Nerdy is a company behind Varsity Tutors, aiming to redefine the learning experience through their AI-Native platform. The Lead Security Engineer will drive the enterprise security strategy, ensuring secure and reliable systems while overseeing compliance and risk management across the organization.
Responsibilities:
- Define and execute enterprise security strategy
- Partner closely with leaders to cover compliance, automation, and security best practices across the organization
- Lead business continuity and disaster recovery planning
- Identify and address security gaps created by the rapid adoption of new tools and platforms
- Oversee threat detection, incident response, and vulnerability management
- Ensure regulatory, privacy, and data protection compliance
- Use AI-powered tools (e.g., Cursor, Claude Code, or equivalent) to implement security guardrails, automate checks, and accelerate security workflows
- Mentor other engineers and collaborate with peers to strengthen the team's collective knowledge
- Design secure, scalable, and resilient architecture
- Embed security controls across Engineering, Product, Legal, and People teams
- Manage vendors, security tools, and IT systems
- Report security posture and risk metrics to executives
Requirements:
- 7+ years in Security Engineering, IT, or Infrastructure leadership
- Experience leading enterprise security in AWS-first environments
- Hands-on experience with AWS security (IAM, security groups, logging, monitoring)
- Strong knowledge of cybersecurity frameworks, risk, and compliance
- Experience leading threat detection, vulnerability management, and incident response
- Demonstrated ability to influence, driving security adoption across engineering and product teams
- Expertise in cloud infrastructure, IAM, endpoint and network security
- Explicit mentoring of senior-level engineers regularly
- Ability to align security strategy with business goals
- Strong executive communication and stakeholder management skills
- Experience using AI tools for security purposes with tools like Cursor, GitHub Copilot, Claude, or similar
- Bachelor's in CS, Information Security, or related field (advanced degree/certs preferred)
- Familiarity with NIST 800-171 and/or CMMC Level 2 compliance frameworks