SecOps Engineer Lead, New York
New York••April 15, 2025
Lab49 is seeking a SecOps Engineer Lead to drive security strategy, governance, and operations across our high-performance engineering environments. This role is critical in designing and implementing security frameworks, ensuring compliance, and proactively defending against cyber threats in fast-paced financial services and capital markets engagements.
Responsibilities:
- Develop and implement a robust security strategy aligned with industry standards, regulatory requirements, and business objectives.
- Lead proactive threat hunting, real-time security monitoring, and rapid incident response to mitigate risks.
- Define security best practices for multi-cloud (AWS, Azure, GCP) and on-prem environments, ensuring secure deployments.
- Work closely with engineering teams to embed security into CI/CD pipelines, automating vulnerability management and compliance enforcement.
- Design and enforce robust IAM policies, privilege management, and zero-trust security models.
- Deploy and manage security tooling, including SIEM, IDS/IPS, endpoint security, SAST/DAST, and cloud security controls.
- Ensure adherence to financial services security frameworks such as ISO 27001, NIST, SOC 2, GDPR, and financial regulatory guidelines.
- Lead internal security training programs, coaching teams on secure coding, risk management, and emerging threats.
- Collaborate with leadership, development teams, and clients to align security initiatives with business objectives.
Requirements:
- 8+ years of experience in security operations, cybersecurity, or cloud security engineering.
- Expertise in SIEM, SOAR, IDS/IPS, EDR/XDR, and security automation tools.
- Strong knowledge of cloud security best practices across AWS, Azure, and GCP.
- Experience with container security (Kubernetes, Docker) and microservices security.
- Hands-on experience in vulnerability management, penetration testing, and forensics.
- Proficiency in Python, Bash, or PowerShell for security automation.
- Strong understanding of IAM, zero-trust architectures, and cryptographic controls.
- Familiarity with regulatory requirements in financial services and capital markets.
- Excellent communication and stakeholder management skills.