Director, Cybersecurity Engineering
Listed on 2026-07-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Overview
The Commercial Technologies Operational Security Lead is a Director role responsible for ensuring the security, resilience, and operational integrity of customer‑facing technology solutions, including software, platforms, and integrated hardware offerings. The role provides hands‑on leadership and expertise across vulnerability research, security engineering, product security, and operational assurance for technology delivered to external customers. It partners closely with product, engineering, cloud, and commercial technology teams to design, implement, validate, and continuously improve security controls throughout the product lifecycle.
This role enables secure innovation, protects customer trust, and ensures solutions meet regulatory, contractual, and risk expectations in a highly regulated environment.
- Provide security oversight and operational assurance for customer‑facing software and hardware technology solutions across development, deployment, and runtime operations.
- Define, assess, and validate security controls for commercial technology platforms, ensuring alignment with enterprise security standards, regulatory requirements, and customer expectations.
- Lead vulnerability research, analysis, and operational response across applications, platforms, infrastructure, and embedded technologies.
- Partner with engineering and product teams to integrate security into architecture, design, and development processes using secure‑by‑design and shift‑left principles.
- Support product security activities including threat modeling, secure design reviews, penetration testing coordination, and remediation validation.
- Provide security architecture guidance for virtualized, cloud‑native, hybrid, and containerized environments supporting customer solutions.
- Oversee vulnerability management operations for commercial technologies, including scanning, prioritization, remediation tracking, and risk acceptance.
- Collaborate with Dev Sec Ops teams to drive automation of security testing, control validation, and continuous monitoring.
- Ensure security requirements are embedded into CI/CD pipelines and product release processes.
- Act as a key liaison between commercial technology teams, enterprise security, risk management, and compliance functions.
- Support customer assurance activities, including security questionnaires, audits, attestations, and incident response coordination.
- Contribute to incident response and root cause analysis for security events impacting customer‑facing technologies.
- Identify gaps, emerging risks, and improvement opportunities across product and operational security capabilities.
- Promote security best practices, standards, and operational maturity across commercial technology portfolios.
- Bachelor’s degree in Computer Science, Engineering, Information Security, or a related field.
- Advanced degree or relevant security certifications preferred.
- Technical Expertise: Strong experience in vulnerability research, vulnerability management operations, and remediation validation. Hands‑on experience with security engineering and product security for software‑based and integrated hardware solutions. Solid understanding of security architecture principles for cloud, virtualized, containerized, and hybrid environments. Experience securing APIs, web applications, SaaS platforms, and distributed systems. Familiarity with Dev Sec Ops practices, CI/CD pipelines, and security automation tooling.
Working knowledge of cryptography, identity and access management, and secure communications. - Operational Security & Product Assurance: Experience supporting customer‑facing technologies where security, availability, and trust are business‑critical. Ability to assess operational risk and translate findings into actionable remediation plans. Experience supporting audits, customer security reviews, and regulatory expectations.
- Experience & Leadership: 10+ years of experience in cybersecurity, product security, security engineering, or related technical disciplines. Demonstrated ability to operate as a leader, influencing outcomes through expertise…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).