
Senior Director, Information Security
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Colorado.
• Report directly to the Chief Information Security Officer.
• Develop a scalable and business-aligned security program that supports numerous SaaS products across various vertical business units.
• Collaborate with Product Development, Legal, Compliance, the People Team, and senior leadership.
• Implement security baselines, Terraform modules, and AWS Control Tower account isolation.
• Integrate SAST, DAST, SCA, dependency analysis, and TruffleHog scanning into GitHub CI/CD pipelines.
• Create signing, scanning, and approval pipelines for the Central Golden Container Registry.
• Enforce AWS Secrets Manager and Vault architectures with automated secret rotation.
• Oversee the modernization of the SOC, SIEM telemetry, and SOAR automation.
• Utilize eBPF and OpenTelemetry telemetry for infrastructure observability.
• Guide incident response, digital forensics, root cause analysis, and executive crisis communications.
• Lead red-team penetration testing, CTF exercises, and threat modeling across HIPAA, PCI, and proprietary SaaS platforms.
• Transition GRC to an API-driven, continuous control validation approach.
• Maintain a real-time, auditable enterprise Risk Register.
• Standardize vendor risk management and provide automated security assurance documentation.
• Deploy and manage embedded Security Engineering spokes in Vertical Business Units.
• Establish security and cloud training guilds.
• Create multi-year cybersecurity plans and roadmaps, align investments with business priorities, support M&A and divestitures, and drive AI and automation.
• Bachelor's or Master's degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field (or equivalent practical experience).
• Over 12 years of progressive leadership with a substantial focus across various information security domains, including cloud security, software platform security, security strategy, architecture, engineering, controls, testing, vulnerability management, incident response, and cyber resiliency.
• At least 6 years of direct leadership experience managing multi-disciplinary teams in high-growth, public SaaS or enterprise technology companies.
• Hands-on engineering experience with AWS cloud infrastructure, Infrastructure-as-Code (Terraform/CloudFormation), and container orchestration (ECS, EKS, Docker).
• Proficient in building or modernizing SIEM/SOAR pipelines, automated detection engineering, and incident response operations.
• Experience in designing and executing continuous compliance programs under SOX 404(b), HIPAA, PCI DSS, or SEC reporting frameworks.
• Ability to interpret complex security risks into clear business metrics for C-suite executives and Board Audit Committees.
• Strong collaborative skills to lead through influence in a decentralized, multi-business unit operational model.
• In-depth knowledge of enterprise security architecture, security GRC programs, cyber threat landscapes, and attacker TTPs.
• Must be eligible to work without sponsorship.
• Preferred: experience in security due diligence and post-merger integration; familiarity with modern security tools; certifications such as CISSP, CISM, CISA, GMON, CCSP, or AWS Certified Security Specialty; experience with SaaS product teams; experience with distributed and remote teams.
• Flexibility to work in a manner that suits you within your country of employment—whether in-office, remote, or hybrid.
• Immediate access to comprehensive health and wellness benefits, including an annual wellness stipend from Day 1.
• 401k plan with up to a 4% match and immediate vesting.
• Generous and flexible time-off policy (FTO).
• Employee Stock Purchase Program.
Primer
Akamai Technologies
Mashreq
Alice
Get handpicked remote jobs straight to your inbox weekly.