Senior Information Security Lead

Posted today

genesis capitalLos Angeles (CA)

SENIORITY

Manager

SALARY

$125,000 per year

Apply

About the role

Genesis Capital (the “Company”) is one of the largest business purpose lenders in the country, focused on providing commercial real estate financing solutions to real estate developers who buy, renovate, and sell single-family and/or multi-family residential real estate. The Company is a subsidiary of Rithm Capital (parent company), a publicly traded mortgage real estate investment trust. The Senior Information Security Lead is a hands‑on senior individual contributor responsible for designing, operating, and governing Genesis Capital’s network and information security controls across a hybrid environment (Microsoft 365, Azure, AWS, and on‑prem). This role serves as the primary security control owner and internal audit gatekeeper for security‑relevant IT General Controls (ITGCs), including responsibility for SOX audit readiness, evidence quality, deficiency remediation, and risk exception governance. The position combines deep technical execution with independent judgment, strategic thinking, documentation rigor, and executive‑level communication, without managing a team.
Principal Duties: ESSENTIAL FUNCTIONSinclude the following. Other duties may be assigned. Network Security (Hands‑On Ownership) Design, configure, and maintain enterprise network security controls, includingPalo Alto firewalls, rulebases, segmentation, and secure connectivity patterns. Own and operate theNetskope Zero Trust / SSEplatform, including access policies, data protection rules, and monitoring. Define and enforce network security standards (Zero Trust principles, segmentation, logging, egress controls) and validate adherence through configuration reviews and monitoring. Perform regular firewall, SSE, and network control reviews to identify risk, over‑permissive access, and audit exposure. Vulnerability & Configuration Risk Management Own the vulnerability management lifecycle usingQualys, including scan coverage, severity thresholds, remediation SLAs, and verification. Assign and track remediation actions across IT teams; independently validate closure through rescans and evidence review. Govern patching and hardening outcomes across infrastructure and cloud services, ensuring results meet security and audit requirements. Enforce security‑related change control expectations, including documentation quality and emergency change review. Information Security Controls & Governance Enforce information security policies acrossMicrosoft 365, Azure, AWS, and on‑premise systems, translating policy into enforceable technical controls. Conduct security risk assessments for new systems, architecture changes, and third‑party integrations; document risks and required controls. Operate and continuously improve security monitoring and alerting (includingSIEMtooling where applicable). Research emerging threats and technologies and recommend security improvements aligned to business risk. SOX & Internal Audit Gatekeeper Act as thesingle point of contactfor internal and external auditors forSOX and security‑related audits. Serve asnamed control ownerfor assigned security and infrastructure ITGCs, with responsibility for: Control design and documentation (narratives, procedures, evidence standards) Evidence completeness, accuracy, and timeliness Walkthroughs and auditor inquiries Deficiency analysis, remediation planning, and validation of closure Maintain audit‑ready documentation and evidence repositories throughout the year. Risk Exception & Decision Authority Act as thesecurity approval authorityfor exceptions, compensating controls, and risk acceptances. Document business justification, compensating controls, and expiration dates for accepted risks. Escalate material or systemic risks to executive leadership with clear impact analysis and recommendations. Incident Response, DR & Resilience Lead technical incident response activities, including containment, root‑cause analysis, and corrective action tracking. Maintain incident response and disaster recovery documentation; coordinate testing, tabletop exercises, and lessons learned. Access Governance & Security Awareness Conductperiodic phishing simulation testingand analyze results to drive targeted remediation. Conductquarterly User Access Reviewsfor SOX‑scoped applications and ensure timely remediation of findings. Review identity, access, and protection reports to identify control weaknesses and audit exposure. Reporting & Executive Communication Prepare clear, executive‑level reporting on: Risk posture Vulnerability trends and mitigations Audit status and findings Control effectiveness and exceptionsEducation and ExperienceTo perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. Bachelor’s degree in Computer Science or related field, or equivalent experience. 7+ yearsof progressive experience in network security and information security within a regulated or sensitive environment (financial services strongly preferred). Hands‑on experience securingMicrosoft 365, Azure, AWS, and hybrid/on‑prem environments. Strong expertise withfirewalls, zero trust, and vulnerability management Strong knowledge of Windows/Linux, VMWare, SQL Server, Active Directory, and networking. Demonstrated experience acting asprimary audit contact and control ownerfor SOX or similar regulatory audits. Working knowledge ofISO 27000, SOX, PCI, and GLBAcontrol expectations. Experience with Juniper and Cisco/Meraki network switches, a plus. Excellent written and verbal communication skills, including audit‑ready documentation and executive briefing Ability to manage IT projects and support strategic initiatives. Hands‑on experience with SIEM systems and open‑source security tools. Security certifications (preferred): CISSP, CISM, CCSP, or equivalent.
Additional Skills Required: Independent ownership and accountability Strong risk‑based judgment and business acumen Ability to say“no”and document defensible decisions Detail‑oriented with audit‑quality rigor Comfortable operating as asenior individual contributor authoritywithout formal management responsibilities While this description is intended to be an accurate reflection of the position’s requirements, it in no way implies/states that these are the only job responsibilities. Management reserves the right to modify, add or remove duties and request other duties, as necessary. _By applying to this position candidate acknowledges that this is not a remote role and is required to be on-site._
Compensation Range: $125,000 - $180,000/annual Equal Employment Opportunity We’re proud to be an equal opportunity employer- and celebrate our employees’ differences, including race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, and Veteran status. Different makes us better. CA Privacy Policy CA Notice at Collection

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this