We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Senior Cybersecurity Engineer

American National Standards Institute
$93,600 to $103,200
United States, New York, New York
25 West 43rd Street (Show on map)
Sep 24, 2026
Position Summary The Senior Cybersecurity Engineer manages the development and deployment of ANSI and ANAB information security products and services, designs and implements the security tools, systems and procedures that sustain the confidentiality, integrity and availability of the organization's data. It is the senior hands-on security engineering role: the person who turns the security roadmap into working, verifiable controls. The position reports to the Chief Information Security Officer (CISO) and works under the CISO's direction on security architecture, translating policy, risk decisions and business requirements into reference architectures, design patterns and solutions that can actually be built and operated in the ANSI / ANAB environment. Essential Functions Security Architecture and Design
  • Support the CISO in producing security architecture and design work: reference architectures, design patterns, security requirements and target-state designs for ANSI / ANAB [cloud] infrastructure, applications and cloud environments.
  • Develop tactical-level technical requirements, architectural designs and procedures for the deployment of security tools and solutions, including tool selection, placement, integration with existing tooling, configuration and testing.
  • Design, develop, engineer and implement security solutions from requirements through production.
  • Ensure the soundness of the integrated security solution as a whole, identify gaps, and adapt reference architectures to the local environment rather than deploying them unchanged.
  • Develop end-to-end programs and service offerings for new and existing security tools and technologies, including alignment to reference architectures, configuration guides, tool applications, health status checks, management guides and test plans.
  • Lead the evaluation and introduction of new methodologies or tooling that measurably improve the security of platforms, infrastructure or access to data.
  • Develop comprehensive plans, goals and objectives covering the full cybersecurity lifecycle of a project.
Engineering, Deployment and Control Assurance
  • Configure security tools and solutions for deployment, and assess tool capability, performance and effectiveness after deployment not only at selection.
  • Administer security controls and review their application, confirming that controls, policies and procedures operate as effectively in practice as their design assumes.
  • Enforce compliance with security policies and standards across systems, projects and third parties.
  • Drive down risk: identify systemic risk and non-compliance issues, define action plans and track them through closure.
  • Contribute to improvements in information security KPIs and KRIs.
  • Create and maintain technical documentation, processes and procedures for security tools and systems, and actively review existing SOPs and documentation for areas of improvement.
  • Stay informed on attack trends, zero-day vulnerabilities, adversary methodologies and emerging risks, and translate them into concrete design and configuration changes.
Supervision and Technical Leadership
  • Review output of the Junior Cybersecurity Engineer (Junior Security Analyst), before it is escalated or published, and give structured feedback.
  • Provide technical mentorship to the junior role.
  • Act as the technical escalation point for security investigations, incident response and overall security matters.
  • Represent security's interests in technical forums, change advisory boards, project design reviews, and deputize for the CISO on technical matters when required.
Key Performance Indicators
  • Design Quality and Reuse: security designs and reference architectures are accepted by the CISO with minimal rework and are reused across subsequent projects rather than rebuilt each time.
  • Documentation Quality: produces clear, well-structured and accurate technical documentation, standards and procedures that are published with minimal editing by the CISO.
  • Solution Delivery: security tooling and solutions are deployed on schedule, fully configured, documented, and validated as effective after deployment.
  • Risk Reduction: systemic risks and non-compliance items are identified, actioned and closed within agreed timeframes, with measurable movement in the agreed security KPIs and KRIs.
Internal ANSI / ANAB Information Security Responsibilities * Attend/complete assigned information security training by the designated completion date. * Read and adhere to published ISMS policies and procedures. * Report timely any observed violations of ISMS policy - or known encroachments on information security - to your department leader and/or the Information Technology Department. Education and Experience
  • Advanced degree in information security, computer science, engineering, mathematics or a related field of study, plus a minimum of 10 years of progressive and related information security work experience in regulated or standards-driven industries.
  • A minimum of 8 to 10 years of hands-on experience in security engineering, cybersecurity architecture, host and network security, host and endpoint technologies, network detection, incident response or IT security tool deployment. Prior experience supervising or formally mentoring at least one junior engineer or analyst is strongly preferable.
  • Professional security certification CISSP, CISM, CCSP, CCSK is preferred.
Other Qualifications
  • Understands that ANSI and ANAB operate as a standards and accreditation body, where continuity of service and the trust of members and accredited bodies are the assets being protected.
  • Able to present a design, its risk and its cost in terms an executive audience can act on, and to weigh security requirements against operational and budget constraints, recommending a defensible position rather than an absolute one.
  • Knowledgeable in Secure / Cloud-based architecture design and management. Infrastructure security automation, infrastructure capacity monitoring and automated scaling.
  • Knowledgeable with DevSecOps, automation of security integration with application code deployment (Jenkins, Maven, Git, Nexus or equivalents). Automation and configuration management frameworks.
  • Understanding of main IAM concepts (PKI, certificate and key management best practice). Endpoint and network security, SIEM/SOC incident response processes.
  • Working knowledge of security and risk frameworks preferred, NIST CSF, NIST SP 800-53, ISO / IEC 27001 and 27002, CIS Controls and the ability to use them as design input rather than as a checklist. Familiarity with secure SDLC, threat modeling, business continuity and IT disaster recovery.
  • Comfortable delivering within given deadlines.
  • Sound problem resolution, judgment, negotiation and decision-making.
  • Able to explain a technical design to a non-technical stakeholder and defend it to a technical one.
  • Clear technical writing.
  • Able to handle confidential and sensitive information with discretion.
  • Availability outside standard business hours during security incidents, scheduled maintenance and change windows or audit deadlines.
  • Willing to act as the senior technical point of contact for security in the absence of the CISO.
Starting compensation will be in the $93,600 to $103,200 range, depending on education, experience, and other qualifications.
This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities and activities may change or new ones may be assigned at any time with or without notice. ANSI provides equal employment opportunities to all employees and applicants for employment, and prohibits discrimination of any type because of race, gender identity or expression, color, national origin or ancestry, religion, creed, age, marital status, sex, sexual orientation, citizenship or authorized alien status, genetics, disability status, protected veteran status, or any other consideration protected by federal, state, or local laws. ANSI policy also prohibits unlawful discrimination based on the perception that anyone has any of those characteristics. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Important Notice for Job Seekers: Protect Yourself from Fraudulent Job Postings We are aware of fraudulent job postings falsely claiming to represent our company. These scams may mirror our legitimate job listings and direct candidates to fake interview links or request personal information. Here's how to spot legitimate opportunities:
  • Verify jobs at www.ansi.org
  • Apply through our official Workday system at https://ansi.wd1.myworkdayjobs.com/ANSI_Careers
  • We won't ask for an interview via Zoom links or texts.
  • We would never ask for payment
  • We won't ask for sensitive, personal information early in an application process.
  • All communication comes from official company emails (@ansi.org).
We prioritize your security and use only official channels. If you see a suspicious posting, please report it to the job board.
Applied = 0

(web-9db6c7984-ddcg9)