Lead Cyber Security & Compliance Engineer (Remote)

OPTION ONE TECHNOLOGIES LLC
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$90,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Amazon Web Services Software System Penetration Testing Microsoft Azure Microsoft Online Services Cloud Computing Security Cyber Security Multi-Factor Authentication Identity and Access Management Python (Programming Language) Network Security Performance Tuning
+14 more
Windows PowerShell Azure Active Directory Phishing Zero Trust Network Access Web Application Security Security Information and Event Management Software Vulnerability Management Scripting Microsoft Fabric Bug Reporting Cybercrime SentinelOne Expertise Cisco Vulnerability Analysis

Job description

We are seeking a senior Cyber Security Engineer to own and advance the security posture of a regulated financial services environment. This is a hands-on role that blends day-to-day operational defense with compliance, user enablement, and offensive testing. You will be the connective tissue between our security tooling, our compliance obligations, and the people who rely on you to keep them safe., * Security operations & monitoring - Operate and tune our SOC/SIEM stack, investigate alerts, triage incidents, and drive detection and response improvements. Reduce noise, increase signal, and document what you find.

  • Endpoint & network defense - Administer and optimize SentinelOne (EDR), Cisco Umbrella and Zscaler (ZTNA / secure web gateway), including policy tuning, exclusions, threat hunting, and incident containment.
  • Vulnerability management - Run and interpret recurring vulnerability scans, prioritize findings by real-world risk, coordinate remediation with IT and engineering, and track issues to closure.
  • Microsoft 365 administration & security: Administer M365/Entra ID tenants across client firms, including identity and access management, Conditional Access, MFA enforcement, Purview retention and eDiscovery, and secure configuration baselines. Own tenant hardening and remediate Secure Score gaps.
  • Penetration testing - Plan and perform internal and external penetration tests, document findings with clear severity and reproduction steps, and partner with stakeholders on remediation. Coordinate scope and results from third-party pen tests where applicable.
  • Compliance & governance - Maintain and evidence controls for SOC 2 and NIST frameworks, and support compliance obligations specific to Registered Investment Advisors, Securities and Exchange Commission (e.g., RIAs/regulatory safeguarding and recordkeeping expectations). Prepare for and support audits. Create and assist customers with writing and maintaining ISP, BCPDR and other relevant policies,
  • Security awareness & training - Own the KnowBe4 program: build phishing simulations, manage training campaigns, analyze results, and follow up with users. Work with employees daily to coach them on secure behavior in plain, approachable language.
  • User-facing support - Serve as a trusted, patient point of contact for security questions across the business. Translate technical risk into terms any user can act on.
  • Documentation & continuous improvement - Keep runbooks, policies, and procedures current. Recommend and implement improvements to tooling, process, and posture.

Requirements

The ideal candidate is equally comfortable triaging a SIEM alert, walking a non-technical user through a phishing simulation result, scoping a penetration test, rolling out a new system to an entire firm, and mapping a control to a NIST subcategory. Strong communication and client relationship is not a “nice to have” here - it is central to the job., * 4+ years in security engineering, security operations, or a closely related role (mid-to-senior range; depth matters more than exact years).

  • Hands-on SOC / SIEM experience - alert triage, investigation, tuning, and detection logic.
  • Working knowledge of and demonstrable experience with SentinelOne, Zscaler, Cisco Umbrella and KnowBe4 (or directly comparable EDR, ZTNA/SWG, and security-awareness platforms).
  • Hands-on Microsoft 365 administration experience, including Entra ID (Azure AD), Conditional Access, Exchange Online, and Microsoft Purview. Comfortable owning tenant-level configuration in a multi-client environment.
  • Practical penetration testing ability and experience running/interpreting vulnerability scans and driving remediation.
  • Solid understanding of SOC 2 and NIST (e.g., 800-53 / CSF) controls, evidence, and audit support.
  • Familiarity with compliance considerations for Registered Investment Advisors or another regulated financial environment.
  • Excellent written and verbal communication - you can teach, de-escalate, and explain risk to non-technical audiences, and you genuinely enjoy working with users every day.

Preferred / Nice to Have

  • Relevant certifications such as OSCP, CISSP, GPEN, GCIH, Security+, or equivalent.
  • Experience with cloud security (AWS / Azure / GCP) and SaaS security posture.
  • Scripting / automation (Python, PowerShell, or similar) for tooling and detection.
  • Prior experience in financial services, fintech, or another highly regulated industry.
  • Microsoft certifications such as MS-102 (M365 Administrator), SC-200 (Security Operations Analyst), or SC-300 (Identity and Access Administrator)., * Writing Security Policies: 1 year (Required)
  • Security User Training: 1 year (Preferred)
  • DUO: 1 year (Preferred)
  • KnowBe4: 1 year (Preferred)

Benefits & conditions

From $90,000 a year - Full-time, Pulled from the full job description

  • Professional development assistance
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Flexible schedule, Why Join Option One Technologies
  • High-impact, multi-disciplinary role - work at the intersection of cybersecurity, compliance, and financial services with some of the most sophisticated firms in the industry
  • Accelerated professional growth - direct exposure to SEC/FINRA regulatory environments, advanced security tooling, and complex network architectures across a diverse client portfolio
  • Entrepreneurial culture - small, senior team where your work directly shapes client outcomes and company direction
  • Professional development budget to earn industry certifications and attend training
  • Comprehensive benefits: health, dental, and vision insurance; flexible schedule; paid time off; hybrid work arrangement
  • Competitive compensation commensurate with experience

Pay: From $90,000.00 per year

Benefits:

  • Dental insurance
  • Flexible schedule
  • Health insurance
  • Paid time off
  • Professional development assistance
  • Vision insurance

About the company

Option One Technologies is a next-generation managed IT and cloud platform revolutionizing how financial services firms and institutions access best-in-class technology. Founded in 2019 by alumni from the Boston-based hedge fund Highfields Capital Management, we deliver white-glove managed services purpose-built for SEC-registered investment advisers, FINRA broker-dealers, hedge funds, and high-net-worth family offices. Our mission is to make enterprise-grade security, compliance, and infrastructure accessible to firms of every size - from established institutions to emerging managers.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all