Remotery

Director of Information Security and Operations

Posted Jul 27

This is a fully remote position, open to applicants in United States.

📋 Description

• Establish the strategic direction for jrni's Information Security program in alignment with ISO 27001 and SOC 2.

• Take ownership of and enhance operational controls to meet the requirements of ISO 27001, SOC 2, GDPR, and other relevant frameworks.

• Manage JRNI's AI security policy and governance standards, ensuring alignment with NIST AI RMF and ISO 42001.

• Lead AI Operations to leverage AI for improved efficiency while ensuring that AI systems are governed to mitigate privacy and security risks.

• Collaborate with Legal and external auditors for audits, evidence gathering, and certification renewals.

• Cultivate a culture of security awareness, data protection, and compliance, including comprehensive training programs.

• Oversee and enhance production cloud infrastructure for scalability, reliability, and compliance requirements.

• Work closely with Engineering / SRE teams on CI/CD processes, release management, and maintaining production stability.

• Supervise monitoring, alerting, and observability efforts to proactively address issues.

• Develop and test disaster recovery and business continuity strategies.

• Lead the management of vulnerabilities, patching, and hardening initiatives across the organization.

• Own the security and operational incident response plans, conducting tabletop exercises to prepare.

• Act as the incident commander for Sev-1/Sev-2 incidents, coordinating efforts with customers, Legal, and executive teams.

• Facilitate blameless post-incident reviews and ensure remediation efforts are tracked to completion.

• Maintain a risk register and conduct periodic enterprise risk assessments.

• Manage third-party and vendor risk, including vendor assessments, Data Processing Agreements (DPAs), and oversight of sub-processors.

• Supervise Identity and Access Management (IAM) across both corporate (SSO, MFA, SCIM) and production environments (least-privilege, JIT access, break-glass), including access reviews and joiner/mover/leaver processes.

• Oversee JRNI's cyber insurance relationship and manage renewals.

• Enhance processes to boost productivity, scalability, and readiness for audits.

• Utilize automation to optimize workflows and enhance compliance reporting.

• Develop and manage the operational budget concerning personnel, technology, and vendors.

• Collaborate with Customer Success to ensure high-quality service delivery and operational excellence.

• Build, mentor, and retain high-performing, engaged InfoSec and TechOps teams.

• Define clear career paths, performance objectives, and development plans for team members.

• Promote a blameless, learning-focused culture within the organization.

• Collaborate across Sales, Customer Success, Product, and Engineering teams.

• Manage responses to customer security questionnaires (SIG, CAIQ), RFPs, and audit requests, while maintaining a customer-facing trust center.

• Serve as the security executive sponsor during enterprise sales cycles.

• Partner with Legal and Product teams on matters related to data residency, classification, retention/deletion, and Data Subject Access Request (DSAR) fulfillment.

• Establish Key Performance Indicators (KPIs) such as uptime, Mean Time to Detect (MTTD)/Mean Time to Respond (MTTR), audit closure rates, remediation Service Level Agreements (SLAs), and Customer Satisfaction (CSAT), reporting these metrics to executives and the Board.


⛳️ Requirements

• Extensive experience in Information Security and/or IT Operations, with a proven track record of leading multiple teams.

• Demonstrated experience managing SOC 2 Type II and ISO 27001 audits from start to finish.

• Proficient in operating production SaaS infrastructure at scale on AWS and GCP, with strong expertise in cloud, network, application security, and DevSecOps practices.

• Hands-on experience with Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), vulnerability scanning tools, and Cloud Security Posture Management (CSPM) platforms.

• Proven leadership in incident response for production SaaS environments.

• Excellent executive communication skills, comfortable engaging with the Board, customers, and auditors.

• Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent professional experience.

• Certifications such as CISSP, CISM, CISA, AWS Security Specialty, or ISO 27001 Lead Auditor/Implementer are desirable.

• Experience with HIPAA, PCI-DSS, or FedRAMP compliance is a plus.

• Familiarity with AI/ML governance frameworks (NIST AI RMF, ISO 42001) and securing AI-enabled products is advantageous.

• Experience in defining and managing customer-facing trust programs is a plus.


🏝️ Benefits

• Opportunities for professional development.

• Flexible work arrangements.

People also viewed

ASG Technologies6 hours ago

IT Security Director

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$165k – $190k/year
ApplyView job
CrowdStrike6 hours ago

Associate Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$70k – $95k/year
ApplyView job
Culmen International7 hours ago

Border Security Trainer

US flagUnited States OnlyFreelanceCybersecurity / Security Engineer
ApplyView job
Threatscape7 hours ago

Security Consultant – Purview

GB flagUnited Kingdom, +1 more countryFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
Unity8 hours ago

Staff Security Architect

US flagTexas OnlyFull-timeCybersecurity / Security Engineer$160.3k – $305.4k/year
ApplyView job
Truist10 hours ago

Cybersecurity Group Manager

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers