Lead Information Security Compliance Engineer - Cloud Security
Listed on 2026-02-15
-
IT/Tech
Cybersecurity, IT Consultant, Information Security, Data Security
Crestron Electronics Inc.
- 22 Link Rockleigh, NJ, 22 Link Drive, Rockleigh, New Jersey, United States of America
Posted Thursday, February 12, 2026 at 5:00 AM
At Crestron Electronics, Inc we build the technology that integrates technology.
We are proud to be the largest and most recognized brand in automation and control solutions, and the premier technology partner for fortune 500 businesses globally. Our products’ are integrated into new high-tech commercial buildings’ to include some of the most exciting real estate throughout the world. Our clients include Google, Microsoft, Amazon, Linked In and many others.
Our automation and control solutions for homes and buildings allow our clients to control entire environments with the push of a button, integrating systems such as Audio Visual, Lighting, Shading, Security, Building Management Systems and HVAC to provide greater comfort, convenience and security.
Summary
The Lead Security Compliance Engineer – Cloud Security is responsible for leading security compliance and risk management activities for a SaaS platform hosted in Microsoft Azure. This role partners closely with engineering, product, cloud operations, and security teams to embed security and compliance into the feature development lifecycle, ensure effective incident and vulnerability management, and maintain alignment with industry and regulatory standards including ISO 27001, NIST 800‑53, and other industry certifications.
This position serves as a senior technical and compliance authority, providing guidance on modern cloud security controls, overseeing audits, and driving continuous improvement of the organization’s security posture.
Responsibilities
- Perform security and threat assessments for new features, architectural changes, and SaaS platform enhancements.
- Participate in change management and feature development processes, ensuring security and compliance requirements are integrated early (shift‑left security).
- Identify security risks related to cloud services, data handling, identity, and application design, and recommend mitigation strategies.
- Provide informed recommendations for information security controls, tools and applications specifically tailored to modern Azure based applications.
- Lead or support incident management activities for SaaS environments and cloud services.
- Drive incident investigations, root cause analysis, and documentation.
- Assist with defining and tracking corrective and preventive actions (CAPAs), ensuring remediation timelines are met.
- Monitor and validate the effectiveness of corrective actions following incidents.
- Maintain strong knowledge of software vulnerabilities, security scanning, and assessment tools.
- Assist with prioritization of vulnerability remediation based on risk, exploitability, and customer impact.
- Advocate for remediation of high‑risk findings and track remediation progress.
- Support coordination of public vulnerability disclosures and customer communications, as required.
- Oversee ISO/IEC 27001 compliance, including maintenance of the ISMS.
- Lead and coordinate external audits (ISO 27001, customer audits, regulatory assessments).
- Plan and conduct internal audits, including control testing, evidence collection, and remediation tracking.
- Ensure alignment with NIST 800‑53, FedRAMP, and other applicable frameworks.
- Support continuous improvement of compliance processes, metrics, and reporting.
- Serve as a trusted security and compliance advisor to engineering, product, legal, risk, and operations teams.
- Translate compliance and security requirements into practical, implementable technical controls.
- Contribute to policy, standard, and procedure development related to cloud security and compliance.
Qualifications
- Bachelor degree in Computer Science, Information Security, Compliance, Cybersecurity or a related field experience.
- Industry security certifications such as CISA, CISM, CRISC, CISSP.
- Industry certifications in Cloud such as AWS, Azure.
- 8-12 years of experience in cybersecurity, security compliance, or cloud security roles.
- 8+ years of hands‑on experience with Microsoft Azure environments, including SaaS or cloud‑native architectures.
- Proven…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).