Lead Cybersecurity Engineer

Ollie's Bargain Outlet, Inc.
Harrisburg, PA, United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cloud Computing Security Cyber Security Data Infrastructure Digital Assets Identity and Access Management Intrusion Detection and Prevention Intrusion Detection Systems Python (Programming Language) Network Security PCI Data Security Standards Windows PowerShell Systems Development Life Cycle
+13 more
Cloud Services Zero Trust Network Access Web Application Security Security Information and Event Management Software Engineering Software Vulnerability Management Scripting Cloud Platform System In-Plane Switching (IPS) Firewalls (Computer Science) Information Technology CIS Benchmarks Network Server

Job description

The Lead, Cybersecurity Engineer is responsible for leading the design, implementation, and continuous improvement of enterprise cybersecurity capabilities that protect the organization’s systems, networks, applications, cloud environments, and data assets. This role provides both strategic leadership and technical oversight across cybersecurity engineering, threat detection, vulnerability management, security architecture, identity security, and incident response capabilities.

The Lead serves as a trusted advisor to technology and business leaders, develops and executes security strategies aligned with organizational objectives, and leads a team of cybersecurity engineers and analysts responsible for maintaining a resilient and scalable security program. This position balances security risk management with business enablement and drives continuous improvement of the organization’s overall security posture., Leadership & Strategy

  • Lead, mentor, and develop a high-performing cybersecurity engineering team through coaching, performance management, career development, and technical leadership.
  • Execute cybersecurity engineering strategies, roadmaps, and priorities aligned with business objectives and enterprise risk tolerance.
  • Partner with executive leadership, infrastructure, application development, operations, compliance, and business teams to embed security into technology initiatives and operational processes.
  • Drive a culture of accountability, continuous improvement, operational excellence, and secure-by-design principles across the organization.
  • Manage security engineering projects, budgets, vendor relationships, and resource planning to ensure successful delivery of strategic initiatives.

Cybersecurity Engineering & Architecture

  • Oversee the design, implementation, and optimization of enterprise security controls across endpoints, networks, servers, cloud platforms, applications, and data environments.
  • Establish security architecture standards, engineering patterns, and technical governance processes that support scalability, resilience, and compliance requirements.
  • Lead architecture reviews and provide security guidance for new technologies, cloud services, digital transformation initiatives, and business projects.
  • Ensure security requirements are integrated throughout the system development lifecycle and infrastructure deployment processes.

Security Operations & Threat Management

  • Provide leadership for security monitoring, threat detection, incident response, and security investigations.
  • Manage the organization’s vulnerability management program, including risk prioritization, remediation governance, metrics, and executive reporting.
  • Oversee the administration and effectiveness of security technologies including SIEM, EDR, IDS/IPS, firewalls, email security, web security, identity security, and data protection solutions.
  • Coordinate response efforts for significant cybersecurity incidents and ensure effective root cause analysis and corrective action implementation.

Identity, Access & Data Protection

  • Lead the maturation of identity and access management capabilities, including privileged access management, authentication controls, least privilege, and access governance.
  • Oversee the implementation of security controls supporting data protection, encryption, secure configuration management, and zero trust initiatives.
  • Ensure appropriate technical safeguards are implemented to protect sensitive business and customer information.

Risk, Compliance & Governance

  • Partner with compliance, audit, and risk management teams to support regulatory, contractual, and industry security requirements.
  • Translate cybersecurity frameworks and standards into practical technical controls and operational processes.
  • Support audits, assessments, and regulatory reviews by providing technical leadership, documentation, and evidence of control effectiveness.
  • Develop metrics, dashboards, and executive reporting that communicate cybersecurity risk, program maturity, and operational effectiveness.

Innovation & Continuous Improvement

  • Evaluate emerging threats, technologies, and industry trends to identify opportunities for enhancing security capabilities.
  • Drive automation initiatives that improve operational efficiency, reduce risk, and strengthen security outcomes.
  • Champion continuous improvement initiatives that enhance cybersecurity resilience, operational effectiveness, and business alignment.
  • Complete any additional responsibilities and/or duties as assigned

Requirements

  • BE A TEAM PLAYER- Associates are expected to be supportive and work together.
  • BE CARING- How do I treat others with courtesy, dignity, and respect?
  • BE VALUE OBSESSED- Live the ā€œgood stuff cheapā€ mindset.
  • BE COMMITTED- Operate with grit, passion, tenacity, and action.
  • BE GROWING- How do we get better every day?
  • BE REAL- Associates should be honest, transparent, genuine, trustworthy, and sincere., * Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field, or equivalent professional experience.
  • 5+ years of progressive experience in cybersecurity, information security, security engineering, infrastructure engineering, or related technology disciplines.
  • Demonstrated experience designing and implementing enterprise security controls across cloud, on-premises, and hybrid environments.
  • Strong expertise in security operations, incident response, vulnerability management, security architecture, and enterprise security technologies.
  • Experience operating in lead role of cross-functional initiatives and influencing stakeholders across technical and business organizations.
  • Working knowledge of cybersecurity frameworks and standards including NIST CSF, CIS Controls, PCI DSS, ISO 27001, or similar frameworks.
  • Strong understanding of cloud security, identity security, network security, endpoint protection, and modern enterprise architectures.
  • Industry certifications such as CISSP, CISM, CCSP, GIAC, or equivalent.
  • Knowledge of Zero Trust architectures, cloud-native security, automation, infrastructure-as-code, and security orchestration technologies.
  • Experience supporting highly regulated environments and enterprise audit programs.
  • Proficiency in scripting or automation using Python, PowerShell, or similar technologies.

Physical Requirements:

  • Ability to sit at a desk to work on a computer for an extended period of time.
  • Ability to see, hear, and speak regularly.
  • Ability to grip, reach, and pinch with arms and hands frequently.
  • Ability to bend and twist occasionally.
  • Ability to work in a constant state of alertness and safe manner.

Benefits & conditions

Pulled from the full job description

  • Health insurance
  • 401(k) matching
  • Vision insurance
  • Dental insurance, Competitive Benefits
  • Medical, Dental, Vision, and RX coverage after 30 days of employment.
  • 401K, Company match begins at Associate enrollment
  • Strong career growth & talent development culture
  • 20% Associate discount on all Ollie’s purchases.
  • Vast array of voluntary benefits

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula Ā· LIVE

3:50 min

Queues in TCP stacks and continuous network connections

Clemens Vasters Clemens Vasters Ā· World Congress 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders Ā· LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn Ā· World Congress 2023

1:27 min

Binding executable logic into network servers

Saoussen Chaabnia Saoussen Chaabnia Ā· Europe 2026 Virtual

Videos

See all

Related articles

See all