waypointjobs

CoorB

Information Security Director

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Category: Technology

Location:

The Information SecurityDirectoris the organization's senior executive accountable for the strategy, governance, and execution of theorganization'sinformation security program.Hedefines and drives the security architecture, oversees incident response and risk management, sets and enforces security policy, owns the security budget, and builds a culture of security awareness across the organization. This role balances executive-level risk communication with the technical depth needed to guide security design, identity and access management, data protection, and threat monitoring (SIEM/SOC) decisions.Hepartners closely with IT leadership, legal, compliance, and business units to ensure security enables — rather than obstructs — the organization'sobjectives.

Key Responsibilities

Cybersecurity Leadership

Own the organization's overall security posture, including threat detection, incident response, vulnerability management, and endpoint/identity protection.

Direct security monitoring and incident investigation (e.g., EDR/SIEM alert triage, threat hunting, and formal incident reporting) and lead response to active threats.

Define andmaintainsecurity architecture standards across cloud (Azure, GCP), including network segmentation,firewall/NGFW policy, and Zero Trust Network Access (ZTNA).

Establish and enforce security policies covering access control, data protection, endpoint management, and acceptable use.

Team Leadership

Build, lead, and develop the information security team, including hiring, coaching, performance management, and succession planning.

Set clear priorities,objectives, and accountability structures for security architects, analysts, IAM/GRC leads, and other direct reports.

Foster a collaborative, high-performingteamculture and support ongoing professional development and certification.

Manage team workload andresourcesto ensure adequate coverage for monitoring, incident response, and project delivery.

Security Strategy, Design & Implementation

Define and own theorganization’ssecurity architecture and strategy.

Lead the design and implementation of security controls for networks, endpoints, applications, and cloud workloads, including secure-by-design reviews for new projects and technologies.

Set technical standards for security toolingselection, deployment, and integration, ensuring coverage across the full technology stack.

Evaluate emerging threats and technologies, adjusting the security roadmap to address new attack surfaces (cloud, AI, remote work, etc.).

Security Incident Management

Own the security incident response program end-to-end: detection, triage, containment, eradication, recovery, and post-incident review.

Establish andmaintainthe incident response plan, playbooks, and escalation procedures, andleadthe response to major security incidents and breaches.

Coordinate with legal, communications, and executive leadership onbreachnotification obligations and external disclosure requirements.

Drive continuous improvement of detection and response capabilities based on lessons learned, tabletop exercises, and threat intelligence.

Security Policies & Governance

Develop,maintain, and enforceorganizationinformation security policies, standards, and procedures (access control, acceptable use, data classification, incident response, vendor security, etc.).

Ensure policiesremainaligned with applicable regulatory and contractual requirements and are reviewed on a regularcadence.

Establish governance structures (security steering committee, policy exception processes) to ensure accountable, auditable decision-making.

Represent security in client, partner, and regulatory due-diligence engagements, including security questionnaires and audits.

Act as the primary liaison with internal and external auditors, coordinating audit scope, evidence collection, and remediation of findings across security and compliance audits.

Risk Management

Own theorganizationsecurity risk management program, including risk identification, assessment, treatment, and reporting.

Maintain the organization's risk register and ensure risk treatment plans have clear ownership, timelines, and executive visibility.

Report on the organization's security risk posture to executive leadership and the board on a regular basis, using clear, business-relevant metrics.

Security Budget & Resource Management

Own and manage theorganizationsecurity budget, including forecasting, prioritization, and return-on-investment analysis for security initiatives.

Build the business case for security investments, balancing risk reduction against cost and operational impact.

Details

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job