> Markdown version of [/jobs/ext/3056977-information-security-lead](https://www.wearedevelopers.com/jobs/ext/3056977-information-security-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Lead - **Company:** Addison Group - **Location:** Los Angeles, CA, United States - **Experience:** Expert - **Salary:** $125,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Identity and Access Management, Network Security, Phishing, Zero Trust Network Access, Software Vulnerability Management, IT General Controls (ITGC), Firewalls (Computer Science), Palo Alto Networks - **Published:** September 24, 2026 - **Apply:** https://www.thejobnetwork.com/job/cc8a396e-7b6a-45d6-a085-f14fa7fc382e/senior-information-security-lead ## About the Role * 5+ years of progressive experience in information security, cybersecurity, network security, or infrastructure security. * Experience administering and supporting Palo Alto Networks Firewalls. * Experience working with Netskope Secure Service Edge (SSE) / Zero Trust solutions. * Working knowledge of cloud security concepts within Microsoft Azure and Amazon Web Services (AWS). * Experience with vulnerability management programs and security risk assessments. * Hands-on experience supporting security audits, compliance reviews, and control testing. * Understanding of IT General Controls (ITGCs) and security governance practices. * Strong knowledge of security frameworks, best practices, and risk management principles. * Excellent documentation, analytical, and problem-solving skills. * Strong communication skills with the ability to interact effectively with technical teams, auditors, and executive leadership., * Experience supporting SOX compliance and audit readiness programs. * Industry certifications such as CISSP, CISM, CCSP, Security+, Palo Alto, Azure Security, or AWS Security certifications. * Experience with hybrid infrastructure environments spanning cloud and on-premises systems. * Familiarity with security operations, threat management, and incident response practices. * Knowledge of identity and access management (IAM) and Zero Trust security architecture. * Experience managing security-related risk exceptions and remediation programs., The ideal candidate is a senior cybersecurity professional who enjoys remaining highly technical while also serving as a trusted advisor for security governance, risk, and compliance activities. This individual is comfortable working independently, partnering with auditors and executives, driving remediation efforts, and maintaining a secure, audit-ready environment without direct people management responsibilities. ## Description Our client is seeking a Senior Information Security Lead to serve as the primary owner of enterprise security controls, security governance, and audit readiness initiatives across a hybrid technology environment. This is a hands-on individual contributor role responsible for designing, implementing, monitoring, and continuously improving network and information security controls across cloud and on-premises platforms. The ideal candidate will combine strong technical cybersecurity expertise with the ability to support compliance, risk management, internal audits, and executive-level reporting. This position plays a critical role in maintaining security posture, driving remediation efforts, managing security exceptions, and ensuring ongoing readiness for regulatory and audit requirements. This role is approximately 70% technical and 30% governance, compliance, and stakeholder engagement., * Design, implement, and maintain enterprise security controls across hybrid environments. * Serve as the primary security control owner for network, cloud, and information security initiatives. * Manage and optimize security technologies including firewalls, secure access platforms, vulnerability management tools, and cloud security controls. * Lead vulnerability management efforts, including identification, prioritization, remediation tracking, and reporting. * Conduct and coordinate phishing simulations, security awareness initiatives, and risk reduction activities. * Partner with internal and external auditors to support audit requests, evidence collection, and compliance reviews. * Maintain security documentation, policies, standards, procedures, and control evidence. * Support SOX compliance efforts and IT General Controls (ITGC) audit readiness. * Manage security findings, control deficiencies, remediation plans, and risk exceptions. * Collaborate with infrastructure, cloud, networking, and application teams to strengthen security posture. * Provide security-related guidance and recommendations to technical teams and business stakeholders. * Communicate risks, remediation status, and security initiatives to leadership and executive stakeholders. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developer Tools for Microsoft Azure](https://www.wearedevelopers.com/videos/450-developer-tools-for-microsoft-azure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)