About the Role
This role is responsible for establishing and maturing the organization's cybersecurity program, providing technical leadership across cloud and identity security, driving compliance, and serving as the primary owner of security operations and risk management.
Responsibilities
- Act as the founding cybersecurity specialist to design, implement, and manage the organization’s end-to-end security program.
- Assess current security posture, identify vulnerabilities, and collaborate with the IT Director to set strategic priorities, risk mitigation plans, and long-term roadmap goals.
- Create, update, and enforce security policies, standards, operational procedures, runbooks, and control frameworks.
- Deliver expert guidance on cybersecurity best practices and regulatory compliance across all departments.
- Partner with engineering to strengthen and monitor AWS environments, focusing on IAM, encryption, logging, backup integrity, and access governance.
- Configure and manage firewalls, encryption protocols, and access controls across cloud platforms and corporate systems.
- Enhance security configurations across identity and productivity platforms including Okta, Entra ID, Microsoft 365, Google Workspace, Box, SharePoint, and AWS.
- Manage and refine role-based access controls, access review cycles, privileged account policies, administrative oversight, service account management, and employee lifecycle security processes.
- Lead the response to cybersecurity incidents such as suspected breaches, account takeovers, malware outbreaks, data leaks, and unauthorized access attempts.
- Direct incident investigation, containment actions, remediation efforts, documentation, root cause analysis, and follow-up improvements.
- Manage collection of security evidence, control documentation, remediation tracking, and audit readiness for SOC 2, HIPAA/HITECH, and GDPR compliance.
- Lead third-party vendor security evaluations and respond to security questionnaires.
- Support vulnerability scanning, penetration testing, phishing simulations, customer security reviews, third-party risk assessments, and employee security training programs.
- Perform additional duties as assigned by leadership.
Work Arrangement
Hybrid — NYC, Boston
Other
- Hybrid work environment with in-office collaboration two days per week
- Unlimited PTO
- 12 company holidays
- Company-wide shutdown between Christmas and New Years
- Weekly in-office lunch benefit every Tuesday
- Annual wellness and professional development stipend