 CFR Part 2 controls for substance use disorder records
  • Breach assessment and notification procedures, with defined timelines
  • Track applicable state privacy laws affecting our customer base
  • Identity, endpoints, and internal IT security
  • SSO and enforced MFA across all business systems
  • MDM, disk encryption, and endpoint protection on every company device
  • Quarterly access reviews and least-privilege enforcement on internal tools
  • Physical security
  • Office access control, visitor procedures, and badge/key management
  • Camera coverage, clean desk standards, and secure device and document disposal
  • Remote and home-office security standards for our distributed staff
  • Document inherited AWS data center controls for audit purposes
  • Incident response
  • Write and maintain the IR plan; define severity levels and escalation paths
  • Run tabletop exercises at least semiannually, including a ransomware and a PHI-exposure scenario
  • Lead investigations and post-incident reviews
  • Security awareness and customer trust
  • Annual training plus ongoing phishing simulations, with completion enforcement
  • Own security questionnaires, RFP responses, and customer security calls β€” fast turnaround here directly wins deals
  • Maintain our public trust page and customer-facing security documentation

Benefits

  • Join a powerful tech workforce and help us change the world through technology
  • Professional development opportunities with international customers
  • Collaborative work environment
  • Career path and mentorship programs that will lead to new levels
Before You Apply
️
remote Be aware of the location restriction for this remote position: Colombia
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
CyberSecurity Manager @Lean Solutions Group
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Colombia
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,868+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later