Senior IT Security Engineer
Chesapeake, VA - USA
Job Summary
About INIT
INIT Innovations in Transportation Inc. is a leading provider of hardware software service support and operations management solutions for public transportation companies across North America. As a turnkey supplier INIT develops produces installs and maintains integrated hardware and software solutions for all key tasks required by transportation authorities including fare collection systems passenger counting CAD/AVL systems passenger information systems and other Intelligent Transportation System solutions.
Our Information Technology team designs builds operates and maintains infrastructure in support of INIT software solutions deployed for transit agency customers in major metropolitan areas including Atlanta Houston Los Angeles San Diego Seattle Portland Tampa Honolulu and more.
Position Summary
INIT is seeking a Senior IT Security Engineer to drive security controls security operations and GRC activities across INITs internal corporate infrastructure and customer-facing transit technology deployments.
This role contributes to the security architecture security operations and control framework across PCI DSS SOC 2 and ISO 27001. The Senior IT Security Engineer works closely with the IT Security Administrator IT Operations and IT Systems Engineering teams and reports to the Director of IT.
Key Responsibilities
Security Strategy
Establish security vision strategy and roadmaps with the Director of IT encompassing internal programs and customer-facing security commitments.
Direct the selection and lifecycle of security tools architectures and infrastructure security direction across the organization.
Establish identity access and security hardening standards including Conditional Access privileged access and CIS benchmark requirements for implementation across the environment.
Evaluate security requirements and architecture for customer projects and proposals identifying gaps strategies and budgets needed to meet requirements and make final decisions on customer project security architecture.
Identify strategic trends affecting the companys security posture and customer trust.
Evaluate and guide secure adoption of AI tools and platforms across IT and business functions balancing productivity gains against data protection compliance and vendor risk.
Security Operations
Serve as incident commander or alternate incident commander during security incidents.
Direct threat intelligence efforts monitoring emerging threats vulnerabilities and attacker techniques relevant to the transit technology industry and translating findings into operational and architectural changes.
Lead the tabletop exercise program setting cadence scope and participation across technical and business stakeholders and direct post-exercise and post-incident retrospectives that translate findings into playbook and control updates.
Communicate security posture risk exposure and incident status to senior management and as needed to customers.
Oversee operational security strategy across customer projects including contractual security and compliance obligations.
GRC (Governance Risk and Compliance)
Direct the organizations risk management program identifying assessing and prioritizing information security risks and recommending treatment strategies to leadership.
Establish and maintain the security control framework mapping across PCI DSS SOC 2 and ISO 27001 ensuring controls satisfy overlapping framework requirements.
Serve as the primary point of contact for external auditors and assessors during compliance audits and certification cycles and direct remediation of audit findings and gap assessment outcomes.
Evaluate new regulatory and contractual requirements and translate them into control requirements.
Set direction for the organizations security policy suite leading the creation review and revision of iinformation security policies and procedures.
Lead third-party vendor security risk management directing vendor risk assessments critical vendor classification and ongoing monitoring of vendor compliance obligations.
Direct the security awareness and training program setting curriculum priorities campaign cadence and risk-based focus areas for the organization.
Set risk-based prioritization standards for the vulnerability management program and review remediation trends against risk tolerance.
Required Qualifications
10 years of experience in information security risk management or compliance with increasing responsibility.
Proven experience establishing and directing information security strategy governance and risk management programs.
Security-relevant certification required such as CISSP CISM CISA or CRISC or actively pursuing one.
Experience implementing assessing or designing systems within PCI DSS SOC 2 ISO 27001 or NIST 800-53 frameworks.
Experience serving as incident commander or leading incident response efforts.
Proven ability to communicate security posture risk and compliance status to senior management and external stakeholders.
Strong leadership problem-solving and critical thinking abilities.
Ability to work collaboratively across IT Operations IT Systems Engineering and software development teams.
Preferred Qualifications
CISSP CISM CISA or CRISC certification held rather than in progress.
Experience directing GRC programs or serving as the primary point of contact for external auditors and QSAs.
Experience mapping controls across multiple compliance frameworks including PCI DSS SOC 2 and ISO 27001.
Experience owning an enterprise incident response and tabletop exercise program.
Familiarity with cloud security architecture in Microsoft Azure and modern security tooling such as Cloudflare Arctic Wolf and Tenable.
Experience in the transportation transit or critical infrastructure sector.
Work Environment and Travel
Hybrid position. Work from Hampton Roads VA is preferred; remote candidates will be considered.
Regular travel to INITs Hampton Roads VA offices expected for team collaboration audit activities and project engagement.
Travel to customer sites across North America required as project and audit needs dictate.
Must be available to adjust work hours as needed to support incident response activities and incident command duties outside of normal business hours.
What INIT Offers
The opportunity to own and direct the security strategy protecting mission-critical transit technology systems deployed across major North American cities.
Ownership of INITs risk management governance and compliance program across PCI DSS SOC2 and ISO 27001.
A collaborative team environment working with IT Operations IT Systems Engineering and software development teams.
Support for professional development and advancement toward executive-level security certifications.
A hybrid work model with flexibility for remote work combined with meaningful in-person collaboration.
Benefits
We offer a comprehensive benefits package designed to support your health financial well-being and work-life balance including:
- Competitive paid time off starting with 15 days of vacation increasing with tenure plus 11 paid holidays a personal day and a community service day
- 6 paid sick days annually
- Paid parental leave
- 100% employer-paid health and dental insurance for employees with generous dependent coverage contributions
- 401(k) with company match (currently dollar-for-dollar up to 5% of salary)
- Company-paid life insurance plus short-term and long-term disability insurance
- Flexible Spending Accounts (medical dependent care and limited FSA options) with employer contributions for eligible medical plans
- Annual benefit allowance for optional employee benefits
- Continuing education assistance and support for professional development
- Optional benefits including accident insurance legal services identity theft protection adoption assistance education assistance and student loan repayment assistance
Compensation
The annual salary range for this position is $125000 -$150000 depending on experience.
INIT Innovations in Transportation Inc. is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race color religion sex national origin disability status protected veteran status or any other characteristic protected by law.
Required Experience:
Senior IC
About Company
INIT is the worldwide leading supplier of integrated planning, dispatching, telematics and ticketing systems for buses and rail.