Lead InfoSec Engineer @Aspenware
All Others
Salary usd 145,000 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 2d ago

[Hiring] Lead InfoSec Engineer @Aspenware

2d ago - Aspenware is hiring a remote Lead InfoSec Engineer. 💸 Salary: usd 145,000 - 175,000 per year 📍Location: USA

Role Description

The Lead Infosec Engineer will be responsible for leading Aspenware’s existing security program and optimizing it to be even more robust. You will manage Aspenware’s security operations including IT vendor and MSSP relationships. You will lead efforts to mitigate existing and emerging cybersecurity threats. You will assess, prioritize, and remediate security risks to improve Aspenware’s overall cybersecurity posture.

This is a key role at Aspenware and reports to the Director of Technology Operations & Security. You will work closely with the VP of Technology, other engineering leaders, and business stakeholders to represent the security needs of our platform and hold the enterprise to a rigorous standard of security. Finally, you will collaborate with the Infosec teams at our parent company, Alterra Mountain Co. You will be responsible for sharing strategies, roadmap progress, and incident retrospectives wherever the larger enterprise is impacted.

What You Will Do

  • Partner with engineering teams and systems architects to ensure the security of our products, cloud infrastructure, and technical platform
  • Be the champion of rigorous security standards when debating resource allocation tradeoffs
  • Improve Aspenware’s AppSec and SDLC security
  • Understand key security attack vectors and protect Aspenware from malicious actors who wish to abuse our system
  • Manage our security vendor relationships with respect to requirements and technical support
  • Lead the company from its recently earned Type I SOC 2 accreditation through Type 2 accreditation
  • Assist end users to remediate security issues
  • Work with external vendors to provide oversight for computers, devices, and networks in a remote work environment
  • Manage and evaluate external vendors to conduct pen testing, endpoint testing, purple team testing, and PCI scans
  • Develop and document network security reference architectures, design patterns, roadmaps, and other architectural artifacts aligned with policies, standards, and industry best practices
  • Work closely with our DevOps team to manage cloud security in Azure
  • Evaluate Azure cloud and hybrid security services, tools, and appliances in the areas of (but not limited to): intrusion detection, intrusion prevention, packet capture, and quarantine
  • Assess network/cloud security posture and recommend modifications for enhancements, improvements, and mitigations
  • Collaborate with enterprise partners and incident response teams regarding requirements and deployment of security services, tools, and appliances
  • Review access control policies and assist in Identity and Access Management through MS Entra
  • Ensure compliance with NIST CSF or similar frameworks and meet disclosure obligations
  • Identify opportunities to improve existing security processes, policies, and tooling
  • Help cultivate and foster a culture of security across the entire organization by driving awareness and promoting a cohesive narrative around security
  • Perform in-depth investigations when the suspicion of a threat emerges
  • Coordinate mitigation and remediation plans to address critical risks

Qualifications

  • Experience owning the Infosec strategy for SaaS companies, especially in ecommerce
  • Expert knowledge of AppSec, Infrastructure security, access control, and GRC
  • 4+ years of experience in a cybersecurity role within a software development organization
  • 8+ years in technical roles – as a software engineer, information security analyst or similar
  • Masters or bachelor's degree in Information Systems with a focus in cyber security or equivalent experience / certifications
  • Experience with NIST CSF, ISO27001, PCI, SOC2 or similar standards/certifications
  • CISSP, CISM, CRISC, CCSP
  • Experience with OWASP or similar standards
  • Experience with DevSecOps
  • Direct experience with Azure cloud security
  • Hands-on experience establishing and configuring security controls for Microsoft Azure and Microsoft 365 components
  • Understanding of DDOS and other infrastructure threats at the edge
  • Strong understanding of security as it relates to CDN, API management, and load balancing technologies
  • Strong understanding of Azure monitoring capabilities
  • Willingness to jump into a complex, fast-paced environment

Benefits

  • 4 weeks of PTO to start and increases with seniority
  • 11 paid holidays
  • 6 days of sick time
  • Paid parental leave for both primary and secondary parents
  • Medical, dental, and vision insurance
  • Life insurance
  • 401k plan with a 5% match
  • Annual all-company ski day
  • Seasonal Ski Pass – Ikon Pass
  • National Park Pass
  • Annual Wellness Stipend
  • Flexible work environment
Before You Apply
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Lead InfoSec Engineer @Aspenware
All Others
Salary usd 145,000 - 1..
Remote Location
🇺🇸 USA Only
Employment Type full-time
Posted 2d ago
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
️
🇺🇸 Be aware of the location restriction for this remote position: USA Only
‼ Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply ✓
Applied ✓
Sent Follow-Up ✓
Interview Scheduled ✓
Interview Completed ✓
Offer Accepted ✓
Offer Declined ✓
Application Denied ✓
Unlock 125,000+ Remote Jobs
×
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 ★★★★★ from 500+ reviews

⚡ 129,413+ remote jobs, refreshed hourly

🔔 Real-time alerts: Apply first, direct to employer

🛡️ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later