Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com

QTG - Cybersecurity, Cyber Strategy & Risk - Manager, Cybersecurity Engineering

Questrade Financial Group
🇮🇱 Israel
On-site
Manager or above
19 hours ago
  • Regulatory Compliance
  • Threat Modeling
  • Design Systems
  • triage
  • DevSecOps
  • Devops
  • OWASP
  • Microservices
  • GCP
  • AWS
  • Azure
  • Kubernetes
  • Secrets Management
  • Machine Learning
  • CISSP
  • CSSLP
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

What’s in it for you as an employee of QFG?

  • Health & wellbeing resources and programs
  • Paid vacation and personal days for work-life balance
  • Competitive compensation and benefits packages
  • Work-life balance
  • Career growth and development opportunities
  • Opportunities to contribute to community causes
  • Work with diverse team members in an inclusive and collaborative environment

We’re looking for our next Manager, Cybersecurity Engineering. Could It Be You?

As the Manager of Cybersecurity Engineering, you will lead and grow a team of security architects dedicated to embedding security into our engineering culture in alignment with our regulatory compliance requirements as a Financial Services provider. Reporting to the Director of Cyber Strategy & Risk, you will own the team's technical direction and its impact on the organization's overall security posture – spanning architecture oversight and threat modeling, legacy system risk, security guardrails and automation, and M&A security diligence. You will balance technical leadership with people management, establishing your team as a trusted consultative partner that enables safe innovation across cloud-native financial platforms, legacy systems, and corporate integrations.

The Manager, Cybersecurity Engineering is a champion for putting the customer first and has a deep passion in understanding customer behaviour. They will create lifecycle journeys to improve the customer experience, engagement and retention as we deliver on our promise to help customers keep more of their money as they become more financially successful and secure.

Need more details? Keep reading…

In this role, responsibilities include but are not limited to:

  • Lead and Develop Technical Talent: Hire, coach, and grow a team of application security architects, including senior individual contributors such as Principal Application Security Architects. Set clear goals, provide regular feedback, and build career growth paths for direct reports.
  • Provide Cybersecurity Architecture Advisory & Consultation: Serve as the primary security architecture consulting team across all Questrade business entities, delivering strategic and technical security guidance during product design, technology selection, and platform modernization.
  • Define and Maintain Security Architecture Patterns: Establish, maintain, and promote enterprise security architecture patterns, reference designs, and technical security standards to guide engineering teams in building secure-by-design systems.
  • Provide Technical Oversight on Architecture and Threat Modeling: Oversee and sign off on reference architectures, solution threat models, and security patterns produced by the team for critical systems, including API security, Agentic AI security, NHI and service-to-service authentication, secure data handling, and hybrid multi-cloud & on-premises network and identity architecture. 
  • Perform Security Architecture Assessments and Own Remediation Initiatives: Direct assessments of proposed and existing solution designs to identify architectural gaps, technical debt, and security risks, providing actionable and pragmatic recommendations through validation of remediations.
  • Partner Across Engineering Leadership: Serve as the primary point of contact between the CISO organization and engineering leadership on security architecture, building trusted relationships with development, architecture, and product teams to embed security early in the design process.
  • Prioritize and Resource Engagements: Triage incoming architecture reviews, threat modeling requests, and legacy system assessments across the team, balancing competing product demands against risk.
  • Oversee Legacy System Risk Programs: Direct efforts to map architectures, uncover hidden risks, and promote modernization and risk mitigation strategies for critical legacy systems and other entities lacking formal security architecture documentation.
  • Support M&A Security Diligence: Oversee architectural security due diligence for M&A targets, ensuring architectural debt and technical integration risks are clearly identified and quantified for leadership.
  • Represent Security to Leadership: Present program strategy, risk posture, and technical updates to senior and executive leadership, building consensus around investment and priorities.
  • Manage Team Operations: Own budget planning, tooling and vendor evaluation, and performance management for the Cybersecurity Engineering team.

 

So are YOU our next Manager, Cybersecurity Engineering? You are if you…

  • A Foundation in Engineering Leadership: 10+ years of technology experience, including a significant background in software engineering, solutions architecture, and DevSecOps/DevOps/SRE, with a deep understanding of how modern applications are designed, built, and deployed.
  • People Management Experience: 3+ years directly managing or formally leading technical teams, ideally including senior architects or principal-level engineers, with a track record of hiring, developing, and retaining strong technical talent.
  • Financial Services / Multi-Entity Experience: Prior experience providing security advisory in regulated environments, multi-entity corporate structures, or financial technology platforms is preferred.
  • Deep Application Security Expertise: 5+ years in application, product, or cloud security architecture, with the ability to evaluate and guide architectural mitigations for OWASP Top 10 and design-level vulnerabilities in a microservices architecture.
  • Cloud Security Architecture: Demonstrated experience defining architecture patterns and conducting security assessments in cloud-native platforms, specifically Google Cloud Platform (GCP); familiarity with AWS or Azure is beneficial.
  • Expertise in Securing Distributed Systems: Strong understanding of security design patterns for microservices architectures, containerized environments (Kubernetes), and event-driven systems, including API gateways, service mesh concepts, secrets management, and network policies.
  • Pragmatic Threat Modeling Expertise: Proven background leading and overseeing architectural threat modeling exercises (e.g., STRIDE or similar frameworks) across cloud-native and distributed environments, and translating theoretical threats into actionable architecture guardrails and engineering requirements.
  • Emerging Technologies: Familiarity with secure architecture considerations for Generative AI integration, agentic workflows, and modern data platform architectures.
  • Excellent Communication and Influence: Exceptional ability to articulate complex technical risks and solutions to both senior engineers and executive stakeholders to drive consensus and prioritization.
  • Budget and Vendor Management: Experience managing team budgets and evaluating security tooling or vendor relationships is a plus.
  • Relevant security, application security, and security architecture certifications (e.g., CISSP, CSSLP, GIAC) are beneficial.

 

Sounds like you? Click below to apply!

QTG - Cybersecurity, Cyber Strategy & Risk - Manager, Cybersecurity Engineering · Questrade Financial Group

Auto apply with Likeremote