
Senior Director, Information Security
Posted 19 hours ago

Posted 19 hours ago
This is a fully remote position, open to applicants in United States.
• Report to the Chief Information Security Officer to enhance a scalable, business-oriented security program.
• Collaborate with Platform Engineering to implement security baselines, Terraform modules, and AWS Control Tower account separations.
• Integrate SAST, DAST, SCA, dependency analysis, and TruffleHog scanning within GitHub CI/CD pipelines.
• Set up signing, scanning, and approval processes for the Central Golden Container Registry.
• Enforce AWS Secrets Manager and Vault architectures alongside automated secret rotation.
• Oversee the modernization of the 24x7 Security Operations Center, SIEM telemetry, and SOAR automation.
• Utilize eBPF and OpenTelemetry telemetry to identify unauthorized access, abnormal queries, and lateral movements.
• Lead enterprise incident response, digital forensics, root cause analysis, and executive crisis communications.
• Manage red-team penetration testing, Capture the Flag exercises, and threat modeling for HIPAA, PCI, and proprietary SaaS platforms.
• Transition GRC to an API-driven continuous control validation approach for SOX 404(b), HIPAA, PCI DSS, NIST CSF, EHNAC, and SEC standards.
• Maintain a real-time, auditable enterprise Risk Register.
• Standardize vendor risk management and deliver automated security assurance documentation for customer agreements.
• Deploy and lead embedded Security Engineering spokes within Vertical Business Units.
• Create security and cloud training guilds.
• Formulate multi-year cybersecurity strategies and roadmaps, aligning investments with business goals.
• Provide cybersecurity support for mergers, acquisitions, and divestitures.
• Promote AI and automation across security operations.
• Motivate teams, cultivate security leaders, nurture stakeholder relationships, communicate risk, and enhance cross-business collaboration.
• Travel to the Denver headquarters or other North American offices as required.
• Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field (or equivalent practical experience).
• 12+ years of progressive leadership experience across diverse information security domains.
• 6+ years of direct leadership experience managing multi-disciplinary teams in high-growth, public SaaS or enterprise technology firms.
• Hands-on engineering experience with AWS cloud infrastructure, Infrastructure-as-Code (Terraform/CloudFormation), and container orchestration (ECS, EKS, Docker).
• Proven experience in building or modernizing SIEM/SOAR pipelines, automated detection engineering, and incident response operations.
• Background in designing and implementing continuous compliance programs under SOX 404(b), HIPAA, PCI DSS, or SEC reporting frameworks.
• Capability to translate complex security risks into business metrics for C-suite executives and Board Audit Committees.
• Strong collaborative skills and ability to lead through influence in a decentralized, multi-business-unit operating environment.
• Comprehensive knowledge of enterprise security architecture, security GRC programs, and cyber threat landscapes, including attacker TTPs.
• Must be eligible to work without sponsorship.
• Preferred: experience in security due diligence and post-merger integration.
• Preferred: familiarity with Information Asset Inventory systems, Elastic Cloud, Torq SOAR, CrowdStrike, EDR/MDR/XDR, Okta, Netskope, AWS Secrets Manager, PAM, TruffleHog, and Lumos AI.
• Preferred: certifications such as CISSP, CISM, CISA, GMON, CCSP, AWS Certified Security Specialty, or similar credentials.
• Preferred: experience in SaaS software development/product teams.
• Preferred: experience working with distributed and remote teams.
• Flexibility to work in the manner you choose within your country of employment – in-office, remote, or hybrid.
• Immediate access to a comprehensive health and wellness benefits package, including an annual wellness stipend.
• 401k plan with up to a 4% match and immediate vesting.
• Flexible and generous (FTO) time-off policy.
• Employee Stock Purchase Program.
• Variable compensation component available in most US locations.
VAILEXA
NatWest Group
Inviso
Atlas Governance
Get handpicked remote jobs straight to your inbox weekly.