VP, Security
New
J
JobgetherTechnology and commerce
Remote position based in the United States.Full-TimeVp
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 12+ years of professional security experience, including 5+ years leading a security function within a SaaS, technology, or platform company.
- Required Skills
- AWSGCPKubernetesCI/CDMicroservices
Requirements
- Bring 12+ years of professional security experience, including 5+ years leading a security function within a SaaS, technology, or platform company.
- Have deep cloud-native security experience, including AWS and/or GCP, Kubernetes, microservices, CI/CD, and API security.
- Demonstrate technical credibility and participate meaningfully in architecture reviews and security engineering decisions.
- Have led security diligence and integration for M&A transactions.
- Have built and operated security programs aligned with NIST CSF, SOC 2, and ISO 27001, including successful audits.
- Have established or managed 24/7 security detection and response through internal teams, MDR providers, or hybrid models.
- Communicate security risks, technical trade-offs, controls, and business implications to boards, executives, finance leaders, and engineering teams.
- Exercise sound judgment in security investment, risk prioritization, controls, and mitigation strategies.
- Lead through influence, build high-performing teams, and establish partnerships across technical and business functions.
- Operate effectively in complex, rapidly changing environments with competing priorities.
- Experience with IPO readiness, public-company security requirements, SEC cybersecurity disclosure, SOX IT controls, or board reporting is a plus.
- Experience with AI/ML security governance or international regulatory requirements is beneficial.
Responsibilities
- Define and execute the security strategy, multi-year roadmap, governance framework, and technical priorities, including alignment with NIST CSF 2.0.
- Expand security audit scopes and certifications and establish governance for AI models, agents, and related initiatives.
- Build and operate security operations, initially leveraging an MDR partner and developing internal detection engineering capabilities.
- Own incident response, including playbooks, on-call processes, executive tabletop exercises, investigations, postmortems, and remediation.
- Lead the security engineering stack across SIEM/SOAR, EDR/XDR, cloud security posture management, API security, secrets management, and vulnerability management.
- Strengthen software delivery security through practices such as signed commits, SBOM generation, dependency and secrets scanning, and SAST/DAST.
- Lead security diligence and integration planning for acquisitions, including assessment of inherited environments, credentials, systems, technical debt, and remediation.
- Partner with Product and Engineering to establish secure-by-default approaches across technology platforms and customer-facing products.
- Oversee penetration testing and bug bounty programs and represent security in enterprise customer reviews and discussions.
- Lead business continuity and disaster recovery efforts and regularly test recovery capabilities.
View Full Description & ApplyYou'll be redirected to the employer's site