Job Context:
We are looking for a hands-on Cybersecurity Expert to take full ownership of information security at Riseup Labs. You will assess our infrastructure, close gaps, put practical controls in place, train our people, lead incident response, and support compliance with SOC 2, PCI DSS, and other frameworks. You will also act as a trusted security voice in client conversations and help grow our cybersecurity offerings.
This is an execution role. We need someone who implements and tests controls, not someone who only writes policies.
Job Responsibilities:
- Security Assessment and Risk Management
- Review infrastructure, networks, cloud environments, applications, devices, access controls, and internal practices to identify vulnerabilities and risks.
- Conduct regular security audits, vulnerability assessments, risk assessments, and security reviews, and track findings through to remediation.
- Maintain a risk register with clear priorities, owners, and timelines.
- Security Governance and Controls
- Establish and continuously improve company-wide security policies, standards, and controls.
- Work with Technology, IT, DevOps, Compliance, HR, and Delivery teams so that controls are implemented and operating, not just documented.
- Implement and manage security controls such as identity and access management, MFA, endpoint protection, logging and monitoring, patching, backup, and encryption.
- Incident Response
- Design and maintain an incident response plan, escalation matrix, and playbooks.
- Lead investigation, containment, recovery, and post-incident reviews for security incidents.
- Run incident-response tabletop exercises and drills.
- Security Awareness and Training
- Deliver regular security awareness training and workshops for all employees.
- Plan and run phishing and social-engineering simulations and report on results and improvement.
- Compliance and Assurance
- Support SOC 2, PCI DSS, and other security and compliance requirements, including evidence collection, control testing, and audit readiness.
- Map controls to relevant frameworks (e.g., ISO 27001, NIST CSF, CIS Controls) and drive continuous improvement of our security posture.
- Secure Development and DevSecOps
- Partner with engineering and project teams on secure SDLC and security-by-design practices.
- Support secure code review, threat modeling, SAST/DAST, dependency and container scanning, and secrets management in CI/CD pipelines.
- Advise on securing cloud and AI platforms, APIs, and data pipelines.
- Pre-Sales and Business Growth
- Join client and pre-sales meetings to understand security requirements and respond to security questionnaires and RFPs.
- Contribute to solution design and proposals with a security component.
- Help define, package, and grow Cybersecurity as a service offering (e.g., assessments, VAPT, compliance readiness, security consulting).
Required Qualifications
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).
- 3+ years of hands-on experience in cybersecurity, information security, or security engineering.
- Proven experience with vulnerability assessment and penetration testing, risk assessment, and security audits.
- Strong knowledge of network security, application security, cloud security (AWS, Azure, or GCP), and identity and access management.
- Practical experience with security tools such as SIEM, EDR, vulnerability scanners (e.g., Nessus, Qualys, OpenVAS), Burp Suite, and Wireshark.
- Hands-on experience with incident response and digital forensics fundamentals.
- Working knowledge of SOC 2, PCI DSS, ISO 27001, and NIST frameworks, with experience supporting at least one audit or certification.
- Familiarity with secure SDLC, DevSecOps, and OWASP Top 10.
- Excellent written and verbal communication, with the ability to explain security topics to technical and non-technical audiences, including clients and leadership.
Preferred Qualifications
- Professional certifications such as CISSP, CISM, CISA, CEH, OSCP, CompTIA Security+, or cloud security certifications (e.g., AWS Security Specialty, AZ-500).
- Experience with ISO 27001 implementation or PCI DSS assessment.
- Experience in a software, IT services, or consulting environment.
- Experience securing AI/ML platforms, APIs, and data pipelines.
- Prior pre-sales, client-facing, or security consulting experience.
- Experience with enterprise or government sector security requirements in Bangladesh.
- Scripting skills (Python, Bash, or PowerShell) for security automation.
Key Competencies
- Ownership and accountability.
- Hands-on, execution-focused approach.
- Risk-based thinking and sound judgment.
- Cross-functional collaboration.
- Teaching and communication skills.
- Client confidence and professionalism.
- Ability to work calmly under pressure during incidents.
Workplace:
Working hour:
Salary:
- Negotiable (Based on experience and skills)
Compensation and Benifits: (Applicable for Bangladeshi Employee Only)
- Annual Performance Evaluation and Increment
- Festival Bonus-02 (As Per Company Policy)
- Group Life and Health Insurance
- Full Subsidized Lunch/Dinner
- Annual Retreats
- Celebration of Events & Occasions
- Training & Development by Organization Assigned Consultants
- Weekly 2 holidays
- Paid Time Off 24 days (CL & SL)
- Maternity Leave with benefits (As per the company’s policy)
- Paternity Leave (As per the company’s policy)
- Bereavement Leave (As per the company’s policy)
- Public Holidays as per Riseup Labs calendar
The Application Process:
- Telephone Round.
- Interview with the Management, Technology Team and Talent Acquisition Team.
- Job Offer.
N.B.: Only shortlisted candidates will be communicated in the recruitment process.