Senior IT Security Engineer
Listed on 2026-08-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Project Manager
About INIT
INIT Innovations in Transportation, Inc. is a leading provider of hardware, software, service, support, and operations management solutions for public transportation companies across North America. As a turnkey supplier, INIT develops, produces, installs, and maintains integrated hardware and software solutions for all key tasks required by transportation authorities, including fare collection systems, passenger counting, CAD/AVL systems, passenger information systems, and other Intelligent Transportation System solutions.
Our Information Technology team designs, builds, operates, and maintains infrastructure in support of INIT software solutions deployed for transit agency customers in major metropolitan areas including Atlanta, Houston, Los Angeles, San Diego, Seattle, Portland, Tampa, Honolulu, and more.
Position SummaryINIT is seeking a Senior IT Security Engineer to drive security controls, security operations and GRC activities across INIT's internal corporate infrastructure and customer-facing transit technology deployments.
This role contributes to the security architecture, security operations and control framework across PCI DSS, SOC 2, and ISO 27001. The Senior IT Security Engineer works closely with the IT Security Administrator, IT Operations, and IT Systems Engineering teams, and reports to the Director of IT.
Key Responsibilities Security Strategy- Establish security vision, strategy, and roadmaps with the Director of IT, encompassing internal programs and customer-facing security commitments.
- Direct the selection and lifecycle of security tools, architectures, and infrastructure security direction across the organization.
- Establish identity, access, and security hardening standards, including Conditional Access, privileged access, and CIS benchmark requirements, for implementation across the environment.
- Evaluate security requirements and architecture for customer projects and proposals, identifying gaps, strategies, and budgets needed to meet requirements, and make final decisions on customer project security architecture.
- Identify strategic trends affecting the company's security posture and customer trust.
- Evaluate and guide secure adoption of AI tools and platforms across IT and business functions, balancing productivity gains against data protection, compliance, and vendor risk.
- Serve as incident commander or alternate incident commander during security incidents.
- Direct threat intelligence efforts, monitoring emerging threats, vulnerabilities, and attacker techniques relevant to the transit technology industry, and translating findings into operational and architectural changes.
- Lead the tabletop exercise program, setting cadence, scope, and participation across technical and business stakeholders, and direct post-exercise and post-incident retrospectives that translate findings into playbook and control updates.
- Communicate security posture, risk exposure, and incident status to senior management and, as needed, to customers.
- Oversee operational security strategy across customer projects, including contractual security and compliance obligations.
- Direct the organization's risk management program, identifying, assessing, and prioritizing information security risks and recommending treatment strategies to leadership.
- Establish and maintain the security control framework mapping across PCI DSS, SOC 2, and ISO 27001, ensuring controls satisfy overlapping framework requirements.
- Serve as the primary point of contact for external auditors and assessors during compliance audits and certification cycles, and direct remediation of audit findings and gap assessment outcomes.
- Evaluate new regulatory and contractual requirements and translate them into control requirements.
- Set direction for the organization's security policy suite, leading the creation, review, and revision of information security policies and procedures.
- Lead third-party vendor security risk management, directing vendor risk assessments, critical vendor classification, and ongoing monitoring of vendor compliance obligations.
- Direct the security awareness and training program, setting curriculum priorities, campaign cadence, and risk-based focus areas for the organization.
- Set risk-based prioritization standards for the vulnerability management program and review remediation trends against risk tolerance.
- 10+ years of experience in information security, risk management, or compliance, with increasing responsibility.
- Proven experience establishing and directing information security strategy, governance, and risk management programs.
- Security-relevant certification required, such as CISSP, CISM, CISA, or CRISC, or actively pursuing one.
- Experience implementing, assessing, or designing systems within PCI DSS, SOC 2, ISO 27001, or NIST 800-53 frameworks.
- Experience serving as incident commander or leading incident response efforts.
- Proven ability to communicate security…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).