Lead InfoSec Engineer
Who We Are:
Aspenware empowers mountain resorts and ski areas to deliver the ideal digital guest experience. Our guest-facing e-commerce and registration software is the most capable in the industry and is used by millions of skiers worldwide to process over a billion dollars in annual sales. The resorts we work with trust the innovation and thought leadership that Aspenware provides, and they leverage the operational advantages of our platform to grow their businesses.
We are a talented and high-performing team and welcome the opportunity to learn from one another.
Aspenware makes hiring decisions based on how well candidates align with our Core Values. Aspenware employees areβ¦
- Dependable: We take ownership. We are accountable and adaptable. We have a can-do attitude and are willing to pivot.
- Caring: We care about our co-workers and our clients. We are mindful of and inspired by the impact our work has on our communities.
- Innovative: We are thought leaders who bring creativity and a desire for innovation to everything we do. We are continually improving ourselves and our surroundings.
- Curious: We challenge default processes while assuming best intent, seeking to understand before judging. We ask good questions to spark learning, better decisions, and smarter outcomes. We make the extra effort to gain a deeper understanding of a situation so we can provide better solutions.
The Role:
The Lead Infosec Engineer will be responsible for leading Aspenware βs existing security program and optimizing it to be even more robust.
You will manage Aspenware βs security operations including IT vendor and MSSP relationships. You will lead efforts to mitigate existing and emerging cybersecurity threats. You will assess, prioritize, and remediate security risks to improve Aspenware βs overall cybersecurity posture.
This is a key role at Aspenware and reports to the Director of Technology Operations & Security. You will work closely with the VP of Technology, other engineering leaders, and business stakeholders to represent the security needs of our platform and hold the enterprise to a rigorous standard of security. Finally, you will collaborate with the Infosec teams at our parent company, Alterra Mountain Co. You will be responsible for sharing strategies, roadmap progress, and incident retrospectives wherever the larger enterprise is impacted.
What You Will Do:
- Partner with engineering teams and systems architects to ensure the security of our products, cloud infrastructure, and technical platform
- Be the champion of rigorous security standards when debating resource allocation tradeoffs
- Improve Aspenware βs AppSec and SDLC security
- Understand key security attack vectors and protect Aspenware from malicious actors who wish to abuse our system.
- Manage our security vendor relationships with respect to requirements and technical support
- Lead the company from its recently earned Type I SOC 2 accreditation through Type 2 accreditation.
- Assist end users to remediate security issues.
- Work with external vendors to provide oversight for computers, devices, and networks in a remote work environment
- Manage and evaluate external vendors to conduct pen testing, endpoint testing, purple team testing, and PCI scans
- Develop and document network security reference architectures, design patterns, roadmaps, and other architectural artifacts aligned with policies, standards, and industry best practices
- Work closely with our DevOps team to manage cloud security in Azure:
- Evaluate Azure cloud and hybrid security services, tools, and appliances in the areas of (but not limited to): intrusion detection, intrusion prevention, packet capture, and quarantine
- Assess network/cloud security posture and recommend modifications for enhancements, improvements, and mitigations
- Collaborate with enterprise partners and incident response teams regarding requirements and deployment of sec