Senior Information Security Lead, SOX & Network Security
Overview
As the Senior Information Security Lead at Genesis Capital, you will own and operate the enterprise security control plane across a hybrid Azure/AWS/Microsoft 365 and on-prem environment. You will be the primary security control owner and audit gatekeeper for SOX ITGCs, partnering with auditors and IT teams to maintain audit-ready evidence and remediate deficiencies. You will act as the technical authority for network security, vulnerability management, and incident response, without managing a team. This role uniquely combines hands-on execution with governance, risk, and executive communication, influencing security posture directly.
What You'll Do8
- 1Design and configure Palo Alto firewall rulebases, segmentation, and secure connectivity across the hybrid network. Operate Netskope SSE policies and monitor for violations.
- 2Own the vulnerability lifecycle with Qualys, setting scan coverage, severity thresholds, and remediation SLAs. Validate closures through rescans and evidence review.
- 3Translate security policies into enforceable controls across Microsoft 365, Azure, AWS, and on-prem systems. Conduct risk assessments for new systems and integrations.
- 4Serve as named control owner for assigned SOX ITGCs, maintaining narratives, evidence standards, and audit-ready documentation throughout the year.
- 5Act as the approval authority for risk exceptions, documenting business justification and compensating controls. Escalate material risks to executive leadership with impact analysis.
- 6Lead incident response from containment to root-cause analysis, tracking corrective actions. Maintain IR and DR documentation and coordinate tabletop exercises.
- 7Drive quarterly phishing simulations and user access reviews for SOX-scoped applications, analyzing results to target remediation.
- 8Prepare monthly executive dashboards on risk posture, vulnerability trends, audit status, and control effectiveness.
Requirements9
- 17+ years of progressive experience in network security and information security, with financial services strongly preferred.
- 2Hands-on experience securing Microsoft 365, Azure, AWS, and hybrid/on-prem environments.
- 3Expertise with firewalls, zero trust, and vulnerability management, including Palo Alto, Netskope, and Qualys.
- 4Strong knowledge of Windows/Linux, VMware, SQL Server, Active Directory, and networking.
- 5Demonstrated experience as primary audit contact and control owner for SOX or similar regulatory audits.
- 6Working knowledge of ISO 27000, SOX, PCI, and GLBA control expectations.
- 7Hands-on experience with SIEM systems and open-source security tools.
- 8Excellent written and verbal communication skills, including audit-ready documentation and executive briefing.
- 9Security certifications (CISSP, CISM, CCSP) are strongly preferred.
Salary Insight
$125 - $165k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.
Concert Golf Partners
VerifiedSenior Cybersecurity Manager, Enterprise Security Operations
You will own the daily operation and health of Concert Golf Partners' enterprise security platform across 40+ premier golf clubs. You will run EDR, SIEM, email security, and vulnerability management tools at scale, reporting to the VP of IT. You will set operating standards and lead technical initiatives with limited oversight. This role offers the chance to shape security operations for a multi-site enterprise, with travel to club locations.

Visionaire Partners
VerifiedSenior Cybersecurity Engineer, Cloud Security
You will spearhead defensive operations, threat detection, and risk mitigation across complex enterprise networks, AWS and Azure, and endpoint environments. You will design security tool architecture to harden system baselines and drive security posture across cloud and containerized infrastructure. Your stack includes SIEM, EDR, CSPM, and IaC tools. You will partner with DevOps and network teams to embed security into the build pipeline. This role puts you at the center of security strategy for a critical infrastructure provider.
Palo Alto Networks
VerifiedPrincipal Network Security Architect | Palo Alto Networks
You will own the architectural blueprint and governance for a global network security footprint spanning hybrid cloud and on-prem. As Principal Enterprise Network Security Architect, you will drive Zero Trust adoption, security automation, and AI/ML integration. You will collaborate with security, infrastructure, and IT teams to embed security into every layer. This role stands out for its automation-first approach and ultimate escalation authority during critical events.

Javen Technologies, Inc
VerifiedSenior IT Risk and Compliance Analyst - GRC Framework Expertise
Lead ownership of IT governance alignment supporting Bank's GRC framework Enterprise Risk Management and Sarbanes-Oxley compliance. Drive improvements through collaboration with IT staff. Analyze technology risks and develop appropriate controls. Stand out by delivering measurable risk reduction outcomes within first 90 days.

Belcan, LLC
VerifiedCybersecurity Operations & Communications Lead
Own the security operations and communications strategy for a global enterprise, coordinating incident response across SIEM, SOAR, and EDR platforms. You lead a team of analysts, manage threat intelligence feeds, and craft executive-level briefings. This role sits at the intersection of technical operations and stakeholder communication, reporting directly to the CISO. You will drive the adoption of MITRE ATT&CK framework and NIST guidelines, shaping the organization's cyber resilience.

CCS Global Tech
VerifiedNetwork Security Administrator CCS Global Tech
Lead design and implementation of secure infrastructure to protect organizational assets. Manage identity and access controls across hybrid environments. Ensure compliance with industry standards while supporting rapid growth initiatives. Drive continuous improvement of security posture through proactive monitoring and incident response.