Sr. Security Lead
Listed on 2026-01-14
-
IT/Tech
Cybersecurity, Cloud Computing, Security Manager, Systems Engineer
If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.
Sr. Security LeadFull-time Regular Cary, NC, US
4 days ago Requisition
Position OverviewThe Senior Security Lead is a hands‑on security leader accountable for aligning the enterprise security vision with the CIO’s strategic technology roadmap. This role is responsible for defining, executing, and continuously maturing the organization’s security strategy, architecture, and day‑to‑day operations.
The Senior Security Lead partners closely with the CIO to design and implement secure, scalable cloud architectures – primarily within AWS – while ensuring strong identity, data, and application protections across Microsoft 365, AWS and SaaS platforms. This leader balances strategic oversight with pragmatic execution, enabling secure digital transformation through control‑based, risk‑informed security practices. Some responsibilities may include:
Cloud Security Architecture & Modernization | Secure AWS design, cloud governance, and modernization- Design and implement secure AWS architectures, including multi-account strategies and governance guardrails (e.g., AWS Control Tower) and scalable security patterns aligned to business requirements.
- Define secure standards for cloud modernization, application migrations, and cloud-native development.
- Lead design reviews, threat modeling, and secure SDLC practices for cloud environments.
- Drive cloud security posture management (CSPM) and continuous control monitoring.
- Own enterprise security policies, standards, and control frameworks aligned to AWS Foundational Security Best Practices, CIS AWS Foundations, NIST 800‑53, NIST
800‑171, and related frameworks. - Maintain control mappings, assessments, policy exceptions, and evidence collection.
- Manage third-party risk, audit engagement, and remediation of findings to closure.
- Communicate security risk and control posture in clear, business‑relevant terms.
- Architect and implement Zero Trust‑aligned identity and access management across AWS, Microsoft 365, and SaaS environments.
- Govern enterprise-wide MFA for all user and privileged identities.
- Maintain and harden Microsoft 365 and Entra security baselines, including Conditional Access and modern authentication patterns.
- Lead IdAM integrations using Entra, Okta, and Amazon Cognito.
- Enforce least privilege, role-based access controls, and continuous access validity.
- Oversee day‑to‑day enterprise security operations, including EDR/MDR partnerships, detection engineering, and incident response.
- Maintain incident response playbooks, coordinate tabletop exercises, and drive post‑incident reviews and continuous improvement.
- Manage security for enterprise data platforms, including SaaS and AWS‑native integrations with Snowflake.
- Ensure strong data protection, access controls, and monitoring across analytics and data warehouse environments.
- Partner with technology, product, and business leaders to enable secure innovation.
- Provide dashboards, briefings, and executive‑level reporting to senior leadership and the board.
Education and Experience
- 10+ years of experience in Information Security, with 5+ years leading security or cloud security teams.
- Proven, hands‑on experience designing and implementing AWS security patterns.
- Demonstrated experience maintaining and securing a Microsoft 365 enterprise environment.
- Experience managing AWS teams and delivering infrastructure aligned to strategic business goals.
- Strong background aligning security design patterns with AWS and NIST‑based frameworks.
- Enterprise ownership of MFA programs…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).