Sr Director of Cybersecurity Engineering

Blue YonderScottsdale, AZ
$186,288 - $241,702Remote

About The Position

Blue Yonder is looking for a Senior Director of Cybersecurity Engineering to lead the teams that design, build, and operate the technical security controls protecting our multi-cloud SaaS platform and the supply chains it powers. This is a builder-leader role at the point where three disciplines meet: engineering systems, security controls, and regulatory expectations. The right leader is deeply fluent in all three and — critically — able to bring clarity and structure across them, translating dense control frameworks and audit obligations into engineering that scales, and translating engineering realities back into terms that satisfy auditors, regulators, and customers. You will own the roadmap and delivery for Cloud & Infrastructure Security Engineering, Identity & Access Engineering, and Product / Application Security with opportunities for further growth, so you should be someone who can architect for the future without over-building for it today. This role demands genuine depth in Azure security engineering — not familiarity, but the kind of hands-on-adjacent fluency that lets you set technical direction, review architecture, and hold your teams to a high bar.

Requirements

  • 12+ years (10 years+ in cybersecurity, with a substantial portion in security engineering, cloud security, or platform security roles.
  • 6+ years leading security engineering teams, including experience leading managers (leader-of-leaders), in a fast-moving SaaS or cloud-native environment.
  • Deep, hands-on-adjacent Azure security expertise — you can set architecture direction, review designs, and hold engineering teams to a high technical bar. Working knowledge of a broader multi-cloud estate (AWS / GCP / OCI) expected.
  • Demonstrated fluency across the intersection of engineering systems, security controls, and regulatory frameworks — and a track record of bringing clarity and structure where those three collide.
  • Strong command of modern security engineering domains: cloud security posture and workload protection, identity and access, application/product security, and secure infrastructure/IaC.
  • Experience operating in an audited environment (SOC 2 and/or ISO 27001 or equivalent), with a real understanding of how controls become evidence.
  • Excellent executive communication: able to make complex technical and regulatory topics legible to engineers, executives, auditors, and customers alike.

Nice To Haves

  • Experience supporting or achieving FedRAMP, CMMC, or other regulated/public-sector frameworks.
  • Hands-on experience with a mature security tooling stack — e.g., CNAPP/CSPM, EDR, IGA/PAM, DSPM, SIEM, and cloud-native security services (Microsoft Defender / Purview).
  • Background in identity governance and Zero Trust at enterprise scale.
  • Prior experience standing up or maturing Detection Engineering and/or Threat & Vulnerability Management functions.
  • Relevant certifications such as CISSP, CCSP, or Azure security certifications.
  • Engineering or software development background earlier in career.

Responsibilities

  • Lead and scale the engineering organization
  • Own strategy, roadmap, and delivery across Cloud & Infrastructure Security Engineering, Identity & Access Engineering, and Product / Application Security.
  • Lead a multi-team organization of managers and senior individual contributors; hire, develop, and retain top security engineering talent in a remote-first model.
  • Set clear technical standards, engineering practices, and outcomes; build the operating cadence, metrics, and prioritization discipline that let the teams ship reliably.
  • Architect the organization to absorb adjacent functions (e.g., Detection Engineering, Threat & Vulnerability Management) over time without disruption.
  • Set the technical direction for securing Blue Yonder's Azure-centered multi-cloud environment (Azure primary; AWS, GCP, and OCI in scope).
  • Drive secure-by-default patterns, guardrails, and platform-level controls across network, compute, runtime, data, and identity layers.
  • Oversee cloud security posture management, workload protection, secrets and key management, and infrastructure-as-code security.
  • Own the engineering behind identity governance, authentication, authorization, privileged access, and lifecycle/joiner-mover-leaver automation.
  • Advance a Zero Trust access model across workforce and workload identities.
  • Reduce standing privilege and drive toward least-privilege, auditable access at scale.
  • Embed security into the SDLC — threat modeling, secure design review, SAST/DAST/SCA, and remediation workflows that developers can actually adopt.
  • Partner with Product and Engineering to shift security left while maintaining velocity.
  • Establish and track application security posture and risk-reduction outcomes.
  • Ensure engineered controls map cleanly to Blue Yonder's compliance obligations (ISO 27001, 27701, 22301, 42001; SOC 1 / SOC 2; ITGC) and produce durable, test-ready evidence.
  • Support the certification and roadmap ambitions of the business, including public-sector and regulated frameworks (e.g., FedRAMP, CMMC).
  • Serve as the engineering authority in audits, customer security reviews, and regulatory conversations — turning control requirements into implemented, attestable engineering.
  • Partner closely with GRC, Security Operations, Product, Platform Engineering, and Customer Trust to align security engineering with enterprise risk and customer commitments.
  • Communicate posture, risk, and progress clearly to executive leadership and, when needed, to customers.

Benefits

  • Comprehensive Medical, Dental and Vision
  • 401K with Matching
  • Flexible Time Off
  • Corporate Fitness Program
  • A variety of voluntary benefits such as; Legal Plans, Accident and Hospital Indemnity, Pet Insurance and much more
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service