Remote job
Director of Information Security
Job details
About this role
Role overview
A senior leadership role responsible for the governance, data protection, privacy, and risk programs that demonstrate responsible data handling to customers, regulators, and the board. The Director will own compliance certifications, data security strategy, the privacy program, and enterprise risk management, while building and leading the team that runs them. The position blends strategic leadership with hands-on program building in a fast-moving, AI-focused environment.
Responsibilities
- Own and mature the end-to-end compliance program across frameworks such as SOC 2 and ISO 27001, leading audits to successful outcomes. - Set data security strategy covering classification, access governance, encryption standards, DLP, and lifecycle controls for sensitive and customer data. - Build and operate the privacy program in line with regulations such as GDPR and CCPA/CPRA, partnering with legal on DPAs and privacy-by-design. - Establish and run the enterprise risk management program, including identification, assessment, treatment, and reporting to leadership and the board. - Own third-party and vendor risk along with customer trust functions, including security questionnaires, customer assurance, and the trust center. - Hire, lead, and grow a high-performing team spanning GRC, privacy, and risk.
Requirements
- Typically 10+ years of experience in information security, GRC, privacy, or risk, with meaningful management experience. - Proven track record owning compliance certifications such as SOC 2 and ISO 27001 and leading audits to completion. - Deep knowledge of data protection and privacy regulations (GDPR, CCPA/CPRA) and how to operationalize them. - Strong grounding in risk management frameworks and enterprise risk programs. - Executive-level communication skills, with the ability to translate risk into business terms for leadership and the board.
Nice to have
- Relevant certifications such as CISSP, CIPP, CISM, or CRISC. - Experience scaling a compliance or privacy program through significant company growth. - Familiarity with continuous compliance tooling and controls automation. - Background supporting enterprise sales and customer security reviews.
Benefits and work setup
- Listed salary is $240,000, with the role described as part of a startup-paced, AI-forward organization.