Senior Cybersecurity & IT Controls Engineer
Core
Design, engineer, and assess cybersecurity and IT controls across SaaS, cloud-native infrastructure, identity platforms, and data environments to ensure effective risk management and compliance.
Role type
Senior individual contributor cybersecurity controls engineer
Builds
Control patterns, guardrails, reference architectures, and automated assurance workflows
Domain
Cybersecurity, IT General Controls, Cloud Security, Compliance (SOX, GDPR, PCI)
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Cybersecurity frameworks (NIST, ISO, CIS), IT General Controls, Cloud platform security, Identity and Access Management (IAM), Regulatory compliance (SOX, GDPR, PCI, CCPA), GRC tooling (ServiceNow IRM), Technical evidence evaluation, Risk assessment, Control automation scripting
Preferred skills
CISA, CISSP, CRISC, CISM, or CCSP certifications, AI/ML for controls automation, Data analytics for reporting, Global enterprise environment experience, Supervisory or mentoring experience
Technologies
ServiceNow IRM, Cloud-native security tools, IAM tools, Logging platforms, Vulnerability management tools
Responsibilities
Design and refine control patterns aligned with NIST, ISO, and CIS standards; Translate policies into actionable technical requirements for engineering teams; Engineer controls assurance workflows and data integrations; Develop automation scripts and pipelines for continuous monitoring; Assess design and operating effectiveness of controls across applications and infrastructure; Identify control gaps and recommend risk-based improvements; Provide executive-ready reporting on control posture and remediation status.
Seniority
Senior, hands-on IC