Talent.com
The National Basketball Association
Cybersecurity Staff EngineerThe National Basketball Association • Secaucus, NJ, US
No longer accepting applications
Cybersecurity Staff Engineer

Cybersecurity Staff Engineer

The National Basketball Association • Secaucus, NJ, US
3 days ago
Salary
$172,500.00 yearly
Job type
  • Full-time
Job description

Director Of Cybersecurity Governance, Risk, And Compliance

We're looking for a seasoned Cybersecurity Staff Engineer to lead our Cyber Governance, Risk, and Compliance efforts one of the most strategically critical functions in our security organization. This is a Director-level individual contributor role reporting to the AVP of Cybersecurity, sitting at the intersection of every cybersecurity practice area we operate. You won't just manage compliance programs you'll be the connective tissue that brings structure, visibility, and accountability across our entire security landscape.

Every cybersecurity organization generates signals risks identified, controls tested, findings logged. But signals without synthesis are just noise. This role exists because our security towers are only as strong as the visibility and accountability that connects them. Without someone owning that connective layer, gaps persist, issues stall, and leadership is left making decisions without a complete picture. This role changes that. By bringing consolidated oversight to risk, compliance, and issue closure across every tower we operate, this role directly shapes our ability to protect fan data, honor our regulatory obligations across global markets, and maintain the trust of partners and stakeholders who expect a world-class security posture from a world-class organization. It's not a support function it's a force multiplier.

Operating within an international sports and entertainment league means our risk surface is anything but ordinary. Global events, broadcast partnerships, fan data at scale, and regulatory obligations spanning multiple jurisdictions make this a role for someone who thrives on complexity and can translate it into clarity.

Major Responsibilities

GRC Integration & Unified Visibility

  • Aggregate risk posture, control gaps, and issue status across all cybersecurity towers into cohesive dashboards and executive-ready reporting frameworks
  • Serve as the single point of GRC intelligence translating disparate signals into a coherent organizational risk picture
  • Establish and maintain consistent metrics and KPIs that reflect compliance health across all towers

Issue Tracking & Risk Closure

  • Own end-to-end issue lifecycle management from identification through remediation ensuring findings don't stall in handoff gaps
  • Build accountability mechanisms across tower leads and partner teams that keep risk closure on track without requiring direct authority
  • Ensure non-IT departments follow documented processes and help them address audit gaps
  • Escalate systemic issues and trend patterns to senior leadership with actionable recommendations

ISO 27001 Program Ownership

  • Lead all aspects of ISO 27001 certification maintenance, including evidence collection, control mapping, audit readiness, and continuous improvement
  • Manage relationships with external auditors and certification bodies
  • Ensure the program remains audit-ready year-round, not just at certification time

SOC 2 Type II Compliance

  • Contribute into our SOC 2 Type II program and lead compliance posture across applicable trust service criteria
  • Coordinate with engineering, IT, and operations teams to ensure controls are implemented, evidenced, and sustainable

Level 1 Cyber Risk Management

  • Conduct and document Level 1 cyber risk assessments using established frameworks including NIST CSF and ISO 27001
  • Maintain the enterprise cyber risk register, ensuring risks are properly rated, owned, and tracked toward resolution
  • Surface emerging risks tied to our industry fan data systems, broadcast infrastructure, global event operations with appropriate context for decision-makers

Cross-Functional Collaboration & Influence

  • Partner with tower leads, IT, Legal, Privacy, and Procurement to align on risk priorities and drive coordinated remediation
  • Communicate policy and regulatory requirements in language that resonates with both technical practitioners and executive stakeholders
  • Operate as a trusted advisor across the organization influencing outcomes without relying on org chart authority

GRC Tooling & Automation

  • Identify opportunities to replace manual compliance effort with scalable automation through GRC platforms and integrations
  • Drive adoption and optimization of tools such as Drata, ServiceNow GRC, OneTrust, or equivalent platforms
  • Stay ahead of the tooling landscape and bring forward recommendations that improve program efficiency and coverage

Regulatory & Global Compliance Awareness

  • Maintain working knowledge of regulations relevant to our global footprint including GDPR, CCPA, and evolving data residency requirements across international markets
  • Support third-party and vendor risk review processes in coordination with Legal and Procurement, ensuring vendor relationships meet our compliance standards

Required Education/Professional Experience

  • 7+ years of progressive experience in Cybersecurity GRC, Risk Management, or Compliance with exposure to both program ownership and cross-functional coordination
  • Demonstrated ability to manage across multiple security domains simultaneously without losing precision or accountability
  • Hands-on experience leading ISO 27001 certification programs and SOC 2 Type II compliance you've owned audit cycles, not just supported them
  • Familiarity with one or more GRC platforms (Drata, ServiceNow, OneTrust, or comparable)
  • CISSP, CISM, or CRISC certification preferred
  • Experience in sports, entertainment, media, or other high-profile consumer-facing industries a plus

Required Skills/Knowledge Attributes

  • Deep fluency in security and compliance frameworks ISO 27001, NIST CSF, and CIS Benchmarks and the ability to translate framework requirements into operational controls
  • Working knowledge of GDPR, CCPA, and data residency obligations across global markets, with the ability to assess their impact on program design and risk posture
  • Understanding of IAM principles and data protection methods (encryption, tokenization) sufficient to evaluate control effectiveness across security towers
  • Ability to develop and execute incident response coordination at the GRC level ensuring compliance obligations are met when security incidents occur
  • Strong systems thinker who understands how risk and compliance data flows across tools, teams, and processes and can identify where the gaps live
  • Skilled at identifying where automation can replace manual compliance effort, and credible enough to bring stakeholders along on the change
  • Excellent written and verbal communicator equally effective presenting to a CISO and partnering with a technical tower lead
  • Proven influencer at the Director level and above, with a track record of driving accountability without direct authority
  • Familiarity with broadcast or live event infrastructure risk considerations a plus

Salary Range:

$172,500-$195,000

Job Posting Title:

Director

Employees currently are eligible to receive an annual discretionary performance bonus, awarded at the sole discretion of the Company and subject to any terms and conditions set by the Company. Employees and/or eligible dependents may be eligible to participate in the following Company-sponsored employee benefit programs: medical; dental; vision; life/AD&D insurance; short- and long-term disability; fertility and family-forming assistance; wellbeing allowance; educational assistance; mental health coaching/therapy; tax advantaged accounts such as HSA and healthcare/dependent care FSAs; a 401(k) retirement plan; and time off benefits that include vacation, sick time, and personal days.

We Consider Applicants For All Positions On The Basis Of Merit, Qualifications And Business Needs, And Without Regard To Race, Color, National Origin, Religion, Sex, Gender Identity, Age, Disability, Alienage Or Citizenship Status, Ancestry, Marital Status, Creed, Genetic Predisposition Or Carrier Status, Sexual Orientation, Veteran Status, Familial Status, Status As A Victim Of Domestic Violence Or Any Other Status Or Characteristic Protected By Applicable Federal, State, Or Local Law.

The NBA is committed to providing a safe and healthy workplace. To safeguard our employees and their families, our visitors, and the broader community from COVID-19, and in consideration of recommendations from health authorities and the NBA's own advisors, any individual working onsite in our New York and New Jersey offices must be fully vaccinated against COVID-19. The NBA will discuss accommodations for individuals who cannot be vaccinated due to a medical reason or sincerely held religious belief, practice, or observance.

About the NBA

The National Basketball Association (NBA) is a global sports and media organization with the mission to inspire and connect people everywhere through the power of basketball.

Create a job alert for this search

Cybersecurity Staff Engineer • Secaucus, NJ, US

Similar jobs

Cybersecurity Staff Engineer

The National Basketball AssociationSecaucus, NJ, United States
Full-time

Director Of Cybersecurity Governance, Risk, And Compliance.We're looking for a seasoned Cybersecurity Staff Engineer to lead our Cyber Governance, Risk, and Compliance efforts one of the most stra... Show more

 • Promoted

Staff / Principal DevOps Engineer

Appgate, Inc.New York, NY, United States
Full-time

Staff / Principal DevOps Engineer.AI Platform & Infrastructure Team.AppGate secures and protects an organization’s most valuable assets with its high performance Zero Trust Network Access (ZTNA) so... Show more

 • Promoted

Strategic CISO: Enterprise Cybersecurity & Risk Leadership

JobtailorNew York, NY, United States
Full-time

Jobtailor is seeking a strategic Chief Information Security Officer to define and execute our enterprise security program.You will lead a large, cross‑functional security organization, align securi... Show more

 • Promoted

PayPal Risk Operations Associate

TradeJobsWorkforce10704 Yonkers, NY, US
Full-time

An exciting opportunity awaits for a PayPal Risk Operations Associate to perform daily responsibilities with dedication.Provide excellent interactions with customers and colleagues.Stay adaptable i... Show more

 • Promoted

Manager, Cyber Defense

KPMGNew York, NY, US
Full-time

The KPMG Advisory practice is at the forefront of transformation, offering excellent opportunities for individuals to advance their careers and expertise with KPMG.Looking ahead, we anticipate cont... Show more

 • Promoted

Front Desk Agent

Sage HospitalityAsbury Park, NJ, United States
Full-time

Beach Club, a boutique hotel, and an unprecedented suite of amenities.A unique blend of intimacy and grandeur serves as the hallmark of your stay in any one of our 54 guest rooms.With magical views... Show more

 • Promoted

Group Director, Cyber Security Engineer

CHANELNew York, NY, United States
Full-time

Group Director, Cyber Risk & Security Engineering.At Chanel, we are focused on creating an inclusive culture that nurtures personal growth, contributing to collective progress.We believe the unique... Show more

 • Promoted

Chief Global Procurement Leader: Strategic Sourcing Growth

NylaboneNeptune Township, NJ, United States
Full-time

Nylabone is seeking a Vice President, Global Procurement to lead our worldwide procurement organization from Neptune City, NJ.This executive will develop enterprise-wide sourcing strategies, optimi... Show more

 • Promoted

Cybersecurity Technology Manager

Brown Brothers HarrimanJersey City, NJ, United States
Full-time

Cybersecurity Technology Manager.At BBH, partnership is more than a form of ownershipit's our approach to business and relationships.We know that supporting your professional and personal goals is ... Show more

 • Promoted

CISO

JFR StaffingWall Township, NJ, United States
Full-time

Chief Information Security Officer (CISO).Person Required | Public Trust Eligible.JFR Staffing is partnering with a rapidly growing SaaS technology company seeking a Chief Information Security Offi... Show more

 • Promoted

Strategic Field CISO & Enterprise Cybersecurity Advisor

Check Point Software TechnologiesNew York, NY, United States
Full-time

Check Point Software Technologies is seeking a senior Field CISO to serve as a trusted cybersecurity advisor to enterprise customers across the Americas.The role requires leading executive-level di... Show more

 • Promoted

AI-Powered Cybersecurity Product Engineer

AnthropicNew York, NY, United States
Full-time

A leading AI research firm in New York is looking for a Software Engineer for Cybersecurity Products to prototype and develop AI-powered solutions.Candidates should have at least 7 years of experie... Show more

 • Promoted

VP, Staff Cryptography Engineer

SynchronyNew York, NY, United States
Full-time

VP, Staff Cryptography Engineer.The VP, Staff Cryptography Engineer will serve as a key role in safeguarding enterprise multi-cloud systems, networks, and data.The position is responsible for desig... Show more

 • Promoted

Senior Cybersecurity Engineer (Partial Remote)

Analytic Search Group,princeton NjNew York City, NY, United States
Remote
Permanent

Global Property and Casualty Provider seeks an experienced Cybersecurity Engineer to support the Information Security Officer in designing, developing, and implementing cybersecurity and IT securit... Show more

 • Promoted

Staff / Principal DevOps Engineer

PVH (Tommy Hilfiger/Calvin Klein)New York, NY, United States
Full-time

Staff / Principal DevOps EngineerLocation: New York City | HybridDepartment: AI Platform & Infrastructure TeamReports to: Vangie Shue – Principal Engineering Manager.AppGate secures and protects an... Show more

 • Promoted

CIO: Elevate IT Strategy & Cybersecurity in Higher Ed

AGB SearchNew York, NY, United States
Full-time

Sarah Lawrence College (SLC) invites applications for the Chief Information Officer (CIO) position.The CIO will lead the IT vision and strategy supporting the College's mission, oversee cybersecuri... Show more

 • Promoted

Senior Staff Engineer, Quote-to-Cash

United States Digital Space LLCNew York, NY, United States
Full-time

We’re looking for a Sr Staff Engineer, Quote-to-Cash (QTC) to design, optimize, and scale our end-to-end Q2C architecture across Salesforce CPQ, Malbek CLM, and NetSuite ERP.You will be the functio... Show more

 • Promoted

Senior Area Executive Chef

SodexoNeptune, NJ, United States
Full-time

Role Overview** ***Craft Your Career*** **Sodexo** is seeking an **Senior Area Executive Chef** **for the Hackensack Meridian Health System in Central and North, New Jersey.Hackensack Meridia... Show more