
Head of Information Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Take charge of the corporate and product information security strategy, program, and annual objectives; establish a prioritized roadmap and align security resources and investment requirements with the COO.
• Drive the enhancement of technical security capabilities across cloud infrastructure, product security, identity management, vulnerability management, detection and response, and security architecture.
• Lead and nurture the CyberDefense and Product Security teams; establish priorities, performance expectations, and accountability for both internal personnel and external providers.
• Supervise the GRC program and manage audit coordination, evidence collection, policy formulation, assessments, remediation tracking, and Vanta administration.
• Ensure audit readiness and oversee necessary audits, certifications, and attestations.
• Evaluate significant cyber risks, challenge risk ratings and treatment plans, approve security exceptions within delegated authority, and escalate business risk acceptance as needed.
• Collaborate with Engineering, Product, DevOps, and IT leadership to integrate security into architecture, development, and operational processes.
• Provide senior security guidance during significant incidents and ensure testing of incident response, disaster recovery, and business continuity capabilities.
• Address cross-functional security decisions that impact delivery, customer commitments, or business risk.
• Communicate security posture, significant risks, incidents, remediation performance, emerging threats, and investment priorities to executive leadership and the Board.
• Act as Accumulus’ senior security representative to customers, prospects, regulators, auditors, partners, and insurers.
• Oversee the customer security assurance program, including discussions with customers and prospects, due diligence, RFPs, and security assessments.
• Extensive progressive experience in information security, including leadership of a corporate or product security function and responsibility for security strategy and program implementation.
• Proven ability to manage and develop internal security teams while holding external contractors or service providers accountable for their results.
• Required knowledge of Vanta and familiarity with ISO 27001, SOC 2, and HITRUST; practical experience in overseeing GRC programs, audits, evidence readiness, and remediation efforts.
• Strong understanding of cloud and SaaS security, secure development practices, identity and access management, encryption, vulnerability management, monitoring, and incident response.
• Experience in assessing cyber risk, evaluating the effectiveness of controls, governing security exceptions, and translating technical findings into business decisions.
• Demonstrated capability to lead customer security reviews and questionnaires, effectively communicating security posture to executives, auditors, regulators, and technical stakeholders.
• Experience coordinating responses, recovery efforts, resilience testing, and follow-through on corrective actions.
• Ability to prioritize competing demands, influence cross-functional teams, and make practical, risk-based security decisions that support product delivery and commercial objectives while safeguarding the company’s security and assurance commitments.
• Discretionary bonus of 22%.
• 3% contribution to a 401(k), even if you do not make contributions.
• Medical, dental, vision, short-term disability, long-term disability, and life insurance provided from day one.
• Unlimited vacation policy.
• Up to 16 weeks of parental leave.
Robots & Pencils
Latitude IT Solutions | SDVOSB
Latitude IT Solutions | SDVOSB
11:11 SYSTEMS
Get handpicked remote jobs straight to your inbox weekly.