Cybersecurity Engineering & Operations Director

Onit · Remote - USA · posted Oct 7, 2026

Open to candidates in United States

$150k–$190kFull-timedirectorSaaS
Can this job hire you?

We never charge to apply.

What this role actually asks for

Extracted by RemoteHunt

Must have

  • •10+ years progressive cybersecurity experience
  • •5+ years security leadership/management
  • •Deep expertise securing cloud-native SaaS apps
  • •Strong hands-on AWS security experience
  • •Experience with SIEM, EDR, CSPM, vulnerability management
  • •Experience securing M365 and Entra ID
  • •Hands-on AI tool proficiency in security work

Nice to have

  • •Experience with multi-tenant SaaS security
  • •Experience with CrowdStrike, Cloudflare
  • •DevSecOps experience
  • •Offensive security or red-team programs
  • •Familiarity with SOC 2, ISO 27001, NIST, FedRAMP

Tools and technologies

AWSTerraformPythonCI/CDMicrosoft 365Entra IDSASTDASTSCAAPILLM

The full posting

About Onit:

We're redefining the future of legal operations through the power of AI. Our cutting-edge platform streamlines enterprise legal management, matter management, spend management and contract lifecycle processes, transforming manual workflows into intelligent, automated solutions.

We’re a team of innovators using AI at the core to help legal departments become faster, smarter, and more strategic. As we continue to grow and expand the capabilities of our new AI-centric platform, we’re looking for bold thinkers and builders who are excited to shape the next chapter of legal tech.

If you're energized by meaningful work, love solving complex problems, and want to help modernize how legal teams operate, we’d love to meet you.

Onit is seeking a Director of Cybersecurity Engineering & Operations to lead the technical cybersecurity function across our AI-driven legal operations SaaS platforms and corporate infrastructure. Reporting to the Vice President, Compliance and Security, this highly technical leader translates the organization's cybersecurity strategy into security architecture, engineering capabilities, and security operations that protect our products, cloud environments, employees, and corporate systems. The Director leads a cybersecurity manager and a team of security engineers and operations professionals, and partners closely with Cloud Engineering, Product Engineering, IT, and Compliance to reduce risk while enabling the company to build and operate securely.

Key Responsibilities

:
• Develop and execute the cybersecurity engineering and operations strategy with the VP, Compliance and Security, translating risk and business priorities into technical roadmaps, architecture standards, and measurable outcomes (e.g., remediation performance, control coverage, incident response effectiveness, attack surface and posture trends).

• Lead the design and continuous improvement of security controls and guardrails across AWS and corporate environments, including cloud identity, network, workload, container/Kubernetes, and data protections, with security automation delivered as code (Terraform, Python, CI/CD, policy-as-code).

• Own technical security operations and incident response: detection, investigation, containment, eradication, and recovery; maintain and exercise IR plans, playbooks, and runbooks; build automated detection and response workflows across SIEM, SOAR, EDR, and cloud-native tooling; and coordinate executive, legal, and regulatory escalation with the VP.

• Own the vulnerability and exposure management program across applications, cloud, endpoints, and external attack surfaces, setting risk-based remediation SLAs and prioritizing by exploitability, exposure, and business impact while driving root-cause fixes for systemic weaknesses.

• Provide security leadership for Microsoft 365 and Entra ID (MFA, Conditional Access, privileged identity management, Just-In-Time access), corporate endpoint and email security, and for application and product security across the SDLC, including SAST/DAST/SCA, SBOMs, API security, threat modeling, a security champions program, and AI-enabled applications and integrations.

• Lead, mentor, and develop the cybersecurity manager, engineers, and security operations staff; define team structure, career paths, and operating processes that scale; manage security vendors, penetration testing, and managed security services; and serve as senior technical security advisor to Engineering, IT, Product, and executive leadership.

Required Skills

:
• 10+ years of progressive cybersecurity experience, including 5+ years in security leadership or management roles leading security engineering, security operations, or cloud security functions, with experience managing managers and technical teams.

• Deep expertise securing cloud-native enterprise SaaS applications, with strong hands-on AWS security experience (IAM, VPC, EC2, RDS, S3, EKS/ECS, logging, monitoring) and strong knowledge of Linux, networking, containers, and Kubernetes.

• Strong experience with security technologies including SIEM, EDR, CSPM, vulnerability management, WAF, and security monitoring platforms, and demonstrated experience building or improving incident detection and response programs.

• Experience securing Microsoft 365 and Entra ID environments (identity protection, MFA, Conditional Access, privileged identity management, access governance) and implementing privileged access management and Just-In-Time access architectures.

• Strong understanding of application and API security (SAST, DAST, SCA, SBOMs, secrets management, authentication/authorization) and experience with security automation and scripting using Python, Bash, Terraform, APIs, and CI/CD platforms, including Infrastructure-as-Code security and policy-as-code guardrails.

• Hands-on AI tool proficiency: experience using AI tools and LLM-based assistants in security work (e.g., AI-assisted alert triage, investigation, detection engineering, and automation), including crafting effective prompts, evaluating output accuracy, and integrating AI into security workflows. Experience securing AI-enabled applications, LLM integrations, and APIs is a plus.

• Ability to communicate complex cybersecurity risks to engineering leaders, executives, and non-technical stakeholders, and to balance risk reduction with business objectives and engineering velocity.

• Preferred: experience with multi-tenant SaaS security, CrowdStrike, Cloudflare (WAF and Zero Trust), DevSecOps, and offensive security or red-team programs; familiarity with SOC 2, ISO 27001, NIST, or FedRAMP technical controls; and certifications such as CISSP, CCSP, AWS Security Specialty, or GIAC.

Send this job to a friend:TelegramWhatsApp

Similar remote jobs

Get new jobs like this by email

Once a week. Remote security engineer jobs that can hire you in your country.

Hiring in: your countryChange

Weekly, only when there are at least 3 new jobs. No account needed. Unsubscribe in one click. You never pay to apply. Privacy

Is this one actually worth your time?

RemoteHunt scores every remote job 0–100 against your own resume, so you apply to the handful that fit instead of the hundred that don't. Free plan, no card required.