Position Summary:
The Senior Lead, Cybersecurity plays a critical role in the daily execution and supervision of Paisly’s security operations. This individual is the key hands-on technical leader responsible for safeguarding the company’s systems, data and customers within our cloud-native environment and extensive Software as a Service (SaaS) interconnectivity.
The ideal candidate is an experienced leader and technical expert, deeply proficient in Development, Security and Operations (DevSecOps) practices. This role ensures security controls are effectively applied, acting as the primary escalation point for operational security issues and focusing on implementing technical solutions that balance business agility with security imperatives.
Essential Responsibilities:
- Serve as a trusted security advisor to Paisly leadership, assisting with business decisions that include appropriate risk considerations.
- Develop and maintain key risk indicators to measure cybersecurity risk, presenting security threats to senior and technology leadership.
- In the future, this role will include the responsibility of leading a small team of security professionals while driving a collaborative, business-aligned security culture.
- Maintain hands-on experience with Google Cloud Platform (GCP) security services and design.
- Practical experience with containerization and orchestration (Docker, Kubernetes/GKE) and/or serverless environments (e.g., Cloud Functions, Cloud Run).
- Experience implementing identity and access management in GCP, Cloud Identity and Access Management (Cloud IAM), workload identity federation, Security Assertion Markup Language (SAML) and Open IDConnect (OIDC).
- Experience conducting risk assessments, mapping controls to frameworks, National Institute of Standards and Technology (NIST), Cybersecurity Framework (CSF), Center for Internet Security (CIS Controls), ISO 27001, and communicating risk in business terms.
- Leverage the Adversarial Tactics, Techniques, and Common Knowledge (MITRE ATT&CK) framework to model threats, assess security control coverage against adversary tactics and enhance detection and response strategies.
- Participate in the security architecture review process to ensure that new products, services and infrastructure are designed and implemented with security built-in from the start.
- Enhance and oversee a data governance program, including data classification, encryption standards and Data Loss Prevention (DLP) strategies to protect sensitive information.
- Oversee the corporate threat intelligence program, translating intelligence from various sources into actionable defense improvements and proactive threat hunting.
- Proven ability to build and scale security processes in a growing organization.
- Partner with Engineering and Product teams to embed DevSecOps practices into CI/CD pipelines, including automated testing, secure builds and shift-left security.
- Oversee core security functions: incident response, vendor risk management, vulnerability management, identity and access management and security awareness.
- Ensure secure interconnectivity of Application Programming Interfaces (APIs), third-party integrations and cross-cloud data flows.
- Conduct and oversee tabletop exercises for disaster recovery, business continuity and incident response.
- Develop and track Key Performance Indicators (KPIs) and metrics to measure and report security performance and risk posture to Paisly and JetBlue leadership.
- Ensure compliance with applicable airline, financial, and data protection regulations (e.g., Payment Card Industry (PCI), Data Security Standard (DSS), General Data Protection Regulation (GDPR), Sarbanes–Oxley Act (SOX).
- Actively engage in security incident detection, investigation and remediation.
- Build and scale right-sized processes that balance agility with regulatory and enterprise standards.
- Other complex projects and duties as assigned.