
Director, Security Architecture – Vulnerability Management and Response
Posted Jul 16

Posted Jul 16
This is a fully remote position, open to applicants in Minnesota.
• Develop and execute a multi-year strategy and roadmap that aligns with Omnissa's risk appetite and business goals.
• Lead, mentor, and expand a globally distributed team of senior security engineers and architects across the AMER and APAC regions.
• Act as the primary escalation point for design conflicts, prioritization of remediation decisions, and for handling security incidents identified through the vulnerability response (PSIRT) process.
• Represent the security function to executive leadership, translating technical risks into business language while reporting on security posture, progress, and investment requirements.
• Collaborate with all business units to establish security standards, conduct architecture and design reviews, and integrate security into every phase of design and implementation.
• Lead the development of security frameworks, hardening standards, and ensure policy compliance throughout the organization.
• Perform risk assessments and gather requirements for new infrastructure, products, and services, ensuring that controls are established prior to deployment.
• Work closely with Product Security and engineering teams to define security architecture requirements throughout the SDLC and CI/CD ecosystem, including threat modeling, architecture standards, SAST, DAST, software composition analysis, secrets detection, and artifact/image signing, ensuring security controls are embedded in development and deployment workflows from design to release.
• Promote secure-by-design practices across the organization, including reference architectures, secure design patterns, and paved-road templates that make secure paths the default for engineering teams, minimizing reliance on post-review processes.
• Oversee the comprehensive Exposure Management program, including tools, scanners, processes, and SLAs that identify, prioritize, and mitigate risks across all environments.
• Take ownership of the enterprise PSIRT strategy, collaborating with the team on vulnerability intake, triage, and coordinated responses for vulnerabilities in Omnissa products and services.
• A minimum of 10 years in information security, with at least 5 years of experience leading technical security teams (engineering, architecture, and/or Exposure/Vulnerability Management), preferably within global SaaS companies.
• Proven experience in developing and managing enterprise identity security strategies, including IAM/PAM architecture, authentication standards, and identity threat detection.
• Extensive hands-on experience across various domains: cloud and network security, endpoint/workload protection, Exposure/Vulnerability Management, and Product Security/SDLC.
• Familiarity with data governance principles (classification, residency, retention) and key compliance/regulatory frameworks—including GDPR, CCPA, and CMMC, in addition to the aforementioned areas; knowledge of AI risk frameworks is an advantage.
• Demonstrated success in collaborating with engineering teams at a global SaaS company to achieve security outcomes through influence and cooperation rather than mandates.
• Comprehensive experience with the entire risk lifecycle: risk assessment, requirements gathering, control design, tool selection, vendor negotiations, and oversight of remediation activities.
• Exceptional communication skills with the ability to influence both executives and engineers effectively.
• Practical experience working with Product/Application Security teams to integrate security into SDLC and CI/CD pipelines.
• Hands-on knowledge of threat modeling methodologies and achieving secure-by-design results at the architecture stage prior to code development.
• Experience working within a globally distributed team while supporting 24x7 service models.
• Employee ownership
• Health insurance
• 401k with matching contributions
• Disability insurance
• Paid time off
• Growth opportunities
• Additional perks
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.