1

Director Offensive Security Engineer Jobs in Utah

You will work closely with Executives, Product, Engineering, and Security Leaders to drive and ... As a Director, Tech Leads you will: Organizational Leadership * Hire, onboard, develop, and retain ...

Reporting to the Chief Information Security Officer (CISO), the Vice President, Deputy Chief Information Security Officer (Deputy CISO) is the direct people manager for Security Engineering, Security ...

Reporting to the Chief Information Security Officer (CISO), the Vice President, Deputy Chief Information Security Officer (Deputy CISO) is the direct people manager for Security Engineering, Security ...

Techops Engineer -Senior Level

Farmington, UT · Remote

$99K - $136K/yr

... security, and automation backbone of our contact center technology platform. This is a high-impact ... ACD Direct, Inc. is an innovative, virtual company that thrives on brokering solutions for our ...

... security, and automation backbone of our contact center technology platform. This is a high-impact ... ACD Direct, Inc. is an innovative, virtual company that thrives on brokering solutions for our ...

Showing results 41-60

Director Offensive Security Engineer information

What is the difference between Director Offensive Security Engineer vs Security Architect?

AspectDirector Offensive Security EngineerSecurity Architect
CertificationsOSCP, CISSP, CEHCISSP, SABSA, TOGAF
Work EnvironmentLeading offensive security teams, penetration testing, red teamingDesigning security frameworks, architecture, and policies
Employer & Industry UsageTech companies, cybersecurity firms, government agenciesOrganizations seeking secure infrastructure, enterprise IT

The main difference is that the Director Offensive Security Engineer focuses on offensive security operations like penetration testing and red teaming, while the Security Architect designs overall security frameworks and infrastructure. Both roles require certifications like CISSP, but their responsibilities and focus areas differ significantly.

How much do Director Offensive Security Engineers make?

Director Offensive Security Engineers typically earn between $130,000 and $200,000 annually, depending on experience, certifications, and the size of the organization. They often oversee security teams, develop penetration testing strategies, and require advanced skills in cybersecurity tools and methodologies.

What are the most commonly searched types of Offensive Security Engineer jobs in Utah?

The most popular types of Offensive Security Engineer jobs in Utah are:

What are popular job titles related to Director Offensive Security Engineer jobs in Utah?

For Director Offensive Security Engineer jobs in Utah, the most frequently searched job titles are:

What job categories do people searching Director Offensive Security Engineer jobs in Utah look for?

The top searched job categories for Director Offensive Security Engineer jobs in Utah are:

What cities in Utah are hiring for Director Offensive Security Engineer jobs?

Cities in Utah with the most Director Offensive Security Engineer job openings:

IT Security and Systems Engineer

SilencerCo, LLC

West Valley City, UT • On-site

$120 - $180/hr

Other

Posted 6 days ago


Key responsibilities

  • Lead readiness and ongoing compliance efforts for CMMC Level 2 and NIST SP 800-171 across multiple business units

  • Support SOC 2 and PCI DSS compliance activities, including evidence collection, control design, gap remediation, and audit coordination

  • Own security and infrastructure projects from scope definition to implementation, including vendor coordination and stakeholder communication


Job description

Location: West Valley City, UT.

Work Model: Onsite, Full-Time

Reports To: Senior IT Manager

Works Closely With: Chief Technology Officer

Scope: Shared services across multiple companies

Position Overview

SicoSyndicate is the shared services company behind SilencerCo, Zev Technologies, Unity Tactical, and other companies. We have a shared IT function that serves all businesses, and we are looking for the person who will drive security across all of them. You will be the subject matter expert for security and compliance company-wide, working under our Senior IT Manager and directly with our CTO.

This is a hands-on role on a small team. Security and compliance are your center of gravity, and this will be your primary responsibility. The systems engineering half of the title is real as well: you will work alongside our core IT team on infrastructure, systems, and technology initiatives that extend beyond security. If you want a role where you spend all your time writing policy and never touch the systems it governs, this is not it. If you want to own a compliance program and stay technically sharp across the whole environment, keep reading.

Key Responsibilities
  • Lead readiness and ongoing compliance for CMMC Level 2 and NIST SP 800-171 across our defense-adjacent business units
  • Support SOC 2 and PCI DSS efforts, including evidence collection, control design, gap remediation, and audit coordination
  • Own security and infrastructure projects end to end: scope them, build the plan, coordinate vendors and internal stakeholders, drive them to agreed timelines, and keep leadership informed on status and risk
  • Administer and improve security tooling: endpoint protection, identity and access management, SIEM, MFA, email security, vulnerability management, and logging
  • Run access reviews, security awareness training, phishing simulations, and incident response tabletop exercises
  • Write and maintain the policies, procedures, and system security plans that our frameworks require, and make sure they reflect what we actually do
  • Partner with business unit leaders on risk decisions, vendor reviews, and security questions from customers and partners
  • Work alongside the core IT team on systems and infrastructure initiatives beyond security, including Microsoft 365/Entra ID and identity administration, server and network projects, endpoint management, and other technology work that supports all business units
How We Work

First, we are lean. Everyone here contributes outside a narrow job description, and the people who do well see that as a chance to understand the whole environment rather than as a distraction.

Second, you will own outcomes, not task lists. Projects here come with real timelines, defined deliverables, and regular check-ins with your manager and business unit leadership. What they do not come with is someone standing over your shoulder deciding how you get there. We will agree on the what and the when. We expect you to surface risks early, keep stakeholders informed, and tell us when a date is going to move before it moves.

Third, you will report to our Senior IT Manager and work directly with our CTO on security strategy, framework roadmaps, and risk decisions. This is a small enough organization that your work is visible at the executive level and your recommendations get heard. That access comes with the expectation that you can communicate clearly with a non-technical audience and defend a position.

If you want a role where the path is handed to you, this is not a fit. If you want ownership with clear expectations and a manager who backs you up rather than second-guesses you, this is that role.

Required Qualifications
  • 8 to 12 years in IT with meaningful depth in security and compliance
  • Direct experience with at least one government contracting framework, ideally NIST SP 800-171 or CMMC
  • Working knowledge of at least one commercial framework such as SOC 2, PCI DSS, or ISO 27001
  • A track record of running projects from kickoff through completion on committed timelines, including ones you identified and proposed yourself
  • Strong general IT fundamentals: Windows and Linux Servers, Microsoft 365 administration, identity and access management, networking, and Windows and Mac endpoint management
  • CompTIA Security+ or equivalent certification
  • The judgment to know when a control needs to be enforced and when it needs to be adapted to how the business actually operates
  • Clear written communication. You will be producing documentation that both auditors and executives read.
Preferred Qualifications
  • CISA, CCSP, CySA+, or CMMC CCP
  • Experience supporting a company through a CMMC assessment
  • Manufacturing or regulated industry background
  • Familiarity with ITAR or EAR export control requirements
  • ERP exposure, particularly Odoo
  • Cloud security experience in AWS and Azure
Measures of Success

We evaluate this role on outcomes, not activity. In your first year, success means:

  • Our CMMC Level 2 gap assessment is complete, the System Security Plan is written, and we are executing against a plan with dates we can defend to an assessor
  • Security and compliance projects land on their committed timelines, and when a date has to move, leadership hears it from you in advance rather than after the fact
  • Critical and high vulnerabilities are remediated within defined windows, and we can show the trend
  • Our security policies reflect how the business actually operates, so people follow them instead of working around them
  • Business unit leaders come to you early on decisions with security implications, because you have made yourself useful rather than obstructive
#J-18808-Ljbffr