安全工程总监(远程,GA,美国,远程)
DIRECTOR OF SECURITY ENGINEERING (REMOTE, GA, US, REMOTE)
薪资:18万美元-20万美元 + 可获得奖金
Compass Technology 是 Compass Group 的一个内部团队,专注于为企业范围内的项目提供支持,以满足我们多元化的客户群体并提升我们的业务运营。我们的领域涵盖广泛的机会,从现场桌面支持到网络安全、云工程、人工智能和现代应用开发。我们致力于构建强大的 IT 基础架构,推动数字化转型等。
职位概述
向 Comapss Group 北美地区的高级网络安全总监汇报,安全工程总监负责在云安全、基础设施安全和检测工程方面制定策略、提供领导并执行 Compass Group 的安全工程职能。该职位领导一个多团队的组织,为跨云环境的安全控制以及支撑我们安全运营的安全工具和基础设施设定技术路线。
该职位负责安全工具的有效性、将遥测数据转化为高保真、可操作信号的检测工程功能,以及在我们多云架构中部署和维护控制能力。该职位高度协作,与 CISO 办公室内的事件管理、身份管理、暴露管理、安全架构和安全行政团队,以及 Comapss Group 北美地区的技术团队紧密合作。
职位职责
- 通过经理和独立贡献者领导安全工程团队(云安全、基础设施安全和检测工程),制定与安全目标一致的组织、团队和个人目标。
- 招聘、培养和留住技术人才:建立清晰的职业发展路径,指导经理和工程师,并进行绩效评估。
- 主导多年安全工程路线图,塑造能力、方法和投资优先级。
- 管理安全供应商组合:工具整合与优化,采购、续约、许可和预算对齐,支持升级,路线图影响,以及季度业务评审。对供应商和工具负责,确保可衡量的结果,并全程管理工具生命周期。
- 与 IT、基础设施、应用和行业技术团队合作推进安全工程项目,并领导或支持相关计划
查看英文原文
Salary: $180,000-$200,000 + bonus eligible
Compass Technology is a dedicated internal team for Compass Group delivering enterprise-wide initiatives that support our diverse customer base and enhance our business operations. Our domain encompasses a vast spectrum of opportunities, from hands-on desk support to Cybersecurity, Cloud Engineering, AI, and Modern Application development. We are committed to building robust IT infrastructures, driving digital transformation, and much more.
Job Summary
Reporting to the Sr. Director of Cybersecurity within Compass Group North America, the Director of Security Engineering owns the strategy, leadership, and execution of Compass Group’s security engineering functions across cloud security, infrastructure security, and detection engineering. Leading a multi-team organization, the Director sets the technical roadmap for security controls across cloud environments and the security tooling and infrastructure underpinning our security operations.
The role owns the health and effectiveness of our security tooling, the detection engineering function that turns telemetry into high-fidelity, actionable signals, and the cloud security capabilities that deploy and maintain controls across our multi-cloud footprint. It is highly collaborative, partnering closely with the Incident Management, Identity Management, Exposure Management, Security Architecture, and Security Administration teams within the CISO Office, and with technology teams across Compass Group North America.
Job Responsibilities
- Lead the Security Engineering organization (Cloud Security, Infrastructure Security, and Detection Engineering) through managers and individual contributors, setting organizational, team, and individual goals aligned to security objectives.
- Recruit, develop, and retain technical talent: build clear career paths, mentor managers and engineers, and conduct performance appraisals.
- Own the multi-year security engineering roadmap, shaping capabilities, methods, and investment priorities.
- Own the security vendor portfolio: tool consolidation and rationalization, procurement, renewals, licensing and budget alignment, support escalations, roadmap influence, and quarterly business reviews. Hold vendors and tools accountable to measurable outcomes and manage tool lifecycle end to end.
- Partner across IT, infrastructure, application, and sector technology teams to advance security engineering projects, and lead or support initiatives sponsored by security, technology, and business teams.
- Present posture and metrics to the CISO Office and senior technology leadership; serve as executive-level subject matter expert on security engineering, cloud-native controls, and defensive engineering.
- Direct the design, deployment, and operation of security visibility and control mechanisms across AWS, GCP, and Azure, including validating adherence through regular monitoring and audits.
- Own the technical direction and operational health, availability, coverage, performance, and patch management of the endpoint, network security, and vulnerability management platform stack.
- Own SIEM, SOAR, and security telemetry platform strategy: log source prioritization, ingestion optimization and filtering, consumption management, and platform health and efficiency.
- Mature detection engineering as a discipline: use cases mapped to recognized adversary frameworks such as MITRE ATT&CK, detection-as-code with version control and testing, tuning, and coverage measurement.
- Drive event prioritization and cross-tool correlation to reduce false positives, in collaboration with the Incident Management team.
- Direct and advance automation development supporting incident management and other security capabilities, and ensure the health, optimization, and intended results of workflows.
- Remain available for escalation during significant security incidents and major security platform disruptions.
Job Qualifications
- 10+ years across cybersecurity and information technology, including 5+ years managing engineering teams and 2+ years leading managers or senior technical leads.
- Bachelor’s degree in Computer Engineering, Computer Science, Information/Cybersecurity, or equivalent work experience.
- Proven experience building or maturing enterprise-scale security engineering functions across cloud security, infrastructure security, and detection engineering, including securing medium to large enterprise infrastructure.
- Deep, current experience designing, implementing, and securing cloud infrastructure in one major platform (AWS, GCP, or Azure), with working knowledge of a second.
- Strong knowledge of cloud security principles and industry standards (NIST, ISO 27001, CIS).
- Demonstrated ownership of enterprise security tooling, including SIEM, EDR, and web content filtering strategy.
- Strong analytical and problem-solving skills, with the ability to assess risk, prioritize competing initiatives, and lead through ambiguity in a decentralized organization.
- Excellent written and verbal communication, project management, and documentation skills, with the ability to present security concepts to technical and non-technical audiences.
Preferred Qualifications
- Broad experience with platforms such as Google SecOps, CrowdStrike, Zscaler, Microsoft 365, vulnerability management, and privileged access management, or equivalents.
- Industry certifications (CISSP, CCSP, CISA, CISM, GCIA, GCIH, or cloud security specialty credentials).
- Experience in a large, highly distributed enterprise environment.
Apply to Compass Group today!
Click here to Learn More about the Compass Story
Compass Group is an equal opportunity employer. At Compass, we are committed to treating all Applicants and Associates fairly based on their abilities, achievements, and experience without regard to race, national origin, sex, age, disability, veteran status, sexual orientation, gender identity, or any other classification protected by law.
Qualified candidates must be able to perform the essential functions of this position satisfactorily with or without a reasonable accommodation. Disclaimer: this job post is not necessarily an exhaustive list of all essential responsibilities, skills, tasks, or requirements associated with this position. While this is intended to be an accurate reflection of the position posted, the Company reserves the right to modify or change the essential functions of the job based on business necessity. We will consider for employment all qualified applicants, including those with a criminal history (including relevant driving history), in a manner consistent with all applicable federal, state, and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York Fair Chance Act.
Compass Technology maintains a drug-free workplace.
Applications are accepted on an ongoing basis.
Associates at Corporate are offered many fantastic benefits.
- Medical
- Dental
- Vision
- Life Insurance/ AD
- Disability Insurance
- Retirement Plan
- Paid Time Off
- Holiday Time Off (varies by site/state)
- Associate Shopping Program
- Health and Wellness Programs
- Discount Marketplace
- Identity Theft Protection
- Pet Insurance
- Commuter Benefits
- Employee Assistance Program
- Flexible Spending Accounts (FSAs)
- Paid Parental Leave
- Personal Leave
Associates may also be eligible for paid and/or unpaid time off benefits in accordance with applicable federal, state, and local laws. For positions in Washington State, Maryland, or to be p formed Remotely, click here or copy/paste the link below for paid time off benefits information.
Certain positions may require Florida Level 2 background screening. Details:
Req ID: 1572403
Compass Technology
MARY DICKSON
Originally posted on Himalayas