Cybersecurity Lead
3Core SystemsJob Description
Role: Cybersecurity Lead
Location: Hybrid
Role (Boston, MA, West Palm Beach, FL) / Remote with Travel
Duration: 6 Month Contract To Hire.
Position Summary
The Cybersecurity Lead is responsible for developing the
organization's cybersecurity strategy, ensuring the confidentiality, integrity,
and availability of company and customer information. This role provides
technical leadership across product security, enterprise security, cloud
security, and compliance while partnering with engineering, IT, product management,
and operations to embed security throughout the organization. The Cybersecurity
Lead will play a critical role in protecting the company's physical security
and identity management solutions from emerging cyber threats.
Key Responsibilities
· Develop Client’s
cybersecurity strategy aligned with business objectives and industry best
practices.
· Lead role in
protecting the company and customers emerging cyber threats and to position the
company at the forefront of security and compliance within the physical
security industry
· Establish and maintain
secure software development lifecycle (SSDLC) practices
· Ensure the
architectures for cloud, on-premises, and hybrid product deployments include
all necessary security design requirements
· Collaborate with product
management PAM and Zero Trust Security initiatives
· Support customer
security assessments, security questionnaires, audits and RFP responses.
· Establish security
metrics, KPIs and executive reporting to communicate cyber risk and program
effectiveness
· Build relationships
with external security researchers, auditors and strategic technology partners
Qualifications
Required
· Bachelor's degree in
Cybersecurity, Computer Science, Engineering, Information Systems, or related
field.
· 8+ years of
cybersecurity experience with increasing technical and leadership
responsibilities.
· Experience securing
enterprise and cloud environments (AWS, Azure, or Google Cloud).
· Strong knowledge of
network security, application security, identity management, encryption, PKI,
and secure authentication technologies.
· Experience
implementing security controls aligned with NIST CSF, CIS Controls, or ISO
27001.
· Experience with
vulnerability management, penetration testing, SIEM, EDR, and security
monitoring tools.
· Knowledge of DevSecOps
practices, CI/CD security, and infrastructure-as-code security.
· Strong understanding
of security incident response and digital forensics.
· Excellent
communication skills with the ability to explain technical risks to executive
leadership and customers.
Preferred
· Master's degree in
Cybersecurity, Computer Science, or Engineering.
· Professional
certifications such as CISSP, CISM, CCSP, GIAC, Security+, or Azure/AWS
Security certifications.
· Knowledge of embedded
systems security, firmware security, and secure device lifecycle management.
· Experience working
within regulated industries or government environments.
Technical Skills
· Zero Trust
Architecture
· Cloud Security
· Secure Software
Development Lifecycle (SSDLC)
· Security Information and
Event Management (SIEM)
· Endpoint Detection
& Response (EDR)
· Vulnerability
Management
· Threat Modeling
· Penetration Testing
· Security Risk
Assessments
· Incident Response
· PKI, TLS, Encryption,
and Key Management
· Microsoft Defender,
Microsoft Sentinel, CrowdStrike, Splunk, or similar platforms
Success Measures
· Reduced organizational
cyber risk through proactive security initiatives
· Timely remediation of
critical vulnerabilities measured against defined SLAs.
· Compliance process,
with customer and regulatory security requirements built into product releases
rather than retrofitted.
· Improved security
awareness and adoption of security best practices throughout the organization.
· Successful attainment
and maintenance of relevant certifications (ISO 27001, SOC 2, and others as
required by customers and markets).
· Reduced turnaround
time on customer security questionnaires, audits, and RFP responses.
· Effective,
well-coordinated response to security incidents across both product and
enterprise IT environments, with minimal business impact.
· Improved security
awareness and adoption of secure-by-design practices across engineering, IT,
and the wider organization.