Apply Edge Start your job search

Security Automation Lead

Confidential · New York, NY

Apply & track with Apply Edge

Location: New York, NYWork Arrangement: Hybrid — 3 days per week in officeBase Salary: $250,000–$350,000 + BonusEstimated Total Compensation: $400,000–$500,000, depending on experience

Employment Type: Full-TimePosition OverviewA leading financial services organization is seeking an experienced Security Automation Lead to build and lead a modern, engineering-driven security automation program.This is a senior, hands-on leadership role responsible for designing and operating scalable security automation across endpoint, identity, cloud, vulnerability management, and cloud-native environments.The ideal candidate combines deep security engineering expertise with strong Infrastructure-as-Code (IaC), CI/CD, automation, Kubernetes, observability, and policy-as-code experience.

This individual will also lead a technical team, own sprint execution, and drive the transition from manual security operations toward version-controlled, auditable, engineering-owned automation.What You'll DoLead the design and operation of a unified, auditable security automation pipeline where security controls are authored, reviewed, validated, and deployed.Build drift detection, reconciliation, and validation engines that identify and remediate configuration divergence across endpoint, identity, cloud, and vulnerability-management environments.Replace manual console-based security operations with version-controlled and auditable automation using Infrastructure-as-Code and configuration-management platforms.Design and scale reusable IaC deployment patterns and automation components that accelerate delivery of security controls across teams.Build and maintain CI/CD pipelines with automated linting, testing, policy-as-code checks, pre-deployment validation gates, and controlled promotion workflows.Develop observability and monitoring pipelines that surface configuration drift, control failures, deployment health, and other security signals.Build and improve container and Kubernetes security automation, including image scanning, admission controls, runtime policy enforcement, and namespace isolation.Integrate automation with existing enterprise security and infrastructure platforms.Drive the transition from contractor-delivered and manual security processes toward sustainable, engineering-owned automation.Lead the team's sprint cycle using a structured backlog, two-week cadence, disciplined capacity planning, and clearly defined completion standards.Manage and develop security engineering talent, including hiring, coaching, performance management, and accountability for delivery.Establish and track operational metrics including toil reduction, bypass rates, change failure rates, drift detection and remediation times, and sprint predictability.Use operational metrics and postmortems to drive continuous improvement across security engineering processes.Required QualificationsDemonstrated experience building and operating security automation pipelines in production environments.Strong hands-on experience with:Security automationInfrastructure-as-CodeCI/CDConfiguration managementScripting and automationProficiency with Python, PowerShell, Bash, or similar scripting languages.Hands-on experience with Terraform, CloudFormation, or Pulumi for infrastructure provisioning and policy enforcement at scale.Proven experience designing and operating CI/CD pipelines using GitHub Actions, GitLab CI, Jenkins, or equivalent platforms.Strong understanding of branching strategies, automated testing, validation gates, and deployment/promotion workflows.Working knowledge of Kubernetes, including:Cluster operationsHelm chart managementContainer/image lifecycleAdmission controllersRuntime securityNamespace isolationExperience designing and operating observability environments using platforms such as Prometheus, Grafana, Datadog, or Splunk.Familiarity with policy-as-code frameworks such as Open Policy Agent (OPA/Rego), Sentinel, Cedar, or similar technologies.Working knowledge of enterprise security technologies across areas such as:Endpoint Detection & Response (EDR)Mobile Device Management (MDM)Identity and access managementSIEMVulnerability managementExperience integrating security platforms with automation and infrastructure tooling.Direct people-management experience, including hiring, coaching, professional development, and accountability for delivery.Demonstrated experience leading teams within a structured sprint environment, including backlog prioritization, capacity planning, and Definition of Done enforcement.Strong communication and cross-functional leadership skills.Commitment to high ethical and professional standards.Ideal Candidate ProfileThe strongest candidate will combine security engineering leadership with hands-on DevSecOps and platform engineering expertise.We are looking for someone who has personally built production automation—not simply managed security teams or administered security tools.You should be comfortable working across Terraform, CI/CD, Kubernetes, scripting, observability, policy-as-code, and enterprise security platforms, while also leading engineers and establishing disciplined engineering practices.The ideal candidate has successfully transformed manual security operations into automated, version-controlled, testable, auditable, and scalable engineering workflows.Experience within financial services, investment management, quantitative trading, fintech, or another highly sophisticated enterprise technology environment is highly desirable.CompensationBase Salary: $250,000–$350,000The position also includes a performance-based bonus, with anticipated total compensation of approximately $400,000–$500,000, depending on experience and qualifications.Location & ScheduleNew York, NYThis is a hybrid position requiring 3 days per week in office.Candidates must be able to regularly commute to the New York City office.Confidential Search: Additional information regarding the organization will be provided to qualified candidates as they progress through the recruitment process.