Sr. Security and Compliance Engineer

Hanwha Q CELLS America Inc.

• $134K — $182K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in information security, Computer Science, or related field, or equivalent experience.
  • 5+ years of experience in cybersecurity, cloud security, security operations, governance, risk, or compliance.
  • Strong knowledge of cloud security concepts: IAM, security groups, VPC, encryption.
  • Understanding of compliance frameworks: FFIEC, SOX, SOC 2, ISO 27001.
  • Experience with incident response, vulnerability remediation, and cloud security in enterprise environments.

Responsibilities

  • Develop and maintain security and compliance strategies and policies.
  • Lead continuous improvement projects for IT systems security.
  • Manage security operations: threat detection, incident response, and compliance monitoring.
  • Ensure backup and disaster recovery meet SLA objectives.
  • Align cybersecurity efforts with compliance requirements and audit practices.
  • Monitor cloud environments using SIEM tools and native security solutions.
  • Investigate and respond to security incidents with thorough documentation.

Benefits

  • Flexible work arrangements with possible remote options.
  • Opportunity to lead and influence security practices at a growing company.
  • Engagement with interdisciplinary teams (IT, Legal, vendor management).
  • Access to ongoing professional development and certifications.
  • Support for a diverse and inclusive work environment.
Full Job Description
Description

POSITION DESCRIPTION:

Qcells is looking for a hands-on senior security and compliance professional to lead cloud security, security operations, governance, risk, and compliance activities across the organization. The Sr. Security and Compliance Engineer will help safeguard IT assets by monitoring threats, responding to incidents, remediating risks, maintaining security technologies, and ensuring alignment with internal policies and applicable compliance frameworks.

This position will be based out of one of our offices in Irvine, CA; San Francisco, CA; or Teaneck, NJ, with an in-office schedule set at the direct manager's discretion in accordance with company policies and procedures. Remote options are available for exceptional cases.

RESPONSIBILITIES:

  • Develop and maintain the information security and compliance strategy, roadmap, policies, standards, and control framework.


  • Lead and support continuous improvement projects to deploy, consolidate, enhance, and/or secure enterprise IT systems and services.


  • Lead security and compliance operations, including threat detection, incident response, vulnerability remediation, forensics coordination, control monitoring, and compliance reporting.


  • Ensure proper back up and disaster recovery are in place and proactively monitored to achieve service level agreements (SLAs) for Recovery Point Objective (RPO) and Recovery Time Objective (RTO).


  • Ensure alignment with cybersecurity, privacy, technology control, and audit requirements, including FFIEC, SOX, SOC 2, ISO 27001, and other applicable obligations.


  • Monitor and secure cloud environments (e.g., Azure, AWS, Salesforce) using security information and event management (SIEM) tools, and cloud-native security solutions.


  • Investigate and respond to security incidents, ensuring proper containment, remediation, and documentation of root causes.


  • Design and mature security and compliance controls for secure architecture, IAM, data handling, audit readiness, and risk management.


  • Support Qcells NA's ISMS through control evidence, risk treatment, audit readiness, corrective actions, and continuous improvement.


  • Partner with IT, Legal, Privacy, vendors, and business teams on security requirements, policy exceptions, and compliance remediation.


  • Evaluate, recommend and implement new solutions that enhance security posture.


  • Oversee end-users access management throughout the organization. Conduct and assist with regularly scheduled user access reviews in active directory and other applications as needed.


  • Execute periodic FinTech risk assessments and comprehensive security awareness programs, ensuring employees adhere to best practices and regulatory security requirements.


  • Stay current with emerging security trends, threats, and technologies to continuously improve security strategies.


  • Collaborate with IT and development teams on security best practices.


  • Operate in a manner demonstrating a high level of integrity, ethics, and discretion when handling sensitive and confidential information.


REQUIRED QUALIFICATIONS:

  • Bachelor's degree in information security, Computer Science, or a related field, or equivalent experience, with 5+ years in cybersecurity, cloud security, security operations, governance, risk, compliance, or a similar role.


  • Strong knowledge of cloud security concepts such as IAM, security groups, VPC, encryption (at-rest and in-transit), and cloud monitoring.


  • Strong understanding of compliance frameworks and audit practices, including FFIEC, SOX, SOC 2, ISO 27001, control testing, evidence collection, and remediation tracking.


  • Experience with incident response, vulnerability remediation, risk assessments, compliance reviews, logging, alerting, forensic investigation, and executive reporting in cloud environments.


PREFERRED QUALIFICATIONS:

  • Strongly Preferred: CCSP (Certified Cloud Security Professional), CISSP (Certified Information System Security Professional), CISM (Certified Information Security Manager), CompTIA A+, CompTIA Security +.


  • Strong understanding of FinTech security compliance and principles, and implementation in cloud environments.


COMPENSATION:

In accordance with applicable pay transparency laws, the anticipated annual base salary for this position is:

  • Zone 1 (Bay Area, NYC): $146,200 - $182,600


  • Zone 2 (CA, NJ, NY): $134,000 - $167,400


  • Zone 3 (All others): $121,800 - $152,200


The applicable salary range is based on the employee's primary work location. Individual compensation will be determined based on qualifications, relevant experience, education, skills, internal equity, and other business-related factors.

PHYSICAL, MENTAL & ENVIRONMENTAL DEMANDS:

To comply with the Rehabilitation Act of 1973 the essential physical, mental and environmental requirements for this job are listed below. These are requirements normally expected to perform regular job duties. Incumbent must be able to successfully perform all of the functions of the job with or without reasonable accommodation.

Mobility

Standing

20% of time

Sitting

70% of time

Walking

10% of time

Strength

Pulling

up to 10 Pounds

Pushing

up to 10 Pounds

Carrying

up to 10 Pounds

Lifting

up to 10 Pounds

Dexterity (F = Frequently, O = Occasionally, N = Never)

Typing

F

Handling

F

Reaching

F

Agility (F = Frequently, O = Occasionally, N = Never)

Turning

F

Twisting

F

Bending

O

Crouching

O

Balancing

N

Climbing

N

Crawling

N

Kneeling

N

The salary range is required by the California Pay Transparency Act and may differ depending on the location of those candidates hired nationwide. Actual compensation is influenced by a wide array of factors including but not limited to, skill set, education, licenses and certifications, essential job duties and requirements, and the necessary experience relative to the job's minimum qualifications.

*This target salary range is for CA positions only and should not be interpreted as an offer of compensation.
You may view your privacy rights by reviewing Qcells' Privacy Policy or by contacting our HR team for a copy.

Similar Jobs

More Jobs at Hanwha Q CELLS America Inc.

More Information Technology Jobs

Find similar Sr. Security and Compliance Engineer jobs: