yandex
point72
Страна
США
Зарплата
200 000 $ – 300 000 $
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
LeadВ офисеПолная занятость

Linux Security Lead

Оценка ИИ

Исключительная вакансия в престижном хедж-фонде с очень высокой базовой зарплатой, отличным соцпакетом и возможностью влиять на глобальную инфраструктуру.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
Оценка ИИ

Высокая сложность обусловлена необходимостью глубоких знаний ядра Linux, опыта работы с комплаенс-фреймворками (NIST, CIS) и навыков автоматизации через Ansible в условиях финансового сектора.

Анализ зарплаты

Медиана225 000 $
Рынок185 000 $ – 275 000 $
Оценка ИИ

Предложенный диапазон $200,000–$300,000 находится на верхнем уровне рынка для позиций Security Lead в Нью-Йорке, значительно превышая средние показатели по отрасли.

Сопроводительное письмо

I am writing to express my strong interest in the Linux Security Lead position at Point72. With over six years of experience in Linux systems and a deep specialization in security hardening, I have a proven track record of implementing automated drift detection and enforcing CIS Benchmarks across complex, hybrid environments. My expertise in Ansible and infrastructure-as-code aligns perfectly with your goal of building scalable, version-controlled delivery patterns.

In my previous roles, I have successfully integrated vulnerability signals into access policies and managed exception governance with a focus on reducing MTTR. I am particularly drawn to Point72’s commitment to leveraging modern cloud architectures and AI to drive smarter decision-making. I am confident that my technical authority in kernel hardening and secure engineering principles will significantly contribute to maintaining a robust security posture for your multi-billion-dollar global business.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в point72 уже сейчас

Присоединяйтесь к лидеру индустрии хедж-фондов и возглавьте направление безопасности Linux в глобальном масштабе!

Описание вакансии

A Career with Point72’s Technology Team

As Point72 reimagines the future of investing, our Technology team is constantly evolving our firm’s IT infrastructure and engineering capabilities, positioning us at the forefront of a rapidly evolving technology landscape. We’re a team of experts who experiment and work to discover new ways to harness open-source solutions, modern cloud architectures, and sophisticated Artificial Intelligence (AI) solutions, while embracing enterprise agile methodologies. Our commitment to building and innovating in the AI space provides the framework intended to drive smarter decision making and enhance how we build and operate our platforms and applications.

As a member of Point72’s Technology team, we encourage and support your professional development from day one—helping you advance your technical skills, contribute innovative ideas, and satisfy your own intellectual curiosity—all while delivering real business impact for our multi-billion-dollar global business

What you’ll do

As the Linux Security Lead, you will own and drive a consistent and enforceable security posture across the firm's Linux fleet — building enforceable baselines, automated drift detection, and verified remediation patterns that scale across a hybrid on-premises and cloud environment. You will report directly to the Head of Infrastructure Security and serve as the technical authority for Linux hardening, operating within a sprint-based engineering discipline and working closely with the Linux Infrastructure team. Specifically, you will:

  • Own the Linux security baseline program end-to-end, including defining hardening intent per distribution and workload class (RHEL, Ubuntu, Amazon Linux), enforcing standards through Ansible and configuration management tooling, and driving continuous drift reconciliation.
  • Build and operate automated drift detection workflows by translating desired state into enforcement, generating alerts with remediation paths, and reducing MTTR for high-risk deviations.
  • Integrate Linux posture signals, including compliance state, vulnerability exposure, and audit telemetry, into broader access policy and detection pipelines.
  • Partner with security automation teams to build scalable, version‑controlled delivery patterns with validation and rollout safeguards.
  • Maintain exception governance discipline, such as time-bounded exceptions with explicit ownership, compensating controls, and regular burn-down reviews.
  • Drive verified vulnerability closure for Linux-specific exposure classes
  • Establish and embed Linux-specific secure engineering principles, such as least privilege daemons, immutable configuration patterns, kernel hardening, and audit telemetry standards, into engineering standards and peer review processes.
  • Contribute to the firm's broader CIS Benchmark compliance posture, maintaining mappings to CIS Controls v8 and NIST CSF 2.0 for audit and regulatory defensibility.

What’s required

  • 6+ years of experience in Linux system administration or security engineering, with at least 3 years focused on Linux security hardening and compliance in an enterprise environment.
  • Demonstrated expertise with configuration management tooling, specifically Ansible, and infrastructure-as-code practices, including version control, peer review workflows, and pipeline-driven enforcement.
  • Hands-on experience with CIS Benchmarks for Linux (RHEL, Ubuntu, or equivalent) and familiarity with the NIST Cybersecurity Framework (CSF 2.0) and STIG compliance frameworks.
  • Proven ability to build and operate drift detection and reconciliation tooling, as well as experience with Qualys, CrowdStrike, or equivalent endpoint monitoring platforms.
  • Working knowledge of Linux kernel security features such as SELinux or AppArmor, auditd, system hardening, privilege separation, and secure boot patterns.
  • Experience operating in an engineering delivery model, specifically with sprint cadence, backlog prioritization, Definition of Done tied to verification, and peer review for high-impact changes.
  • Strong collaboration skills with the ability to define and maintain explicit interfaces with adjacent teams and communicate posture risk clearly to technical and non-technical stakeholders.
  • Commitment to the highest ethical standards.

We take care of our people

We invest in our people, their careers, their health, and their well-being. When you work here, we provide:

  • Fully-paid health care benefits
  • Generous parental and family leave policies
  • Mental and physical wellness programs
  • Volunteer opportunities
  • Non-profit matching gift program
  • Support for employee-led affinity groups representing women, minorities and the LGBT+ community
  • Tuition assistance
  • A 401(k) savings program with an employer match and more

About Point72

Point72 Asset Management is a global firm led by Steven Cohen that invests in multiple asset classes and strategies worldwide. Resting on more than a quarter-century of investing experience, we seek to be the industry’s premier asset manager through delivering superior risk-adjusted returns, adhering to the highest ethical standards, and offering the greatest opportunities to the industry’s brightest talent. We’re inventing the future of finance by revolutionizing how we develop our people and how we use data to shape our thinking. For more information, visit www.Point72.com/working-here

The annual base salary range for this role is $200,000-$300,000 (USD), which does not include discretionary bonus compensation or our comprehensive benefits package. Actual compensation offered to the successful candidate may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level, among other things.

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • Linux
  • Ansible
  • Cybersecurity
  • Infrastructure as Code
  • SELinux
  • AppArmor
  • Qualys
  • CrowdStrike
  • RHEL
  • Ubuntu
  • Amazon Linux
  • NIST CSF
  • CIS Benchmarks
  • Auditd

Возможные вопросы на собеседовании

Проверка практического опыта внедрения стандартов безопасности.

Расскажите о вашем опыте внедрения CIS Benchmarks в крупной организации: с какими основными трудностями вы столкнулись при автоматизации этого процесса?

Оценка навыков работы с инфраструктурным кодом и предотвращения отклонений.

Как бы вы спроектировали систему автоматического обнаружения и устранения дрифта конфигураций (drift detection) для парка из нескольких тысяч серверов?

Проверка глубоких технических знаний ОС.

В каких случаях вы бы предпочли использование SELinux вместо AppArmor, и как вы подходите к отладке политик безопасности в высоконагруженных системах?

Оценка умения работать в команде и управлять рисками.

Как вы находите баланс между строгими требованиями безопасности и потребностями команд разработки в гибкости и скорости доставки (Agile/DevOps)?

Проверка опыта управления уязвимостями.

Опишите ваш подход к приоритизации и закрытию уязвимостей в ядре Linux, когда стандартные патчи могут нарушить работу критически важных финансовых приложений.

Похожие вакансии

lucidmotors
23 $ – 32 $

Security Officer Team Lead

LeadВ офисеСША
Physical Security · Genetec · LifeRaft · Envoy · Microsoft Excel · Microsoft Outlook · Microsoft PowerPoint · Microsoft Word · Leadership · Incident Reporting · GSOC Operations
+11 навыков
point72
300 000 $ – 350 000 $

Identity and Entitlement Architecture Lead

LeadВ офисеСША
IAM · OAuth2 · OIDC · SAML · Okta · Microsoft Entra ID · Active Directory · OPA · AWS Cedar · XACML · Zero Trust · SCIM · Microservices · API
+14 навыков
point72
225 000 $ – 275 000 $

Tech Team Lead, Network Security

LeadВ офисеСША
Palo Alto Networks · Firewalls · VPN · SASE · WAF · IDS · IPS · Zero Trust Architecture · Micro-segmentation · AWS · Azure · GCP · PCI DSS · GDPR · HIPAA · CISSP · CCNP · Illumio · Zscaler · Vulnerability Management
+20 навыков
sofi
Не указана

Lead Insider Trust & Fraud Investigator

LeadГибридСША
SIEM · UEBA · DLP · EDR · Digital Forensics · Incident Response · Cybersecurity · Data Exfiltration Detection · Internal Controls
+9 навыков
accenturefederalservices
116 900 $ – 243 100 $

Cyber Defense Forensics (CDF) Lead

LeadВ офисеСША
Digital Forensics · Incident Response · SIEM · DLP · Windows · Linux · macOS · Cloud Computing · Malware Analysis · GCFA · GCFE · CISSP · CISM · Network Security · Endpoint Detection and Response
+15 навыков
accenturefederalservices
116 900 $ – 243 100 $

Cyber Threat Hunt (CTH) Lead

LeadВ офисеСША
Cyber Threat Hunting · SIEM · Cyber Threat Intelligence · Network Security Monitoring · Incident Response · Purple Teaming · CEH · DOD 8570 · TTPs · Endpoint Management Tools
+10 навыков
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!

point72
Страна
США
Зарплата
200 000 $ – 300 000 $