What are the responsibilities and job description for the Lead Cybersecurity & compliance Engineer position at New York Technology Partners?
Title: Lead Cybersecurity & compliance Engineer
Location: San Francisco, California (Onsite)
Position: Contract
Note: Looking for Independent Visa Candidate who can work on W2
Position Summary:
• We are seeking an experienced Lead Cybersecurity & Compliance Engineer to bridge the gap between advanced cloud engineering, cybersecurity operations, and enterprise risk management.
• This role will be responsible for designing and implementing security controls across cloud and hybrid environments while ensuring compliance with industry regulations, corporate governance standards, and security frameworks.
• The ideal candidate will possess deep expertise in cloud security, cybersecurity architecture, regulatory compliance, risk assessment, and security automation.
• They will partner closely with engineering, infrastructure, DevOps, legal, audit, and business stakeholders to drive security-by-design principles and establish a strong compliance posture across the organization.
Key Responsibilities:
Cybersecurity Leadership
• Lead the design, implementation, and continuous improvement of enterprise cybersecurity programs.
• Develop and maintain security architectures for cloud, hybrid, and on-premises environments.
• Establish and enforce security policies, standards, and best practices across the organization.
• Provide technical leadership on cybersecurity initiatives, security assessments, and remediation activities.
• Drive secure-by-design and zero-trust architecture principles across technology platforms.
Cloud Security & Engineering:
• Architect and implement security controls across cloud platforms such as Microsoft Azure, AWS, and Google Cloud Platform (GCP).
• Design and manage cloud-native security solutions including IAM, network security, encryption, key management, and workload protection.
• Collaborate with DevOps and platform engineering teams to integrate security into CI/CD pipelines.
• Implement Infrastructure-as-Code (IaC) security practices and automated compliance validation.
• Lead vulnerability management and cloud posture management initiatives.
Compliance & Governance
• Own and manage compliance programs
• Conduct compliance assessments, audits, and control reviews.
• Develop remediation plans to address audit findings and security gaps.
• Maintain security governance documentation, policies, procedures, and evidence repositories.
• Partner with internal and external auditors during compliance reviews and certification audits.
Risk Management
• Perform enterprise risk assessments and security control effectiveness evaluations.
• Identify, assess, prioritize, and mitigate cybersecurity risks.
• Develop risk reporting dashboards and executive-level communications.
• Facilitate third-party and vendor security assessments.
• Support business continuity, disaster recovery, and resilience initiatives.
Stakeholder Management
• Act as the primary liaison between engineering teams, security leadership, compliance teams, and enterprise risk management organizations.
• Present security risks, compliance status, and remediation strategies to senior leadership.
• Mentor junior engineers and promote a culture of security awareness across the organization.
Required Qualifications
• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related field.
• 10 years of experience in cybersecurity, cloud security, governance, risk, and compliance (GRC), or security engineering.