Remotery

Director, Security Architecture – Vulnerability Management and Response

Posted Jul 16

This is a fully remote position, open to applicants in Minnesota.

📋 Description

• Develop and execute a multi-year strategy and roadmap that aligns with Omnissa's risk appetite and business goals.

• Lead, mentor, and expand a globally distributed team of senior security engineers and architects across the AMER and APAC regions.

• Act as the primary escalation point for design conflicts, prioritization of remediation decisions, and for handling security incidents identified through the vulnerability response (PSIRT) process.

• Represent the security function to executive leadership, translating technical risks into business language while reporting on security posture, progress, and investment requirements.

• Collaborate with all business units to establish security standards, conduct architecture and design reviews, and integrate security into every phase of design and implementation.

• Lead the development of security frameworks, hardening standards, and ensure policy compliance throughout the organization.

• Perform risk assessments and gather requirements for new infrastructure, products, and services, ensuring that controls are established prior to deployment.

• Work closely with Product Security and engineering teams to define security architecture requirements throughout the SDLC and CI/CD ecosystem, including threat modeling, architecture standards, SAST, DAST, software composition analysis, secrets detection, and artifact/image signing, ensuring security controls are embedded in development and deployment workflows from design to release.

• Promote secure-by-design practices across the organization, including reference architectures, secure design patterns, and paved-road templates that make secure paths the default for engineering teams, minimizing reliance on post-review processes.

• Oversee the comprehensive Exposure Management program, including tools, scanners, processes, and SLAs that identify, prioritize, and mitigate risks across all environments.

• Take ownership of the enterprise PSIRT strategy, collaborating with the team on vulnerability intake, triage, and coordinated responses for vulnerabilities in Omnissa products and services.


⛳️ Requirements

• A minimum of 10 years in information security, with at least 5 years of experience leading technical security teams (engineering, architecture, and/or Exposure/Vulnerability Management), preferably within global SaaS companies.

• Proven experience in developing and managing enterprise identity security strategies, including IAM/PAM architecture, authentication standards, and identity threat detection.

• Extensive hands-on experience across various domains: cloud and network security, endpoint/workload protection, Exposure/Vulnerability Management, and Product Security/SDLC.

• Familiarity with data governance principles (classification, residency, retention) and key compliance/regulatory frameworks—including GDPR, CCPA, and CMMC, in addition to the aforementioned areas; knowledge of AI risk frameworks is an advantage.

• Demonstrated success in collaborating with engineering teams at a global SaaS company to achieve security outcomes through influence and cooperation rather than mandates.

• Comprehensive experience with the entire risk lifecycle: risk assessment, requirements gathering, control design, tool selection, vendor negotiations, and oversight of remediation activities.

• Exceptional communication skills with the ability to influence both executives and engineers effectively.

• Practical experience working with Product/Application Security teams to integrate security into SDLC and CI/CD pipelines.

• Hands-on knowledge of threat modeling methodologies and achieving secure-by-design results at the architecture stage prior to code development.

• Experience working within a globally distributed team while supporting 24x7 service models.


🏝️ Benefits

• Employee ownership

• Health insurance

• 401k with matching contributions

• Disability insurance

• Paid time off

• Growth opportunities

• Additional perks

People also viewed

LimeJul 26

Senior Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security Engineer$120k/year
ApplyView job
ThreatscapeJul 26

Associate Consultant – Microsoft Security, Purview, Data Security and Governance, AI

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
GFT TechnologiesJul 26

Senior IT Security Project Manager

CR flagCosta Rica OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
BeyondTrustJul 26

VP, Product Management, AI Security – Strategy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
QuisitiveJul 26

Digital Security Coach

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
GEICOJul 25

Senior Field Security Investigator

US flagFlorida OnlyFull-timeCybersecurity / Security Engineer$3,200 – $5,000/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers