Remote job
Director of Information Security
Job details
About this role
Role overview A scaling SaaS organization that powers connected experiences for millions of locations is hiring a Director of Information Security to elevate an already-certified program. The company holds ISO 27001 and SOC 2 Type 1, and the next chapter is about turning that foundation into a durable, engineer-friendly operation that protects cloud, network, and application layers without slowing product velocity.
Responsibilities - Own and mature the information security program, keeping it aligned with ISO 27001 and SOC 2 and steering the transition to SOC 2 Type 2. - Author, formalize, and maintain policies, standards, and procedures spanning risk management, access control, incident response, vendor risk, change management, and business continuity. - Run the internal control environment end to end: risk assessments, control testing, audit evidence collection, and remediation tracking, while managing external auditors, penetration testers, and compliance partners. - Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging and monitoring, and incident response across AWS and GCP environments. - Embed secure software delivery practices through threat modeling, secure code review, dependency and supply-chain security, and CI/CD pipeline hardening. - Lead, coach, and develop the security team, defining roles, workflows, and an enablement-first culture; serve as the primary security voice to Engineering, Product, IT, Legal, and the executive team, and support customer-trust and sales-enablement efforts.
Requirements - Bachelor's degree in Information Security, Computer Science, Computer Engineering, or a related field, or equivalent practical experience. - 10+ years in information security with at least 3 years leading a security program end to end. - Hands-on operational experience living inside ISO 27001 and SOC 2 frameworks day to day, not only at audit time. - Strong technical depth in cloud security (AWS/GCP), network security, and modern application security, including SDLC, AppSec tooling, and container or Kubernetes security. - Demonstrated success building or rebuilding policies and procedures from the ground up in a scaling SaaS environment. - Track record managing external auditors, penetration testers, and compliance vendors, plus clear communication skills that flex between engineering whiteboards and board-level risk briefings.
Nice to have - CISSP, CISM, or equivalent certification. - Experience implementing or operating under ISO 27701 and the NIST Cybersecurity Framework. - Background at organizations of similar size and stage, post-certification and actively scaling the security team.