Full-Time

Lead Security Engineer

Posted on 10/3/2025

Practising Law Institute

Practising Law Institute

Compensation Overview

$140k - $175k/yr

New York, NY, USA

Hybrid

Hybrid remote/in-person scheduling; NY-based position

Category
IT & Security (1)
Requirements
  • Bachelor’s degree in Computer Science, Information Security, or a related discipline, or equivalent practical experience.
  • 5-8 years of experience in IT security, emphasizing vulnerability management, identity governance, networking, and application security within regulated sectors.
  • Proficiency with key vulnerability management platforms (Tanium, Tenable), IAM tools (Okta, Azure AD), and perimeter protection technologies (WAF, CDN, firewalls).
  • Extensive hands-on expertise integrating application security solutions (Veracode, Snyk) in agile DevSecOps environments.
  • Demonstrated ability in designing secure cloud architectures on AWS, Azure, and GCP, with a strong grasp of network segmentation and infrastructure as code.
  • Experience with industry standards and frameworks, including ISO 27001, NIST, PCI DSS, and SOC 2
  • Proven track record of making security and operational impacts through KPIs.
  • Professional certifications such as CISSP, CISM, CIAM, CCSP, or equivalent credentials.
  • Experience deploying zero-trust models and privileged access management systems.
  • Background in network security architecture, including VPNs, firewalls, IDS/IPS, and threat intelligence integration.
  • Success in promoting shift-left security and embedding it within agile SDLC processes.
  • Excellent communication and mentoring abilities, with skill in translating technical risks to actionable items for stakeholders.
Responsibilities
  • Partner with technology team on Security design and implementation.
  • Architect, deploy, and supervise perimeter protection measures such as web application firewalls (WAF), cloud-based next-generation firewalls, and CDN configurations to mitigate network and application threats.
  • Formulate and maintain robust identity and access management (IAM) strategies, incorporating zero-trust architecture, comprehensive identity governance, and privileged access management protocols to secure all infrastructure and applications.
  • Direct application security initiatives by integrating static and dynamic code analysis tools (e.g., Veracode, Snyk) into CI/CD pipelines to facilitate early-stage security.
  • Oversee the entire vulnerability management lifecycle, including discovery, prioritization, risk assessment, and remediation tracking via automated solutions and manual processes.
  • Lead CIRT operations, facilitating swift incident detection and resolution through SIEM solutions and threat intelligence platforms, supported by comprehensive playbooks and KPIs.
  • Collaborate with DevSecOps and SRE teams to ensure alignment of security controls with DevOps practices and secure infrastructure-as-code workflows (Terraform, Ansible).
  • Security Posture for cloud and hybrid environments across AWS, Azure, and GCP, ensuring robust segmentation, secure communication, and regulatory compliance.
  • Provide mentorship and guidance to security and engineering teams concerning best practices for vulnerability management, identity controls, network security, and application security.
  • Other duties as assigned.
Practising Law Institute

Practising Law Institute

View

Company Size

N/A

Company Stage

N/A

Total Funding

N/A

Headquarters

N/A

Founded

N/A

INACTIVE