Senior Director, Information Security

Posted 19 hours ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Report to the Chief Information Security Officer to enhance a scalable, business-oriented security program.

• Collaborate with Platform Engineering to implement security baselines, Terraform modules, and AWS Control Tower account separations.

• Integrate SAST, DAST, SCA, dependency analysis, and TruffleHog scanning within GitHub CI/CD pipelines.

• Set up signing, scanning, and approval processes for the Central Golden Container Registry.

• Enforce AWS Secrets Manager and Vault architectures alongside automated secret rotation.

• Oversee the modernization of the 24x7 Security Operations Center, SIEM telemetry, and SOAR automation.

• Utilize eBPF and OpenTelemetry telemetry to identify unauthorized access, abnormal queries, and lateral movements.

• Lead enterprise incident response, digital forensics, root cause analysis, and executive crisis communications.

• Manage red-team penetration testing, Capture the Flag exercises, and threat modeling for HIPAA, PCI, and proprietary SaaS platforms.

• Transition GRC to an API-driven continuous control validation approach for SOX 404(b), HIPAA, PCI DSS, NIST CSF, EHNAC, and SEC standards.

• Maintain a real-time, auditable enterprise Risk Register.

• Standardize vendor risk management and deliver automated security assurance documentation for customer agreements.

• Deploy and lead embedded Security Engineering spokes within Vertical Business Units.

• Create security and cloud training guilds.

• Formulate multi-year cybersecurity strategies and roadmaps, aligning investments with business goals.

• Provide cybersecurity support for mergers, acquisitions, and divestitures.

• Promote AI and automation across security operations.

• Motivate teams, cultivate security leaders, nurture stakeholder relationships, communicate risk, and enhance cross-business collaboration.

• Travel to the Denver headquarters or other North American offices as required.


⛳️ Requirements

• Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical field (or equivalent practical experience).

• 12+ years of progressive leadership experience across diverse information security domains.

• 6+ years of direct leadership experience managing multi-disciplinary teams in high-growth, public SaaS or enterprise technology firms.

• Hands-on engineering experience with AWS cloud infrastructure, Infrastructure-as-Code (Terraform/CloudFormation), and container orchestration (ECS, EKS, Docker).

• Proven experience in building or modernizing SIEM/SOAR pipelines, automated detection engineering, and incident response operations.

• Background in designing and implementing continuous compliance programs under SOX 404(b), HIPAA, PCI DSS, or SEC reporting frameworks.

• Capability to translate complex security risks into business metrics for C-suite executives and Board Audit Committees.

• Strong collaborative skills and ability to lead through influence in a decentralized, multi-business-unit operating environment.

• Comprehensive knowledge of enterprise security architecture, security GRC programs, and cyber threat landscapes, including attacker TTPs.

• Must be eligible to work without sponsorship.

• Preferred: experience in security due diligence and post-merger integration.

• Preferred: familiarity with Information Asset Inventory systems, Elastic Cloud, Torq SOAR, CrowdStrike, EDR/MDR/XDR, Okta, Netskope, AWS Secrets Manager, PAM, TruffleHog, and Lumos AI.

• Preferred: certifications such as CISSP, CISM, CISA, GMON, CCSP, AWS Certified Security Specialty, or similar credentials.

• Preferred: experience in SaaS software development/product teams.

• Preferred: experience working with distributed and remote teams.


🏝️ Benefits

• Flexibility to work in the manner you choose within your country of employment – in-office, remote, or hybrid.

• Immediate access to a comprehensive health and wellness benefits package, including an annual wellness stipend.

• 401k plan with up to a 4% match and immediate vesting.

• Flexible and generous (FTO) time-off policy.

• Employee Stock Purchase Program.

• Variable compensation component available in most US locations.

People also viewed

VAILEXA19 hours ago

Product Security and Regulatory Expert

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
NatWest Group19 hours ago

Security Intelligence Specialist

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Inviso20 hours ago

Security & Identity Engineer

PL flagPoland OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Atlas Governance21 hours ago

Information Security Governance Intern

BR flagBrazil OnlyInternshipCybersecurity / Security Engineer
ApplyView job
Triumph Enterprises, Inc.21 hours ago

Cloud Security Architect / Engineer

US flagDistrict of Columbia, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
Inviso21 hours ago

Security & Identity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$145k – $190k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers