Director of Information Security
jobgether
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director of Information Security based in the United States.
As Director of Information Security, you will lead and mature a growing security program at a critical stage of organizational expansion.
You will build on established ISO 27001 and SOC 2 foundations while developing a durable, operational security framework.
The role combines strategic leadership with hands-on ownership across cloud, infrastructure, networks, applications, and security operations.
You will strengthen governance, policies, risk management, compliance, incident response, and secure software development practices.
A key part of the position is partnering closely with Engineering and Product to make security an integrated and practical part of how technology is built.
You will also lead and develop the security team while communicating security risks and priorities clearly to executives and the board.
This is an opportunity to shape a high-impact security function within a rapidly scaling SaaS and technology environment.
Accountabilities:
As the senior security leader, you will own the information security program end to end, balancing strong governance and risk management with practical security engineering and close partnership across the organization.
- Own and continuously mature the information security program in alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2.
- Develop, formalize, maintain, and operationalize security policies, standards, and procedures covering risk management, access control, incident response, third-party risk, change management, business continuity, and related areas.
- Manage the internal control environment, including risk assessments, control testing, audit evidence, remediation tracking, and ongoing certification readiness.
- Build and maintain effective relationships with external auditors, penetration testers, and security and compliance partners.
- Own security across infrastructure, networks, AWS/GCP cloud environments, endpoints, and applications.
- Define the strategy and roadmap for identity and access management, cloud and network security, endpoint protection, vulnerability management, logging, monitoring, and incident response.
- Establish and continuously improve secure SDLC practices, including threat modeling, secure code review, dependency and software supply-chain security, and CI/CD pipeline security.
- Develop and maintain an effective incident response program, including response plans, tabletop exercises, and leadership during significant incidents.
- Lead, coach, and develop the security team while establishing clear ownership, workflows, priorities, and operating standards.
- Build a collaborative security culture that enables engineering teams to work securely without unnecessary friction or delays.
- Define effective engagement models with Engineering and Product, including embedded reviews, self-service security tooling, and clear service-level expectations.
- Serve as the primary security partner for Engineering, Product, IT, Legal, and executive leadership.
- Translate technical security risks into clear business implications and provide pragmatic, risk-based recommendations to leadership and the board.
- Support customer trust and commercial activities through security questionnaires, customer audits, trust-center initiatives, and related security engagements.
- Establish measurable success criteria for security operations, including policy adoption, team ownership, audit readiness, incident response effectiveness, and security review efficiency.
Requirements:
The ideal candidate combines deep information security expertise with proven leadership experience in a scaling SaaS environment, along with the ability to operate comfortably between technical teams, compliance stakeholders, and executive leadership.
- Bachelor’s degree in Information Security, Computer Science, Computer Engineering, or a related field, or equivalent professional experience.
- 10+ years of experience in information security, including at least 3 years in a leadership role with end-to-end ownership of a security program.
- Direct operational experience with ISO 27001 and SOC 2, with a strong understanding of what maintaining audit readiness requires on an ongoing basis.
- Strong technical expertise in cloud security, particularly AWS and/or GCP.
- Strong understanding of network security and modern application security practices.
- Experience with secure SDLC, application security tooling, and security practices across development and deployment environments.
- Experience with container and Kubernetes security is a plus.
- Proven experience building or rebuilding security policies, procedures, and operating processes within a scaling SaaS organization.
- Demonstrated ability to build security teams and establish effective, collaborative relationships with Engineering and Product.
- Strong understanding of how security tooling, automation, communication, and practical processes can drive adoption more effectively than policy alone.
- Experience managing external auditors, penetration testers, and compliance vendors.
- Excellent written and verbal communication skills, with the ability to communicate effectively with engineers as well as senior executives and board-level stakeholders.
- Strong judgment and ability to make pragmatic, risk-based decisions in complex and rapidly changing environments.
- CISSP, CISM, or a comparable security certification is a plus.
- Experience with ISO 27701 is a plus.
- Experience with the NIST Cybersecurity Framework is a plus.
- Experience working in a post-certification, high-growth technology or SaaS environment is preferred.
Benefits:
- Competitive compensation aligned with experience and qualifications.
- Remote opportunity within the United States.
- Opportunity to lead and shape a growing information security function.
- Strategic and hands-on ownership across governance, cloud security, application security, infrastructure, and security operations.
- Direct partnership with Engineering, Product, IT, Legal, and executive leadership.
- Opportunity to influence security strategy and risk decisions at the organizational level.
- Ability to build and develop a high-performing security team.
- Opportunity to strengthen established ISO 27001 and SOC 2 programs and lead the path toward SOC 2 Type 2.
- Collaborative environment focused on making security an effective enabler of technology development.
- Opportunity to work in a rapidly scaling SaaS and cloud technology environment.
- Professional growth through exposure to modern cloud, application, infrastructure, compliance, and security challenges.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
- ...Position Summary The Director of Information Security owns Fetch's security function end to end: vulnerability management and AppSec, incident response and forensics, security architecture, GRC/compliance, third-party risk, and security awareness. This role is the...SuggestedFull timeFor contractorsWork at officeRemote workFlexible hours
$135k - $160k
...and continuous growth. Position Summary: Key Responsibilities: • Develop, maintain, and execute the firm’s information security program, roadmap, and annual priorities in alignment with business objectives, client obligations, and regulatory expectations...SuggestedFull timeFixed term contractRemote work- ...Capital One is seeking an experienced Director, Assistant General Counsel for the Global Payment Network - Network Participant Risk. The role advises on legal risks in network participant relationships, including issuers, acquirers, and network alliances. The attorney...Suggested
- ...RTX Corporation is seeking a Director of Product Cyber Supply Chain Risk Management to lead cyber supply chain risk strategy across product... ..., Supply Chain, Quality, and Enterprise Services to embed secure-by-design practices and assurance artifacts throughout development...SuggestedRemote work
- ...Director of Information Security Company: Akamai Work Type: Remote Employment: Full Time Location: US Seniority: Senior Level Technologies: FedRAMP, NIST RMF, NIST SP 800-53, Vulnerability management, Encryption, Security monitoring, Cloud security Requirements: 12+ years...SuggestedFull timeRemote work
- Job DescriptionAdvance Auto Parts is seeking a seasoned and strategic Director of Security Operations to lead the operational arm of our Information Security program. This role is responsible for overseeing the day-to-day execution of security operations, including threat...Work at officeLocal areaRemote work1 day per week
- ...thinkers, and doers. And it's how we're reinventing what's possible every day. Role Description We're looking for a Director of Information Security to lead and mature our security program at a critical inflection point. We've already achieved ISO 27001 and SOC 2...Full timeWork experience placementFlexible hours
- ...Summary Leads the company's cybersecurity program, overseeing governance, risk, compliance, and day-to-day security operations. Responsible for information security across internal systems, cloud solution providers, vendor/third-party solutions, identity and access...Contract workLive inFlexible hoursNight shift
$165k - $185k
...'re the person who keeps that platform fast, reliable, and secure. As Director of DevOps, Security & IT, you'll own how jrni builds, runs,... .... Security & compliance Set the direction for jrni's Information Security program against ISO 27001 and SOC 2. Own and improve...Full timeRemote work- ...The VP of Information Security OR Senior Director OR Head of Security owns the full breadth of information security capabilities across a large, complex global enterprise. This is not a narrow technical role - it carries direct leadership accountability across security...Full timeFor contractorsLocal areaRelocationRelocation package
$154.1k - $264k
...Job Description POSITION PURPOSE The Global Director of Infrastructure, Operations, and Security is a senior leadership role responsible for the reliability... ...to the Global Vice President, Chief Digital & Information Officer, this leader will own global infrastructure...Contract work$200k - $240k
Overview Director of Cloud-Native Security Operations - 245347 Medix is seeking a Director of Cloud-Native Security Operations for one of our top... ...Response (SOAR) practices Leveraging data from Security Information and Event Management (SIEM) platforms to drive proactive...Hourly payFull timeContract workRemote workShift work$141.6k - $283.25k
...people and animals everywhere. Job Details Summary The Senior Director of Cloud Security leads the global strategy, architecture, engineering, and... ...teams, other corporate support functions, and other Information Security organizations to protect the corporate brand, data...Full timeWork experience placementWork at officeLocal area- ...Director of Enterprise Cyber Security Architecture This role has been designed as 'Hybrid' with a requirement that you will work on average 2 days... ...~ Bachelor's degree in Computer Science, Information Systems, Engineering, Cybersecurity, or related field....Work at officeLocal areaImmediate start2 days per week
$199.8k - $270.3k
...Pharmaceuticals, in their search for a Director of Cybersecurity Architecture. This is a... ...Cybersecurity Architecture to define and drive the security architecture strategy that enables... ...early and consistently. Partner with Information Technology and Expertise Areas to align...Full timeTemporary workLocal areaFlexible hours2 days per week- ..., deep relationships, innovation, continuous improvement and accountability. About The Role We are seeking a seasoned Chief Information Security & Privacy Officer (CISO/CPO) responsible for leading our enterprise-wide cybersecurity, data protection, and privacy programs...Full timeTemporary workWork at officeRemote workWork from homeMonday to Friday
- ...Job Description Job Description Director of Cyber Security 10916 The ideal candidate brings deep security operations experience, strong... ...Qualifications ~ Bachelor's degree in Computer Science, Information Security, or a related field. ~10+ years of...Interim role
$205k - $230k
...Director, Security Operations Role Overview The Director of Security Operations leads the organization's day-to-day cybersecurity operations across traditional and AI-enabled environments. Reporting to the CISO, the Director leads Security Operations while partnering...Full timeWork experience placementRemote workFlexible hours- ...Matching Grants Programs. Make your mark in Information Technology At AIG, technology is at the... ...shielding the company’s systems from security risks, while designing technology strategies... .... How you will create an impact The Director of Security Operations Enablement is a senior...Work at office
- ...Fidelity Investments is seeking an experienced Director of Security Operations to lead multiple sites in protecting employees, customers, and property. You will drive Global Security Operations goals, communicate effectively, assess site risk, and champion security initiatives...
$130k - $235k
...Job Summary Leidos has an immediate opening for a Sector Security Director to lead the Leidos Intelligence Sector enterprise security... ...billion for the fiscal year ended January 3, 2025. For more information, visit . Pay and Benefits Pay and benefits are fundamental...Local areaImmediate start$78k - $83k
...Titan Security is built on serving our clients and building careers - just like yours. We are trusted by some of the most well-known companies... ...you! We are seeking an executive-level, strategic Security Director to oversee physical security, risk management, and operational...Permanent employmentContract workWork at officeLocal areaShift work- ...providing immigration sponsorship for this position The Role: The Director, Security Operations is an experienced security professional who can... ...for their unique perspectives and experiences. For information about working at Fidelity, visit FidelityCareers.com. Fidelity...Full timeLocal area
- ...Director of Security Etix is an international, web-based ticketing provider serving entertainment, sports, fairs, and live events across... ...branded apparel for client facing team members. Other Information No sponsorship or H1B situations can be accommodated...Temporary workCasual workH1bWork at officeRemote workRelocationFlexible hours1 day per week
$140k
...we serve thereby righting societal imbalances. The Director of Security is responsible for the strategic leadership, development, and... ...served, staff, and visitors while supporting a trauma-informed, service-oriented environment. The Director of Security will...Work at officeLocal areaRemote work$144.18k - $163.09k
...Assistant Superintendent, Administrative Services, the Director of Safety and Security plans, organizes, directs, supervises, and evaluates a comprehensive... ...office equipment, and telephone. SUPPLEMENTAL INFORMATION APPOINTMENT: In accordance with Education Code...Permanent employmentFull timeWork at officeLocal areaImmediate startTrial periodFlexible hoursAfternoon shift- ...To lead enterprise-wide Environmental Health & Safety (EHS) and security initiatives, the full-time Director of Safety & Security will define strategic risk management frameworks, oversee compliance across multiple sites, and foster a culture of safety within a remote...Full timeRemote work
- ...Senior Security Professional Oracle is now looking for a senior security professional to join our team. This position will be responsible... .... Performs additional functions as directed by the Senior Director, Global Security Operations as necessary to achieve assigned...
$95k - $110k
...Most Offers Expected: $100,000 - $105,000 Are you a seasoned security leader who can protect VIPs, lead emergency response, and build... ...compromising the guest experience? We're seeking an experienced Director of Security & Guest Protection to lead security operations for...$140k - $175k
Director of Security Operations Cyber 429 · Kansas City Company: Cyber 429 (cyber429.com) Location: Kansas City metro area. Hybrid, with time on-site for SOC work and campus operations. Reports to: Founder/CEO, working day-to-day with the COO. Type: Full-time. About...Full timeApprenticeshipWork at officeShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Information Security. Be the first to apply!
- head of security United States
- director of corporate security United States
- chief security officer United States
- director of security United States
- information system security engineer United States
- information security compliance analyst United States
- information security United States
- information security analyst United States
- senior director information security United States
- sr information security engineer United States


