
Director of IT Security
Posted Jun 30

Posted Jun 30
This is a fully remote position, open to applicants in California, +4 more states.
• Develop and implement the organization's information security strategy along with a scalable security roadmap.
• Establish and uphold enterprise security policies, standards, and governance frameworks.
• Present cybersecurity risks, recommendations, and security metrics to executive leadership.
• Collaborate with department leaders to integrate security into business operations and decision-making processes.
• Stay informed about emerging cybersecurity threats, AI risks, and industry best practices.
• Conduct ongoing cybersecurity risk assessments across the enterprise, including infrastructure, endpoints, applications, and business processes.
• Build and maintain the organization's cybersecurity risk register and remediation roadmap.
• Lead vulnerability management initiatives and prioritize remediation efforts based on business risk.
• Conduct security assessments of third-party vendors and manage ongoing vendor risk.
• Continuously evaluate new technologies and recommend enhancements to security measures.
• Oversee the organization's incident response program, which includes playbooks, tabletop exercises, and post-incident reviews.
• Manage endpoint security, identity and access management, privileged access controls, MFA, and device security.
• Partner with the Senior IT Manager to implement technical security controls and monitor the security environment's health.
• Coordinate with external security vendors and managed security service providers as needed.
• Develop and oversee business continuity and disaster recovery planning initiatives.
• Lead compliance initiatives related to security, including SOC 2 Type II and future security certifications.
• Manage customer security questionnaires and support enterprise sales opportunities by showcasing Directive's security posture.
• Collaborate with Legal, Insurance, and Finance teams on privacy, data governance, and regulatory compliance matters.
• Maintain documentation for security policies, controls, audits, and evidence collection.
• Build and/or manage organization-wide security awareness and phishing training programs.
• Foster a security-first culture throughout the organization.
• Educate employees about evolving cybersecurity threats, social engineering, AI usage, and data protection best practices.
• Establish security metrics and regularly report on the organization's security maturity.
• Minimum of 7 years of experience in cybersecurity, information security, or risk management.
• At least 3 years of experience leading enterprise security programs or security teams.
• Proven experience conducting cybersecurity risk assessments and threat modeling.
• Strong knowledge of cloud-first and SaaS-based environments, including Google Workspace, Salesforce, NetSuite, Okta, and modern identity platforms.
• Experience in implementing and maintaining security frameworks such as SOC 2, ISO 27001, or the NIST Cybersecurity Framework.
• In-depth understanding of endpoint security, identity management, vulnerability management, incident response, and security operations.
• Experience working in fully remote organizations supporting distributed workforces.
• Excellent executive communication skills with the ability to convey technical risks in terms of business impact.
• CISSP, CISM, CRISC, or equivalent cybersecurity certification is highly preferred.
• Medical, dental, and vision plans, along with disability and life insurance coverage for you and your family that align with your lifestyle.
• Includes a 100% employer-paid plan for you and a 50% employer contribution for your dependents.
• Mental health support - Access to certified therapists through Spring Health and a membership to Headspace.
• Physical health support - Physical therapy through Omada, fertility assistance through Carrott, thousands of Aaptiv virtual workouts, and a complimentary One Medical membership for primary and virtual care.
• Unlimited PTO (minimum of 2 weeks), Paid Company Holidays, Your Birthday Off, End of Year Recharge (Closed from December 24 to January 1), and Paid Parental Leave.
• Traditional and Roth 401(k) plans with a 3% company match.
• Annual bonus based on tenure, which increases in total amount over time.
GuidePoint Security
Redpanda Data
CyberSheath
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.