Security Engineering Lead
Job description
About the role
This position leads the enterprise security strategy and execution for Hudson River Trading. The hire will define technical direction for protecting critical systems, applications, and data across the entire technology stack. They will manage a team of security engineers responsible for enabling secure and productive work environments. The role requires balancing robust security controls with the need for business productivity and user experience. The ideal candidate will act as a hands-on technical leader and security generalist in a fast-paced, high-impact environment.
Key facts
What you'll do
- Define the technical strategy for securing enterprise products and services across the organization.
- Design, review, and implement robust security hardening solutions for hosts and workloads spanning multiple data centers, colocation facilities, public cloud services, offices, and remote endpoints running various operating systems and applications.
- Build and maintain a unified vulnerability management solution that integrates disparate agents, scanners, SBOM tools, and threat intelligence feeds into a coherent posture.
- Partner with developers, engineers, and vendors across the organization to identify, prioritize, and drive initiatives in AI security, Identity and Access Management, Public Key Infrastructure, endpoint security, and serverless workload protection.
- Lead and mentor a small team of security engineers, fostering a high-performing and inclusive team environment.
- Execute complex security projects smoothly, functioning effectively both as an individual contributor and as a project lead when required.
- Advise internal teams on securing productivity applications and cloud infrastructure to reduce risk without impeding operational efficiency.
- Manage the security lifecycle for machine identities and device posture across thousands of endpoints in hybrid environments.
- Contribute to the development and implementation of containerization strategies and guardrails for generative AI agents to mitigate emerging threats.
Requirements
- Bring a minimum of 7 years of hands-on experience in security engineering roles.
- Demonstrate at least 2 years of experience leading a technical team through mentorship and project execution.
- Show proven ability to harden Linux environments at scale using configuration management and infrastructure-as-code tooling.
- Possess practical experience with Cloud Security Posture Management on GCP, Azure, and/or AWS platforms.
- Have familiarity with emerging generative AI security tooling and best practices, including guardrails, agents, sandboxing, and MCP security.
- Understand endpoint security technologies commonly deployed on macOS and Windows operating systems.
- Be knowledgeable about Public Key Infrastructure workflows, encompassing certificate templates, issuance, renewal, and revocation processes.
- Exhibit proficiency in the Python programming language as a core requirement for automation and tooling.
- Make principled decisions that carefully balance workforce productivity with the organization's security requirements.
- Maintain curiosity and agility, adapting quickly to complexity and uncertainty while implementing novel solutions.
- Collaborate effectively with partners throughout the business to achieve company-wide security impact and objectives.
- Contribute to a culture of continuous learning and improvement within the security organization.
- Apply analytical rigor to troubleshoot security issues and resolve incidents in a timely manner.
- Communicate technical concepts clearly to both technical and non-technical stakeholders across the enterprise.
Practical notes
- Work is full-time based in New York, NY, United States.
- This role is eligible for discretionary performance-based bonuses and a competitive benefits package.
- The estimated base salary range for this position is 200,000 to 300,000 USD per year (or local equivalent).
- The base pay offered may vary depending on multiple individualized factors, including location, job-related knowledge, skills, and experience.
- Candidates must be authorized to work in the United States without sponsorship for this position.
- No current sponsorship is available for this role.
About the role
This position leads the enterprise security strategy and execution for Hudson River Trading. The hire will define technical direction for protecting critical systems, applications, and data across the entire technology stack. They will manage a team of security engineers responsible for enabling secure and productive work environments. The role requires balancing robust security controls with the need for business productivity and user experience. The ideal candidate will act as a hands-on technical leader and security generalist in a fast-paced, high-impact environment.
Key facts
What you'll do
- Define the technical strategy for securing enterprise products and services across the organization.
- Design, review, and implement robust security hardening solutions for hosts and workloads spanning multiple data centers, colocation facilities, public cloud services, offices, and remote endpoints running various operating systems and applications.
- Build and maintain a unified vulnerability management solution that integrates disparate agents, scanners, SBOM tools, and threat intelligence feeds into a coherent posture.
- Partner with developers, engineers, and vendors across the organization to identify, prioritize, and drive initiatives in AI security, Identity and Access Management, Public Key Infrastructure, endpoint security, and serverless workload protection.
- Lead and mentor a small team of security engineers, fostering a high-performing and inclusive team environment.
- Execute complex security projects smoothly, functioning effectively both as an individual contributor and as a project lead when required.
- Advise internal teams on securing productivity applications and cloud infrastructure to reduce risk without impeding operational efficiency.
- Manage the security lifecycle for machine identities and device posture across thousands of endpoints in hybrid environments.
- Contribute to the development and implementation of containerization strategies and guardrails for generative AI agents to mitigate emerging threats.
Requirements
- Bring a minimum of 7 years of hands-on experience in security engineering roles.
- Demonstrate at least 2 years of experience leading a technical team through mentorship and project execution.
- Show proven ability to harden Linux environments at scale using configuration management and infrastructure-as-code tooling.
- Possess practical experience with Cloud Security Posture Management on GCP, Azure, and/or AWS platforms.
- Have familiarity with emerging generative AI security tooling and best practices, including guardrails, agents, sandboxing, and MCP security.
- Understand endpoint security technologies commonly deployed on macOS and Windows operating systems.
- Be knowledgeable about Public Key Infrastructure workflows, encompassing certificate templates, issuance, renewal, and revocation processes.
- Exhibit proficiency in the Python programming language as a core requirement for automation and tooling.
- Make principled decisions that carefully balance workforce productivity with the organization's security requirements.
- Maintain curiosity and agility, adapting quickly to complexity and uncertainty while implementing novel solutions.
- Collaborate effectively with partners throughout the business to achieve company-wide security impact and objectives.
- Contribute to a culture of continuous learning and improvement within the security organization.
- Apply analytical rigor to troubleshoot security issues and resolve incidents in a timely manner.
- Communicate technical concepts clearly to both technical and non-technical stakeholders across the enterprise.
Practical notes
- Work is full-time based in New York, NY, United States.
- This role is eligible for discretionary performance-based bonuses and a competitive benefits package.
- The estimated base salary range for this position is 200,000 to 300,000 USD per year (or local equivalent).
- The base pay offered may vary depending on multiple individualized factors, including location, job-related knowledge, skills, and experience.
- Candidates must be authorized to work in the United States without sponsorship for this position.
- No current sponsorship is available for this role.