> Markdown version of [/jobs/ext/803455-engineer-cyber-security](https://www.wearedevelopers.com/jobs/ext/803455-engineer-cyber-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Engineer, Cyber Security - **Company:** Holley Performance Products, Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Network Security, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Tisax, Data Logging, Cloud Platform System, Software Security, Vulnerability Analysis - **Published:** June 2, 2026 - **Apply:** https://www.dice.com/job-detail/3e6660bd-9d3f-48ee-ba1f-a314995dd13d ## About the Role * 8-12+ years of experience in cybersecurity, with strong hands-on engineering expertise. * Experience working with managed security service providers (MSSPs) or external security vendors. * Deep experience across multiple security domains (network, endpoint, cloud, identity, application security). * Experience with modern security tools (SIEM, EDR, IAM, vulnerability management platforms). * Strong understanding of cloud security (AWS preferred; Azure acceptable). * Experience supporting compliance frameworks such as TISAX, SOX, ISO 27001, or NIST. * Proven ability to translate risk into actionable technical controls. * Strong analytical and incident response capabilities. ## Description The Senior Cybersecurity Engineer is responsible for defining, implementing, and continuously improving the security posture of Holley's technology environment. This role ensures that security is embedded into how we design, build, and operate systems across infrastructure, applications, and cloud platforms. This individual acts as both a technical expert and a strategic partner, working across IT, business teams, and external partners to proactively identify risk, implement effective controls, and enable secure growth. A key focus of this role is supporting regulatory and compliance initiatives, while ensuring security practices are practical, scalable, and aligned to business objectives. The primary objective: reduce risk, improve resilience, and ensure security is an enabler-not a blocker-to the business., * Design and implement security solutions across network, infrastructure, endpoints, identity, and cloud environments. * Define and enforce security standards, patterns, and best practices across IT. * Embed security into system design, application development, and integration efforts ("secure by design"). * Partner with all IT Teams to ensure new solutions meet security requirements from the outset. * Evaluate emerging technologies and recommend improvements to strengthen overall security posture. Threat Detection, Response & Resilience * Lead advanced threat detection and response efforts across the environment. * Own and continuously improve incident response processes, including playbooks, escalation paths, and post-incident reviews. * Conduct root cause analysis and ensure corrective actions are implemented and sustained. * Simulate and test response readiness (e.g., tabletop exercises, incident scenarios). * Drive improvements in detection coverage, response time, and overall resilience. Vulnerability & Risk Management * Establish and maintain a risk-based vulnerability management program. * Prioritize vulnerabilities based on business impact and threat exposure-not just severity scores. * Partner with IT teams to drive timely remediation and reduce risk exposure. * Track and report on risk posture, remediation progress, and outstanding gaps. * Proactively identify systemic risks and drive long-term fixes. Identity, Access & Data Protection * Partner with the IAM Engineer to strengthen identity and access management practices across the organization. * Support implementation of least privilege access, role-based access controls, and privileged access management. * Assist in the rollout and governance of identity platforms. * Ensure identity-related controls are integrated into broader security architecture and operations. * Help drive adoption of IAM best practices across IT and business teams. Security Operations & Tool Optimization * Own and optimize core security tooling (SIEM, EDR, vulnerability scanners, email security, network security tools). * Ensure effective logging, monitoring, and alerting across all environments. * Drive automation and integration across tools to improve efficiency and response times. * Continuously assess tool effectiveness-reduce noise and improve signal. Managed Services & Vendor Partnership * Partner closely with the managed security services provider (MSSP) to ensure effective monitoring, detection, and response. * Establish clear accountability, service expectations, and performance metrics with the vendor. * Continuously evaluate vendor performance and drive improvements where needed. * Ensure seamless coordination between internal IT teams and external partners-no gaps, no duplication, no finger-pointing. * Act as the internal owner of the relationship, ensuring services align with Holley's security priorities and risk posture. Compliance, Governance & Audit Support * Lead and support cybersecurity compliance efforts, including TISAX, SOX, and other applicable frameworks. * Translate compliance requirements into practical, enforceable controls. * Partner with audit and risk teams to prepare for and complete audits successfully. * Maintain documentation of controls, processes, and evidence. * Ensure ongoing adherence-not just point-in-time compliance. Cross-Functional Collaboration & Enablement * Act as a trusted advisor across the entirety of IT * Ensure security is fully integrated into IT processes, not operating as a siloed function. * Enable teams to make secure decisions without slowing down delivery. * Serve as the escalation point for complex security challenges. * Promote a culture of shared ownership for security across IT. Continuous Improvement & Security Maturity * Drive initiatives to improve overall cybersecurity maturity. * Identify gaps in current capabilities and develop plans to address them. * Stay current on emerging threats, vulnerabilities, and industry trends. * Contribute to building a security-first culture across the organization. ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)