Technical Cyber Security Manager (Hybrid) - Cedar Park, TX

James Avery Craftsman Inc
Cedar Park, United States of America
28 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Senior

Job location

Remote
Cedar Park, United States of America

Tech stack

Microsoft Windows
Domain Controllers
Artificial Intelligence
Amazon Web Services (AWS)
Azure
Booting (BIOS)
Spreadsheets
Cloud Computing Security
Computer Security
Continuous Integration
Data Centers
Software Debugging
Linux
Identity and Access Management
Python
Kerberos (Protocol)
Machine Learning
Public Key Infrastructure
Software Vulnerability Management
S3 Bucket
Retrieval-Augmented Generation
Large Language Models
Multi-Agent Systems
Software Security
Mitre Att&ck
Multi-Cloud
Technical Debt
Amazon Web Services (AWS)
Kubernetes
Information Technology
Cybercrime
Devsecops

Job description

We are seeking a high-caliber Technical Cyber Security Manager to serve as the primary authority for our security architecture, engineering and enforcement. This is a hands-on, technical leadership role, actively engaged in the work and not focused on spreadsheets and slide decks but thriving in the terminal. As a player-coach, leads a security team while remaining deeply technical, capable of diving into tasks such as VPC configuration, hardening on-prem domain controllers, or auditing an LLM integration for prompt injection vulnerabilities. The ideal candidate approaches security as an engineering discipline, leveraging code, automation, and deep architectural expertise to solve., * Hybrid Security Leadership: Defines and implement security architectures across a complex environment involving legacy on-prem data centers and modern multi-cloud (AWS/Azure) footprints.

  • AI Security Implementation: Establishes guardrails for the secure deployment of AI/ML models. This includes securing RAG (Retrieval-Augmented Generation) pipelines, managing API security for LLMs, and monitoring for adversarial attacks. Recognizes the evolving impact of AI on the threat landscape and proactively learns how to defend against and leverage emerging technologies.
  • Active Defense: Leads and participates in hands-on threat hunting, incident response, and vulnerability remediation. Serves as the primary escalation point for complex technical challenges and blockers.
  • DevSecOps Integration: Builds and maintains CI/CD security gates, infrastructure-as-code (IaC) scanning, and automated compliance monitoring.
  • Architectural Guidance & Correctness: Ensures architectural integrity and prevents drift by providing clear technical direction and guidance to teams.
  • Strategic Technical Debt Management: Balances long-term sustainability with near-term delivery by guiding decisions on technical debt, tooling, and security priorities.
  • Clear Communication: Translates complex technical issues such as buffer overflow or a misconfigured S3 bucket policies into clear, actionable business risks for non-technical stakeholders.
  • Leads and develops a high-performing security team, fostering a culture of continuous learning and technical excellence.
  • Responsible for the overall leadership, direction and evaluation of employees utilizing the Company's Leadership CRAFT Standard.

Requirements

  • Bachelor's Degree in Computer Science, Information Technology or relevant field; or equivalent combination of education and/or experience.
  • 8 years direct cybersecurity experience, with deep technical expertise and a demonstrated "hands-on-keyboard" approach.
  • 5 years Leadership experience.
  • Experience with the MITRE ATT&CK framework.
  • Expert-level knowledge of Cloud-Native Security (CNAPP) with ability to manually audit complex Kubernetes clusters or debug cross-account IAM role assumption issues.
  • Deep understanding of Windows/Linux boot process, memory protection, and securing legacy protocols (SMB, Kerberos).
  • Hands-on experience with PKI management.
  • Advanced proficiency in Python and Go with ability to build custom security tooling when off-the-shelf solutions do not meet requirements.
  • Ability to evaluate the security of Python-based AI orchestration frameworks like LangChain or AutoGPT.
  • Exceptional communication and interpersonal skills, with the ability to build strong relationships and influence stakeholders at all levels., * CISSP, CISM or deep technical certifications such as OSCP, AWS Certified Security or Google Professional Cloud Security Engineer.

Apply for this position