> Markdown version of [/jobs/ext/2547636-lead-cyber-security-compliance-engineer-remote](https://www.wearedevelopers.com/jobs/ext/2547636-lead-cyber-security-compliance-engineer-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Cyber Security & Compliance Engineer (Remote) - **Company:** OPTION ONE TECHNOLOGIES LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $90,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Microsoft Online Services, Cloud Computing Security, Cyber Security, Multi-Factor Authentication, Identity and Access Management, Python (Programming Language), Network Security, Performance Tuning, Windows PowerShell, Azure Active Directory, Phishing, Zero Trust Network Access, Web Application Security, Security Information and Event Management, Software Vulnerability Management, Scripting, Microsoft Fabric, Bug Reporting, Cybercrime, SentinelOne Expertise, Cisco, Vulnerability Analysis - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=0796a6c9c2700476 ## About the Role The ideal candidate is equally comfortable triaging a SIEM alert, walking a non-technical user through a phishing simulation result, scoping a penetration test, rolling out a new system to an entire firm, and mapping a control to a NIST subcategory. Strong communication and client relationship is not a "nice to have" here - it is central to the job., * 4+ years in security engineering, security operations, or a closely related role (mid-to-senior range; depth matters more than exact years). * Hands-on SOC / SIEM experience - alert triage, investigation, tuning, and detection logic. * Working knowledge of and demonstrable experience with SentinelOne, Zscaler, Cisco Umbrella and KnowBe4 (or directly comparable EDR, ZTNA/SWG, and security-awareness platforms). * Hands-on Microsoft 365 administration experience, including Entra ID (Azure AD), Conditional Access, Exchange Online, and Microsoft Purview. Comfortable owning tenant-level configuration in a multi-client environment. * Practical penetration testing ability and experience running/interpreting vulnerability scans and driving remediation. * Solid understanding of SOC 2 and NIST (e.g., 800-53 / CSF) controls, evidence, and audit support. * Familiarity with compliance considerations for Registered Investment Advisors or another regulated financial environment. * Excellent written and verbal communication - you can teach, de-escalate, and explain risk to non-technical audiences, and you genuinely enjoy working with users every day. Preferred / Nice to Have * Relevant certifications such as OSCP, CISSP, GPEN, GCIH, Security+, or equivalent. * Experience with cloud security (AWS / Azure / GCP) and SaaS security posture. * Scripting / automation (Python, PowerShell, or similar) for tooling and detection. * Prior experience in financial services, fintech, or another highly regulated industry. * Microsoft certifications such as MS-102 (M365 Administrator), SC-200 (Security Operations Analyst), or SC-300 (Identity and Access Administrator)., * Writing Security Policies: 1 year (Required) * Security User Training: 1 year (Preferred) * DUO: 1 year (Preferred) * KnowBe4: 1 year (Preferred) ## Description We are seeking a senior Cyber Security Engineer to own and advance the security posture of a regulated financial services environment. This is a hands-on role that blends day-to-day operational defense with compliance, user enablement, and offensive testing. You will be the connective tissue between our security tooling, our compliance obligations, and the people who rely on you to keep them safe., * Security operations & monitoring - Operate and tune our SOC/SIEM stack, investigate alerts, triage incidents, and drive detection and response improvements. Reduce noise, increase signal, and document what you find. * Endpoint & network defense - Administer and optimize SentinelOne (EDR), Cisco Umbrella and Zscaler (ZTNA / secure web gateway), including policy tuning, exclusions, threat hunting, and incident containment. * Vulnerability management - Run and interpret recurring vulnerability scans, prioritize findings by real-world risk, coordinate remediation with IT and engineering, and track issues to closure. * Microsoft 365 administration & security: Administer M365/Entra ID tenants across client firms, including identity and access management, Conditional Access, MFA enforcement, Purview retention and eDiscovery, and secure configuration baselines. Own tenant hardening and remediate Secure Score gaps. * Penetration testing - Plan and perform internal and external penetration tests, document findings with clear severity and reproduction steps, and partner with stakeholders on remediation. Coordinate scope and results from third-party pen tests where applicable. * Compliance & governance - Maintain and evidence controls for SOC 2 and NIST frameworks, and support compliance obligations specific to Registered Investment Advisors, Securities and Exchange Commission (e.g., RIAs/regulatory safeguarding and recordkeeping expectations). Prepare for and support audits. Create and assist customers with writing and maintaining ISP, BCPDR and other relevant policies, * Security awareness & training - Own the KnowBe4 program: build phishing simulations, manage training campaigns, analyze results, and follow up with users. Work with employees daily to coach them on secure behavior in plain, approachable language. * User-facing support - Serve as a trusted, patient point of contact for security questions across the business. Translate technical risk into terms any user can act on. * Documentation & continuous improvement - Keep runbooks, policies, and procedures current. Recommend and implement improvements to tooling, process, and posture. ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Job Boards for Remote Work for Developers](https://www.wearedevelopers.com/magazine/290-best-job-boards-for-remote-work-for-developers)