What are the responsibilities and job description for the Security Engineering Lead/ Manager position at Lorvenk Technologies?
Role: Security Engineering Lead/ Manager
Location: Boston, MA – 3 days/week onsite
Experience: 13
Interview: F2F interview is required
Visa: US Citizen / Green Card only
Security Engineering Manager will lead and execute cybersecurity engineering across our existing on-premises infrastructure, new AWS cloud environment, Snowflake data platform, and emerging AI application ecosystem.
This is not a pure oversight or policy role. The primary need is a senior technical security practitioner who can hands-on design, build, harden, implement, troubleshoot, and continuously improve security controls. The role will manage and mentor a small team of talented security engineers, but the individual must remain deeply hands-on and comfortable acting as the senior technical architect executor for cybersecurity engineering.
The ideal candidate has strong financial services experience, has previously helped secure a new AWS environment from the ground up, understands traditional infrastructure and data center security, and can help the Bank safely adopt cloud, data, and AI technologies.
Required Qualifications
- 8 years of hands-on cybersecurity experience, with significant experience in security engineering, cloud security, infrastructure security, or security architecture.
- Prior experience in financial services, banking, fintech, payments, lending, insurance, or another regulated financial environment is required.
- Proven experience securing and operationalizing an AWS environment, ideally from early-stage setup or greenfield implementation.
- Strong hands-on knowledge of AWS security services, IAM, networking, encryption, logging, monitoring, and cloud governance.
- Strong understanding of on-premises infrastructure security, including Windows/Active Directory, network security, endpoint security, vulnerability management, privileged access, and SIEM/logging.
- Practical experience designing and implementing security controls, not just reviewing policies or writing standards.
- AI security experience, especially securing LLM-based applications, RAG systems, AI agents, internal AI tools, or AI-enabled workflows
- Demonstrated ability to lead, mentor, and manage a small technical security team.
Strongly Preferred Qualifications
- Snowflake security experience, including RBAC, masking policies, row access policies, network policies, SSO, logging, and data governance.
- Experience with secure software development, DevSecOps, CI/CD security, SAST/DAST/SCA, secrets scanning, container security, and infrastructure-as-code security.
- Experience with AWS Control Tower, Organizations, SCPs, GuardDuty, Security Hub, Config, IAM Identity Center, KMS, Macie, Inspector, CloudTrail, and CloudWatch.
- Experience with Microsoft security ecosystem, including Entra ID, Defender, Purview, Intune, Sentinel, or related tools.
- Security certifications such as CISSP, CCSP, AWS Certified Security – Specialty, CISM, GIAC, or equivalent practical experience.
Desired Technical Skills
- AWS security architecture and operations
- IAM, least privilege, privileged access management
- Network security, firewalls, segmentation, VPN, zero trust concepts
- Active Directory and Microsoft security controls
- Endpoint detection and response
- Vulnerability management and patch governance
- SIEM, logging, alerting, and incident response
- CloudTrail, GuardDuty, Security Hub, Config, KMS, Macie, Inspector, Crowd Strike
- Snowflake access control and data protection
- AI/LLM application security
- Secure SDLC and DevSecOps
- Vendor security reviews
- Audit evidence and remediation management
- Security automation and scripting