Senior IT Security Engineer
INIT Innovations in Transportation, Inc. · United States
FULL TIMEfull-time
Job Description
<p>About INIT
INIT Innovations in Transportation, Inc. is a leading provider of hardware,
software, service, support, and operations management solutions for public
transportation companies across North America. As a turnkey supplier, INIT
develops, produces, installs, and maintains integrated hardware and software
solutions for all key tasks required by transportation authorities, including
fare collection systems, passenger counting, CAD/AVL systems, passenger
information systems, and other Intelligent Transportation System solutions.
Our Information Technology team designs, builds, operates, and maintains
infrastructure in support of INIT software solutions deployed for transit agency
customers in major metropolitan areas including Atlanta, Houston, Los Angeles,
San Diego, Seattle, Portland, Tampa, Honolulu, and more.
Position Summary
INIT is seeking a Senior IT Security Engineer to drive security controls,
security operations and GRC activities across INIT's internal corporate
infrastructure and customer-facing transit technology deployments.
This role contributes to the security architecture, security operations and
control framework across PCI DSS, SOC 2, and ISO 27001. The Senior IT Security
Engineer works closely with the IT Security Administrator, IT Operations, and IT
Systems Engineering teams, and reports to the Director of IT.
Key Responsibilities
Security Strategy
• Establish security vision, strategy, and roadmaps with the Director of IT,
encompassing internal programs and customer-facing security commitments.
• Direct the selection and lifecycle of security tools, architectures, and
infrastructure security direction across the organization.
• Establish identity, access, and security hardening standards, including
Conditional Access, privileged access, and CIS benchmark requirements, for
implementation across the environment.
• Evaluate security requirements and architecture for customer projects and
proposals, identifying gaps, strategies, and budgets needed to meet
requirements, and make final decisions on customer project security
architecture.
• Identify strategic trends affecting the company's security posture and
customer trust.
• Evaluate and guide secure adoption of AI tools and platforms across IT and
business functions, balancing productivity gains against data protection,
compliance, and vendor risk.
Security Operations
• Serve as incident commander or alternate incident commander during security
incidents.
• Direct threat intelligence efforts, monitoring emerging threats,
vulnerabilities, and attacker techniques relevant to the transit technology
industry, and translating findings into operational and architectural changes.
• Lead the tabletop exercise program, setting cadence, scope, and participation
across technical and business stakeholders, and direct post-exercise and
post-incident retrospectives that translate findings into playbook and control
updates.
• Communicate security posture, risk exposure, and incident status to senior
management and, as needed, to customers.
• Oversee operational security strategy across customer projects, including
contractual security and compliance obligations.
GRC (Governance, Risk, and Compliance)
• Direct the organization's risk management program, identifying, assessing, and
prioritizing information security risks and recommending treatment strategies to
leadership.
• Establish and maintain the security control framework mapping across PCI DSS,
SOC 2, and ISO 27001, ensuring controls satisfy overlapping framework
requirements.
• Serve as the primary point of contact for external auditors and assessors
during compliance audits and certification cycles, and direct remediation of
audit findings and gap assessment outcomes.
• Evaluate new regulatory and contractual requirements and translate them into
control requirements.
• Set direction for the organization's security policy suite, leading the
creation, review, and revision of iinformation security policies and procedures.
• Lead third-party vendor security risk management, directing vendor risk
assessments, critical vendor classification, and ongoing monitoring of vendor
compliance obligations.
• Direct the security awareness and training program, setting curriculum
priorities, campaign cadence, and risk-based focus areas for the organization.
• Set risk-based prioritization standards for the vulnerability management
program and review remediation trends against risk tolerance.
Required Qualifications
• 10+ years of experience in information security, risk management, or
compliance, with increasing responsibility.
• Proven experience establishing and directing information security strategy,
governance, and risk management programs.
• Security-relevant certification required, such as CISSP, CISM, CISA, or CRISC,
or actively pursuing one.
• Experience implementing, assessing, or designing systems within PCI DSS, SOC
2, ISO 27001, or NIST 800-53 frameworks.
</p><ul><li>Experience serving as incident commander or leading incident response efforts.</li><li>Proven ability to communicate security posture, risk, and compliance status to</li></ul>
senior management and external stakeholders.
<ul><li>Strong leadership, problem-solving, and critical thinking abilities.</li><li>Ability to work collaboratively across IT Operations, IT Systems Engineering,</li></ul>
and software development teams.
Preferred Qualifications
<ul><li>CISSP, CISM, CISA, or CRISC certification held, rather than in progress.</li><li>Experience directing GRC programs or serving as the primary point of contact</li></ul>
for external auditors and QSAs.
• Experience mapping controls across multiple compliance frameworks, including
PCI DSS, SOC 2, and ISO 27001.
• Experience owning an enterprise incident response and tabletop exercise
program.
• Familiarity with cloud security architecture in Microsoft Azure and modern
security tooling such as Cloudflare, Arctic Wolf, and Tenable.
• Experience in the transportation, transit, or critical infrastructure sector.
Work Environment and Travel
• Hybrid position. Work from Hampton Roads, VA is preferred; remote candidates
will be considered.
• Regular travel to INIT's Hampton Roads, VA offices expected for team
collaboration, audit activities, and project engagement.
• Travel to customer sites across North America required as project and audit
needs dictate.
• Must be available to adjust work hours as needed to support incident response
activities and incident command duties outside of normal business hours.
What INIT Offers
• The opportunity to own and direct the security strategy protecting
mission-critical transit technology systems deployed across major North American
cities.
• Ownership of INIT's risk management, governance, and compliance program across
PCI DSS, SOC2, and ISO 27001.
• A collaborative team environment working with IT Operations, IT Systems
Engineering, and software development teams.
• Support for professional development and advancement toward executive-level
security certifications.
• A hybrid work model with flexibility for remote work combined with meaningful
in-person collaboration.
Benefits
We offer a comprehensive benefits package designed to support your health,
financial well-being, and work-life balance, including:
* Competitive paid time off, starting with 15 days of vacation, increasing with
tenure, plus 11 paid holidays, a personal day, and a community service day
<ul><li>6 paid sick days annually</li><li>Paid parental leave</li><li>100% employer-paid health and dental insurance for employees, with generous</li></ul>
dependent coverage contributions
<ul><li>401(k) with company match (currently dollar-for-dollar up to 5% of salary)</li><li>Company-paid life insurance, plus short-term and long-term disability</li></ul>
insurance
* Flexible Spending Accounts (medical, dependent care, and limited FSA options)
with employer contributions for eligible medical plans
<ul><li>Annual benefit allowance for optional employee benefits</li><li>Continuing education assistance and support for professional development</li><li>Optional benefits including accident insurance, legal services, identity</li></ul>
theft protection, adoption assistance, education assistance, and student loan
repayment assistance
Compensation
The annual salary range for this position is $125,000 -$150,000, depending on
experience.
INIT Innovations in Transportation, Inc. is an equal opportunity employer. All
qualified applicants will receive consideration for employment without regard to
race, color, religion, sex, national origin, disability status, protected
veteran status, or any other characteristic protected by law.
<p></p>
Details
| Company | INIT Innovations in Transportation, Inc. |
| Location | United States |
| Type | FULL TIME |
| Niche | general |
| Experience | full-time |
