Live opening · Posted 9 days ago

Cyber Security Lead

HCS Serbia · Belgrade, Serbia (Remote)
Linkedin No
You are 9 days behind. JobBeeper subscribers saw this role while it was still new.

At a glance

The key details from the original listing.

Posted 9 days ago
CompanyHCS Serbia
LocationBelgrade, Serbia (Remote)
Work modeNo
SourceLinkedin
Listed9 days ago

Your early-applicant advantage

Live timing from JobBeeper.

Live data
15 min from Linkedin publishing this role to us finding it
6 min median time from a role going live to a subscriber being told
6 hours subscribers had this role before this page existed
71,889 roles found in the last 24 hours — the newest are not on this site yet
Start your free trial →

About the role

Description supplied by the original job listing.

🚀 We’re Hiring: Cyber Security Lead (Remote | Full‑Time | SaaS | AI‑Native Platform)
Company: FieldFlo, USA. Industry: Construction • Environmental Services • Demolition • SaaS •
FieldFlo is a fast‑growing, mobile‑first SaaS platform built for the construction, demolition, and environmental services industries. Teams across the U.S. rely on us daily for compliance, safety, time tracking, training, and seamless field operations. We’re backed by industry veterans and growing fast — this is your chance to directly influence a platform that keeps workers safe and projects running smoothly.
🌟 Role Summary: A growing share of our clients are prime contractors to the US federal government. That means FieldFlo processes Controlled Unclassified Information (CUI) and is executing a formal compliance program: FedRAMP Moderate Equivalency (NIST 800-53 Rev 5 Moderate baseline, ~325 controls) supporting our clients' CMMC Level 2 obligations, with a third-party assessment scheduled for Q4 2026. This role exists to lead that effort from the inside.
This is a hands-on, doer role with technical leadership responsibilities - not a paper CISO position. You will be FieldFlo's first dedicated security hire: the technical owner of our security program and the engineering
lead for our FedRAMP Moderate Equivalency effort. You'll spend most of your time implementing controls, hardening cloud infrastructure, deploying and tuning security tooling, and producing the evidence that stands up to a 3PAO assessment.
You won't do it alone. You'll work alongside an external compliance advisory partner (SSP and readiness documentation), a third-party assessment organization (3PAO), and a part-time Compliance Specialist who
runs FedRAMP program management - schedules, trackers, and auditor coordination. You own the technical half of that pairing: making the controls real in production and proving it. You'll also work daily with our lean DevOps and engineering teams, and report to the CTO.
Assessment windows are unforgiving - auditors stack engagements back-to-back, and missing a milestone can push a certification by months. We need someone who treats compliance deadlines like production incidents.
💡 What You’ll Work On
Security Program Leadership
Own technical implementation and evidence for the NIST 800-53 Rev 5 Moderate control baseline across our AWS environment.
Partner with our advisory firm on the System Security Plan (SSP): authorization boundary documentation, data flows, control narratives, and architectural rationale for in-boundary and excluded components.
Drive POA&M remediation - prioritize gaps, implement fixes, and close findings with evidence rather thanpromises.
Serve as the technical point of contact for the 3PAO during assessment: interviews, artifact requests, demonstrations, and remediation of assessment findings.
Hold the line on assessment milestones - track dependencies, escalate early, and keep the technical workstream on schedule.
Cloud and Infrastructure Security
Harden and secure our production environment: EKS (Kubernetes), Aurora MySQL, CloudFront + WAFv2, Lambda, and supporting services across primary and DR regions.
Operate and expand our AWS-native security stack: GuardDuty, CloudTrail, IAM Identity Center (federated access, no IAM users), OIDC-based CI/CD, and IRSA for workloads - and lead the rollout of Security Hub and Inspector.
Implement FedRAMP-driven infrastructure requirements: FIPS 140-validated cryptography, hardened/approved machine images, configuration baselines, and boundary segmentation.
Evaluate and, if required, help design gov-oriented enclave architectures as our federal footprint grows.
Security Operations
Stand up centralized log ingestion and detection (Datadog SIEM) - define what we collect, what alerts, and who responds.
Own incident response: playbooks, runbooks, on-call escalation (SquadCast), tabletop exercises, and post-incident reviews.
Run vulnerability management end-to-end: scanning (Inspector), dependency and code analysis (Dependabot, Semgrep, PHPStan in CI), triage, SLAs, and remediation tracking with engineering.
Coordinate penetration testing and DAST with external providers - scoping, scheduling, findings disposition, and retest.
Corporate & Endpoint Security
Lead our EDR/MDM rollout (SentinelOne paired with MDM) across company-issued devices, and define contractual security requirements and evidence collection for our BYOD contractor fleet.
Own security policies and procedures - written to be followed and evidenced, not shelfware.
Run the security awareness program (KnowBe4): phishing simulations, training completion, and measurable improvement.
Conduct vendor security reviews and manage third-party risk for tools and integration partners.
🔧 Must‑Have Qualifications
✅ 5+ years of hands-on cybersecurity or security engineering experience.
✅Experience securing cloud environments (AWS preferred).
✅Direct experience supporting security, compliance, or audit initiatives such as NIST, SOC 2, ISO 27001, CMMC, or similar frameworks.
✅Strong understanding of IAM, vulnerability management, security monitoring, and incident response.
✅Experience working closely with engineering and DevOps teams.
✅Excellent written and verbal English communication skills.
✅Self-starter with strong ownership and execution skills.
Nice to have:
Experience with FedRAMP, NIST 800-53, SSP development, POA&M management, or government-focused compliance programs.
DevOps, SRE, or cloud infrastructure leadership experience.
Kubernetes/EKS security experience.
Experience with Datadog, SentinelOne, Security Hub, GuardDuty, or similar tools.
CISSP, CCSP, AWS Security Specialty, OSCP, or related certifications.
SaaS startup or scale-up experience.
💼 What We Offer
Full-time remote (with at least 2h overlap with US Mountain Time)
B2B contract
Paid national holidays (based on your country)
Optional unpaid personal time off
3‑month probation
High-impact role shaping the future of an AI-native SaaS platform
📣 Recruitment Process
Initial call with Recruiting Agency HC Solutions
Technical panel interview (Senior Engineer + Tech Lead)
Interview with AI Labs team
Final interview with VP Engineering & CTO

Work arrangement
No

Get JobBeeper Mobile App

Never miss a job opening! Get instant job alerts on your phone.

Subscribers see fresh openings within minutes. Download the JobBeeper App on Google Play to get real-time push notifications and apply before anyone else.

⚡ Instant Push Alerts 🎯 Tailored Filters 🚀 Direct Employer Links
GET IT ON Google Play

More openings worth a look

Recently tracked roles with full details and direct application links.

6 roles
Good roles move before most people even see them. Tell JobBeeper what you want and get fresh matches delivered in minutes.
Start your free trial →
⚡ Get fresh job alerts 📱 Get App