Platform Security Lead
Ion
Job Summary
ION Markets Information Security Team is seeking a Platform Security Lead to support the division's security strategy by defining and implementing security controls across platforms, infrastructure, and operational workflows. This role involves designing and implementing end-to-end security controls for ION Markets' on-premises infrastructure and internal platforms, focusing on security architecture, engineering, and operations with an emphasis on automation, detection, and secure by design principles. The lead will also be responsible for threat detection, incident response, and vulnerability management remediation, acting as both a technical leader and operational responder. Collaboration with Product, infrastructure, and Security Operations teams is essential. The ideal candidate is a hard-working, dedicated, and motivated individual with excellent communication skills, capable of cultivating strong working relationships with colleagues of varying technical abilities and driving career progression within a security team.
Must Have
- Serve as senior incident responder
- Collaborate on security incidents
- Conduct root cause analysis
- Enhance system visibility
- Maintain incident response runbooks
- Lead vulnerability management
- Support security architecture reviews
- Research security threats
- Perform threat hunting
- Develop SOPs for operations & architecture
Good to Have
- Degree/diploma/certifications in technology
- Relevant working experience
- Pen Test+, Security+, OSCP, CCSP, CEH, GCIH, GMON certifications
- Fundamental programming/scripting (Python, PowerShell, Bash)
- In-depth understanding of OS (Windows/Linux)
- Team player, able to work independently
- Ability to own and complete tasks
- Time management and prioritization skills
- Excellent communication skills (written/verbal)
- Exceptional attention to detail
- Excellent problem-solving skills
- Endpoint security concepts for Servers
- IT networking concepts and network security
- Cryptography fundamentals and data security
- Forensic investigation techniques
- Experience with security technologies (AV/EPP/EDR, SIEM, DLP, SWG, CASB, UEBA, IDS, IPS, firewalls, IAM/PIM/PAM, vulnerability management, MDM)
Job Description
- Serve as a senior incident responder, addressing emerging threats across the environment.
- Collaborate with infrastructure, network, and cross-functional teams to contain, investigate, and remediate security incidents.
- Conduct root cause analysis and participate in forensic investigations as needed.
- Enhance system visibility by expanding logging coverage and implementing additional monitoring capabilities.
- Maintain, update, and regularly test incident response runbooks, containment strategies, and escalation protocols.
- Lead the end-to-end vulnerability management process for ION Markets systems, from identification to remediation.
- Provide support for security architecture reviews of developed systems to ensure alignment with best practices.
- Stay up to date with the latest security threats, news, intelligence, tactics, techniques, and vulnerabilities; conduct research and analysis to assess potential impact and exposure.
- Perform proactive threat hunting activities, and manage the triage, investigation, and escalation of security alerts.
- Develop Standard operating procedures for operations & architecture activities.
Required Skills, Experience and Qualifications
- Degree/diploma/certifications in a technology-related field and/or relevant working experience; highly desired certifications include:
- Pen Test+, Security+, OSCP, CCSP, CEH, GCIH, GMON.
- 7+ years' experience in Information Security or Security Architecture roles.
- Must have fundamental programming/scripting capabilities (e.g. python, PowerShell, bash, etc.).
- Must have in-depth understanding of operating systems (Windows/Linux).
- A team player with the ability to work independently and unsupervised.
- Ability to own delegated tasks and see them through to completion.
- Ability to manage time and prioritize work to maximize productivity.
- Excellent communication skills (both written and verbal).
- Exceptional attention to detail and quality.
- Excellent problem-solving techniques and trouble analysis skills.
- Endpoint security concepts, controls, and best practices for Servers (e.g. Windows and Linux).
- General IT networking concepts, protocols, standards and network security concepts, controls, and best practices.
- Cryptography fundamentals and data security controls and best practices.
- Forensic investigation techniques.
- Prior experience deploying, configuring, managing, and/or operating security technologies is preferred, such as endpoint security (e.g. AV/EPP/EDR), SIEM, DLP, SWG, CASB, UEBA, IDS, IPS, firewalls, IAM/PIM/PAM, vulnerability management, MDM, etc.