Who We Are: Aspenware empowers mountain resorts and ski areas to deliver the ideal digital guest experience. Our guest-facing e-commerce and registration software is the most capable in the industry and is used by millions of skiers worldwide to process over a billion dollars in annual sales. The resorts we work with trust the innovation and thought leadership that Aspenware provides, and they leverage the operational advantages of our platform to grow their businesses. We are a talented and high-performing team and welcome the opportunity to learn from one another. Aspenware makes hiring decisions based on how well candidates align with our Core Values. Aspenware employees are… Dependable: We take ownership. We are accountable and adaptable. We have a can-do attitude and are willing to pivot. Caring: We care about our co-workers and our clients. We are mindful of and inspired by the impact our work has on our communities. Innovative: We are thought leaders who bring creativity and a desire for innovation to everything we do. We are continually improving ourselves and our surroundings. Curious: We challenge default processes while assuming best intent, seeking to understand before judging. We ask good questions to spark learning, better decisions, and smarter outcomes. We make the extra effort to gain a deeper understanding of a situation so we can provide better solutions. The Role: The Lead Infosec Engineer will be responsible for leading Aspenware’s existing security program and optimizing it to be even more robust. You will manage Aspenware’s security operations including IT vendor and MSSP relationships. You will lead efforts to mitigate existing and emerging cybersecurity threats. You will assess, prioritize, and remediate security risks to improve Aspenware’s overall cybersecurity posture. This is a key role at Aspenware and reports to the Director of Technology Operations & Security. You will work closely with the VP of Technology, other engineering leaders, and business stakeholders to represent the security needs of our platform and hold the enterprise to a rigorous standard of security. Finally, you will collaborate with the Infosec teams at our parent company, Alterra Mountain Co. You will be responsible for sharing strategies, roadmap progress, and incident retrospectives wherever the larger enterprise is impacted. What You Will Do: Partner with engineering teams and systems architects to ensure the security of our products, cloud infrastructure, and technical platform Be the champion of rigorous security standards when debating resource allocation tradeoffs Improve Aspenware’s AppSec and SDLC security Understand key security attack vectors and protect Aspenware from malicious actors who wish to abuse our system. Manage our security vendor relationships with respect to requirements and technical support Lead the company from its recently earned Type I SOC 2 accreditation through Type 2 accreditation. Assist end users to remediate security issues. Work with external vendors to provide oversight for computers, devices, and networks in a remote work environment Manage and evaluate external vendors to conduct pen testing, endpoint testing, purple team testing, and PCI scans Develop and document network security reference architectures, design patterns, roadmaps, and other architectural artifacts aligned with policies, standards, and industry best practices Work closely with our DevOps team to manage cloud security in Azure: Evaluate Azure cloud and hybrid security services, tools, and appliances in the areas of (but not limited to): intrusion detection, intrusion prevention, packet capture, and quarantine Assess network/cloud security posture and recommend modifications for enhancements, improvements, and mitigations Collaborate with enterprise partners and incident response teams regarding requirements and deployment of security services, tools, and appliances Review access control policies and assist in Identity and Access Management through MS Entra Ensure compliance with NIST CSF or similar frameworks and meet disclosure obligations Identify opportunities to improve existing security processes, policies, and tooling Help cultivate and foster a culture of security across the entire organization by driving awareness and promoting a cohesive narrative around security Perform in-depth investigations when the suspicion of a threat emerges. Coordinate mitigation and remediation plans to address critical risks Who You Are: You are passionate about cybersecurity and have a track record in improving the security posture of software engineering organizations. You are a proud advocate of rigorous security standards. You take pride in staying on top of and ahead of information security techniques, standards, and trends. You are a lifelong learner who is constantly educating and challenging yourself to stay ahead of the cybersecurity curve. You thrive in small to mid-size companies where you can take ownership and practice a blend of strategic planning, communication, and individual contribution. You are skilled at communicating with peers, leadership, and clients. You can define and execute on a complex department roadmap and proactively update stakeholders on the status of each of your parallel initiatives. You Ideally Have: Experience owning the Infosec strategy for SaaS companies, especially in ecommerce Expert knowledge of AppSec, Infrastructure security, access control, and GRC 4+ years of experience in a cybersecurity role within a software development organization 8+ years in technical roles – as a software engineer, information security analyst or similar Masters or bachelor's degree in Information Systems with a focus in cyber security or equivalent experience / certifications Experience with NIST CSF, ISO27001, PCI, SOC2 or similar standards/certifications Experience with OWASP or similar standards. Experience with DevSecOps Direct experience with Azure cloud security Hands-on experience establishing and configuring security controls for Microsoft Azure and Microsoft 365 components Understanding of DDOS and other infrastructure threats at the edge Strong understanding of security as it relates to CDN, API management, and load balancing technologies Strong understanding of Azure monitoring capabilities Willingness to jump into a complex, fast-paced environment. What’s In It for You: 4 weeks of PTO to start and increases with seniority 11 paid holidays 6 days of sick time Paid parental leave for both primary and secondary parents Medical, dental, and vision insurance Life insurance 401k plan with a 5% match Annual all-company ski day Seasonal Ski Pass – Ikon Pass National Park Pass Annual Wellness Stipend Flexible work environment
Web Developer Intern
Evergreenir
Director of Premium Audit Learning and Development
ARMStrong Insurance Services
Java Engineer
Lean TECHniques
Senior ML/Platform Engineer
Icanbwell
Product Advocate, Developer GTM
Mastra
Salesforce Business Analyst
Aspire