Director of Information Security
Fetch
Director Of Information Security
The Director of Information Security owns Fetch's security function end to end: vulnerability management and AppSec, incident response and forensics, security architecture, GRC/compliance, third-party risk, and security awareness. This role is the senior full-time security leader for the company, taking day-to-day ownership of the security program. The Director of Information Security is the dedicated, always-on owner of the security posture; someone who can run point on a critical incident, drive a vulnerability program to completion, and build the compliance backbone the company needs as it scales.
Role Purpose
- Own the security function's day-to-day execution.
- Reduce the company's exposure to high-blast-radius security risk, AI agent architecture, and application security.
- Build a mature, auditable, and scalable security program (policy, controls, evidence, reporting) ahead of compliance and customer-trust demands.
- Lead and grow a Security team, providing the people management the function has lacked.
- Serve as the primary technical authority and incident commander for security events.
- Represent Information Security credibly to executives, auditors, customers, and partners.
Key Responsibilities
1. Security Engineering & Vulnerability Management
- Own the AppSec and vulnerability management program (Snyk and adjacent tooling), including pack ownership, CI/CD security gating, and repository risk classification processes.
- Drive vulnerability remediation SLAs and hold engineering accountable to them.
- Continuously mature the program from reactive scanning toward proactive, gated prevention.
2. Incident Response & Forensics
- Act as an incident commander for security incidents, including coordinating cross-functional response, containment, and communication.
- Own the bug bounty and continuous penetration testing disclosure program: triage, validation, remediation tracking, and researcher communication.
- Facilitate post-incident reviews and root-cause analysis, with particular attention to recurring architectural risk patterns.
- Ensure remediation of systemic issues, not just point fixes and elevate platform-level fixes when the same root cause recurs across incidents.
3. Security Architecture & Emerging Risk
- Own security architecture review for new systems, platforms, and AI agent deployments, including AI agent identity and access patterns (eg, cross-app access, delegated identity).
- Maintain security standards for cloud infrastructure, endpoint protection, and network/edge security.
- Partner with IT Operations on identity-related risk (entitlement sprawl, contractor and non-employee access, and access governance) providing the security requirements and risk lens that IT Operations executes against.
4. GRC, Policy & Compliance
- Own the security policy library, risk register, and control framework; keep them current and audit-ready.
- Lead internal and external audits and assessments, coordinating evidence collection across IT, Engineering, and Legal.
- Report program maturity, open risk, and remediation progress to executive leadership on a regular cadence.
- Oversee processes to update and maintain the Enterprise Security Risk Register.
5. AI Governance & Emerging Technology Risk
- Partner with the Chief AI Officer on the security dimensions of AI governance, including enforcement of AI acceptable-use policy and identification of security risk in new AI tooling and agent deployments.
- Provide the security review and risk sign-off for new AI platforms, agents, and integrations prior to broad rollout.
6. Third-Party & Vendor Risk
- Own vendor and third-party security risk assessment for new tools, integrations, and contractors.
- Maintain a defensible, repeatable process for evaluating vendor security posture before onboarding.
7. Security Awareness & Culture
- Own company-wide security awareness programming, phishing simulation, and targeted training following incidents or audit findings.
- Build blameless, clear communications that raise the organization's security literacy without creating fear or confusion.
8. Team Leadership & People Management
- Hire, coach, and develop the Security Engineering team.
- Set team priorities, run performance management, and build a growth path for security engineers.
- Establish team operating rhythm: on-call/incident rotation, backlog grooming, and technical review standards.
9. Executive & Cross-Functional Communication
- Own the security content in recurring executive reporting.
- Represent Information Security in cross-functional forums (Legal, AI governance, IT Operations, Engineering leadership).
- Escalate material risk, resourcing gaps, or unresolved cross-functional blockers promptly and clearly.
Required Qualifications
- 7+ years in information security, including meaningful experience in application security, incident response, and security architecture.
- Demonstrated experience running vulnerability management programs at scale (eg, Snyk or comparable tooling).
- Direct incident command experience, including coordinating cross-functional response to significant security events.
- People management experience, ideally building or scaling a security engineering team.
- Working knowledge of cloud security, identity and access management concepts, and modern AI/agent architecture risk.
- Strong written and verbal communication skills, including comfort presenting to executive audiences.
Preferred Qualifications
- Experience with bug bounty/responsible disclosure program management.
- Experience building or maturing a GRC program, including audit and compliance framework experience (SOC 2, ISO 27001).
- Familiarity with AI agent security risk, including MCP-style tool/agent architectures and identity delegation patterns.
- Experience partnering with AI governance or data governance functions.
- Relevant certifications (CISSP, CISM, or equivalent).
Core Competencies
- Incident command and crisis leadership
- Security architecture and risk assessment
- Program and process maturity building
- People leadership and coaching
- Executive communication
- Cross-functional influence without direct authority over partner teams
- Judgment under ambiguity and time pressure
$170.5k - $272.75k
...technology company delivering mission-critical solutions to government and commercial customers. We are seeking an experienced Director of Information Security to lead our cybersecurity program and ensure the protection of sensitive national security information.SummaryThe...SuggestedPermanent employmentFull timeContract workFor contractorsWork experience placementWork at officeRemote work- Job Posting:JR101916 Director of Information Security (Open)Department:Information Technology, PMPosition Type:RegularOpen Date:06-30-2026Close Date:$140,000 - $150,000Job Description:The Director of Information Security position is responsible for developing and executing...SuggestedFull timeWork at office
- Posting Details Announcement Information Job SummaryThe Center for Information Technology (CIT) invites qualified applicants for the position of Director of Information Security, a strategic leadership role responsible for advancing Oberlin College & Conservatory’s enterprise...SuggestedFull timeContract workWork at office
$160k - $170k
Position Details Position Information About HofstraHofstra University is nationally ranked... ...CategoryAdministrationSchool/DivisionITS Information Security (division)DepartmentITS Information... ...Chief Information Officer (CIO), the Director of Information Security is a member of...SuggestedFull timeWork experience placement$160k - $180k
...Job Description: The Senior Director of Information Security serves as Berklee’s primary information security authority and hands-on technical leader. Operating in a high-impact, lean team environment, the Sr. Director balances strategic governance, policy development...SuggestedFull timeContract workWork at officeLocal areaNight shiftWeekend work- Job Requirements Phenom is looking for a Director of Security & Trust Enablement to build and scale the services that connect our Security... ...QualificationsBachelor’s degree or higher in Cybersecurity, Information Technology, or related field5+ years of experience in cybersecurity...
- New York, New YorkHybridFull Time$180k - $220kJob Title: Director of Information Security / CISOLocation: New York, NY (Hybrid)This established data management and secure communications firm provides critical information services to highly regulated industries. Operating...
- ...RTX Corporation is seeking a Director of Product Cyber Supply Chain Risk Management to lead cyber supply chain risk strategy across product... ..., Supply Chain, Quality, and Enterprise Services to embed secure-by-design practices and assurance artifacts throughout development...Remote work
- ...To lead information security initiatives, the full-time Senior Director of Information Security will manage strategic governance, policy development, and budget oversight while providing hands-on technical leadership in a remote environment. Key responsibilities Establish...Full timeRemote work
- ...MMC in Harlan, IA seeks an Information Systems Director to oversee the IS department, security, and system implementations. The role partners with various departments to align technology with organizational needs and to ensure robust security and reliable operations. The...
- ...Summary: Leads the company's cybersecurity program, overseeing governance, risk, compliance, and day-to-day security operations. Responsible for information security across internal systems, cloud solution providers, vendor/third-party solutions, identity and access...Contract workLive inFlexible hoursNight shift
- ...Director of Information Security A global industrial technology company is hiring a Director of Information Security to lead its enterprise cybersecurity program from its Westford, MA headquarters. This full-time leadership role is responsible for driving security...Full time
- ...We're looking for a hands-on, detail-oriented Information Security Director to take ownership of leading both our internal Information Security and Information Systems. In this role, you'll lead the implementation and management of our security operations, policies,...
$105k - $130k
...Director of Information Security Bookmark this Posting Print Preview | Apply for this Job Position Details Position Information Position Title Director of Information Security Department Information Services - Office of VP -Group Pay Type Exempt Appointment...Full timeH1bWork at officeRemote workRelocationWork visa$200k - $275k
...Director Of Information Security We are a renewable energy and ocean technology company committed to rapidly developing and deploying technologies that will ensure a sustainable future for Earth by unlocking the vast energy potential of its oceans. Our focus is on...Full timeWork at officeRelocation packageFlexible hours- ...Director of Information Security Duration: Full-Time Location: Remote About BigRio : BigRio is a Digital Transformation consulting firm headquartered in Boston, MA, specializing in data and analytics, custom development, software implementation, data...Full timeRemote work
- ...Director Of Information And Security Our client is seeking a Director of Information and Security to lead global IT operations across cybersecurity, infrastructure, cloud services, server management, DevOps, Disaster Recovery as a Service (DRaaS), and desktop support...
- ...contract This role is hybrid, with 3 days onsite in Boston , MA expected Locals only Title: Director of Information Security # Open (if applicable): 1 Location: 216 Mass Avenue, Boston, MA 02115 -they are by the Christian...Full timeContract workFor contractorsWork experience placementWork at officeLocal areaShift work
$112k - $190.5k
...benefit society that provides financial security to members and their families through our... ...-Hybrid Overview The Associate Director of Governance, Risk, and Compliance (GRC) is a resourceful and experienced information security leader responsible for managing,...Full timeTemporary workWork experience placementFlexible hours- ...Regal Rexnord is seeking a Senior Director, Corporate Security to lead a global program protecting people, facilities, assets and reputation. Based at Rosemont, IL with a hybrid schedule, you will manage 3 direct reports and partner across Legal, HR, EHS, IT Security,...
- ...We are seeking a Director, Central Accounting - Record to Report (R2R) to lead Versant's centralized enterprise-wide R2R accounting operations. Reporting to the Senior Director, Global Record to Report, this role is responsible for delivering efficient, timely, accurate...
$137.4k - $206.2k
Job Summary: The Director of Security Engineering is responsible for leading enterprise security architecture, engineering, and exposure management... ...:Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline;...Hourly payMinimum wageFull timeLocal area- ...Executive Director Of Security & Information ProtectionOdyssey is seeking an Executive Director of Security & Information Protection to lead the recently formed Security & Information Protection group. This role carries enterprise-level responsibility for both strategic...Contract workFor contractorsWork experience placementRemote work
- ...Titan Security seeks a Security Director to oversee total physical security, public safety, and on-site operations at a major Chicago mixed-use center. Ideal candidate has 5+ years in security leadership, with a track record in large-scale environments; PERC license and...
$169.01k - $370.53k
...and governance of IAM solutions leveraging SailPoint Identity Security Cloud (ISC), Saviynt, CyberArk, and related technologies to address... ...from an accredited college/university in computer science, information security, information systems, engineering, or a related field...H1bLocal area- ...policy.Establish and maintain a Responsible Accountable Consulted Informed (RACI) model across ORS, OESC, departmental IT, lab managers,... ..., and PI onboarding materials; maintain a TTU research-security web hub & FAQs.Define continuous monitoring requirements and evidence...Contract workTemporary workWork at office
- ...Director Of Security OperationsAdvance Auto Parts is seeking a seasoned and strategic Director of Security Operations to lead the operational arm of our Information Security program. This role is responsible for overseeing the day-to-day execution of security operations...Work at officeLocal areaRemote work1 day per week
- ...Clover Health is seeking a Director of Governance, Risk, and Compliance (GRC) to define and execute security governance and risk strategy for a public, technology-enabled healthcare company. The role leads enterprise-level governance, risk decisions, and compliance readiness...
- Summit Pacific Medical Center in Elma, Washington, seeks an experienced IT leader to plan and oversee technology services across the district, including the Electronic Health Record (EHR), ERP, and payroll systems. You will drive upgrades, governance, and 24/7 operational...
- ...E-logic, Inc. seeks an experienced Security Director to design, implement, and govern the cybersecurity program (GRC) for the State of Texas DIR STS SecOps contract. The role ensures compliance with NIST, PCI-DSS, IRS 1075, CJIS, and HIPAA while guiding enterprise security...Contract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Director of Information Security. Be the first to apply!
- director of corporate security United States
- chief security officer United States
- director of security United States
- head of security United States
- data center security officer United States
- sr information security engineer United States
- senior information security analyst United States
- information system security engineer United States
- data security manager United States
- director information security United States

