Director of Information Security
New
J
JobgetherSaaS Technology
Remote opportunity within the United States.Full-TimeDirector
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 10+ years of experience in information security, including at least 3 years in a leadership role
- Required Skills
- AWSGCPRisk Management
Requirements
- Bachelor’s degree in Information Security, Computer Science, Computer Engineering, or equivalent experience.
- 10+ years of experience in information security.
- At least 3 years in a leadership role with end-to-end ownership of a security program.
- Direct operational experience with ISO 27001 and SOC 2.
- Strong technical expertise in cloud security, specifically AWS and/or GCP.
- Strong understanding of network security and modern application security practices.
- Experience with secure SDLC, application security tooling, and deployment environment security.
- Proven experience building or rebuilding security policies and processes in a scaling SaaS organization.
- Demonstrated ability to build security teams and establish collaborative relationships with engineering.
- Experience managing external auditors, penetration testers, and compliance vendors.
- Excellent written and verbal communication skills for technical and executive stakeholders.
- Strong judgment in making pragmatic, risk-based decisions.
Responsibilities
- Own and continuously mature the information security program in alignment with ISO 27001 and SOC 2 requirements.
- Develop, formalize, and operationalize security policies covering risk management, incident response, and third-party risk.
- Manage the internal control environment, including risk assessments, audit evidence, and certification readiness.
- Define strategy for identity and access management, cloud/network security, vulnerability management, and incident response.
- Establish secure SDLC practices including threat modeling, secure code review, and CI/CD pipeline security.
- Lead, coach, and develop the security team, establishing clear operating standards.
- Act as the primary security partner for Engineering, Product, IT, and executive leadership to align security with business goals.
View Full Description & ApplyYou'll be redirected to the employer's site