
Director of Information Security and Operations
Posted Jul 27

Posted Jul 27
This is a fully remote position, open to applicants in United States.
• Establish the strategic direction for jrni's Information Security program in alignment with ISO 27001 and SOC 2.
• Take ownership of and enhance operational controls to meet the requirements of ISO 27001, SOC 2, GDPR, and other relevant frameworks.
• Manage JRNI's AI security policy and governance standards, ensuring alignment with NIST AI RMF and ISO 42001.
• Lead AI Operations to leverage AI for improved efficiency while ensuring that AI systems are governed to mitigate privacy and security risks.
• Collaborate with Legal and external auditors for audits, evidence gathering, and certification renewals.
• Cultivate a culture of security awareness, data protection, and compliance, including comprehensive training programs.
• Oversee and enhance production cloud infrastructure for scalability, reliability, and compliance requirements.
• Work closely with Engineering / SRE teams on CI/CD processes, release management, and maintaining production stability.
• Supervise monitoring, alerting, and observability efforts to proactively address issues.
• Develop and test disaster recovery and business continuity strategies.
• Lead the management of vulnerabilities, patching, and hardening initiatives across the organization.
• Own the security and operational incident response plans, conducting tabletop exercises to prepare.
• Act as the incident commander for Sev-1/Sev-2 incidents, coordinating efforts with customers, Legal, and executive teams.
• Facilitate blameless post-incident reviews and ensure remediation efforts are tracked to completion.
• Maintain a risk register and conduct periodic enterprise risk assessments.
• Manage third-party and vendor risk, including vendor assessments, Data Processing Agreements (DPAs), and oversight of sub-processors.
• Supervise Identity and Access Management (IAM) across both corporate (SSO, MFA, SCIM) and production environments (least-privilege, JIT access, break-glass), including access reviews and joiner/mover/leaver processes.
• Oversee JRNI's cyber insurance relationship and manage renewals.
• Enhance processes to boost productivity, scalability, and readiness for audits.
• Utilize automation to optimize workflows and enhance compliance reporting.
• Develop and manage the operational budget concerning personnel, technology, and vendors.
• Collaborate with Customer Success to ensure high-quality service delivery and operational excellence.
• Build, mentor, and retain high-performing, engaged InfoSec and TechOps teams.
• Define clear career paths, performance objectives, and development plans for team members.
• Promote a blameless, learning-focused culture within the organization.
• Collaborate across Sales, Customer Success, Product, and Engineering teams.
• Manage responses to customer security questionnaires (SIG, CAIQ), RFPs, and audit requests, while maintaining a customer-facing trust center.
• Serve as the security executive sponsor during enterprise sales cycles.
• Partner with Legal and Product teams on matters related to data residency, classification, retention/deletion, and Data Subject Access Request (DSAR) fulfillment.
• Establish Key Performance Indicators (KPIs) such as uptime, Mean Time to Detect (MTTD)/Mean Time to Respond (MTTR), audit closure rates, remediation Service Level Agreements (SLAs), and Customer Satisfaction (CSAT), reporting these metrics to executives and the Board.
• Extensive experience in Information Security and/or IT Operations, with a proven track record of leading multiple teams.
• Demonstrated experience managing SOC 2 Type II and ISO 27001 audits from start to finish.
• Proficient in operating production SaaS infrastructure at scale on AWS and GCP, with strong expertise in cloud, network, application security, and DevSecOps practices.
• Hands-on experience with Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR), vulnerability scanning tools, and Cloud Security Posture Management (CSPM) platforms.
• Proven leadership in incident response for production SaaS environments.
• Excellent executive communication skills, comfortable engaging with the Board, customers, and auditors.
• Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent professional experience.
• Certifications such as CISSP, CISM, CISA, AWS Security Specialty, or ISO 27001 Lead Auditor/Implementer are desirable.
• Experience with HIPAA, PCI-DSS, or FedRAMP compliance is a plus.
• Familiarity with AI/ML governance frameworks (NIST AI RMF, ISO 42001) and securing AI-enabled products is advantageous.
• Experience in defining and managing customer-facing trust programs is a plus.
• Opportunities for professional development.
• Flexible work arrangements.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.