9 months ago
Base Salary
$161k - $220k/yr
Responsibilities
- Guide and coach the Blue Team across information protection, incident detection and response, and security service delivery.
- Provide strategic and technical oversight for security programs and technically lead security engineers and analysts hunting, detecting, and responding to threats.
- Lead information protection activities including security tool selection, testing, implementation, maintenance, security awareness, provider management, and control testing.
- Oversee vulnerability management, threat hunting, security reviews, incident response, security services, risk assessments, vendor assessments, and PCI and SOC audit support.
- Coordinate detection and response throughout all incident phases, produce accurate incident reports, and improve response controls.
- Monitor, detect, and remediate cloud misconfigurations and security risks while participating in a 24/7 on-call rotation.
- Apply web application and API security principles to protect cloud services and provide actionable risk and vulnerability guidance to product teams.
- Mentor team members, collaborate with customers and partners, and drive security automation and technology improvements.
Requirements
- 5+ years of experience in Security Engineering, Security Operations, or Security Architecture.
- Experience acting as a technical lead for distributed teams consisting largely of remote engineers.
- Experience with PCI-DSS and other compliance and regulatory standards.
- Knowledge of attacker tactics, techniques, procedures, evolving threats, attack patterns, incident response, and cybersecurity standards.
- Experience developing and leading incident response, remediation, and mitigation activities, including investigation and countermeasure implementation.
- Deep understanding of operating system, networking, and application concepts.
- Experience hardening Windows, macOS, Linux containers, and Kubernetes.
- Familiarity with AWS security best practices and Infrastructure-as-Code.
- Experience deploying and maintaining security technologies including access proxies, API gateways, anti-malware, application control, cloud security posture tools, data leak prevention, endpoint detection and response, intrusion detection systems, firewalls, SIEM, vulnerability assessment tools, web proxies, WAFs, and zero-trust controls.
- Ability to work with Product & Engineering, Legal, People & Culture, Finance, GTM teams, external partners, auditors, and customers.
- Ability to work during critical incidents and support coverage requirements.
- CISSP, GCIH, or a similar certification is preferred.
Benefits
- Remote work from anywhere in the U.S. or from Olo’s New York City headquarters, with remote or office choice for employees in the New York City area.
- 20 days of paid time off, 10 sick days, 11 holidays, and year-end closure.
- Health, dental, and vision coverage for employees and families.
- 401(k) match, remote-office stipend, parental leave, volunteer time off, and gift matching policy.
- Participation in a 24/7 on-call rotation.
