Director, Information Security
$210,000–$250,000 year
HybridRedwood City, California, United States
Job Summary
Define and execute PubMatic's enterprise information security strategy and multi-year roadmap while leading Security Engineering, Operations, Governance, and Incident Response. Build a highly automated, AI-enabled security organization focused on operational efficiency, establishing executive metrics and reporting for the Board. Lead security architecture across cloud infrastructure, Kubernetes, and identity, driving automation, threat detection, and DevSecOps integration. Develop the company's AI security strategy and governance framework to secure enterprise AI platforms and address risks like prompt injection and data leakage. Partner with business leaders to balance regulatory requirements with operational velocity, managing vendor relationships and leading security awareness initiatives.
Required Qualifications
- Bachelor's degree or higher in Computer Science, Cybersecurity, Engineering, or related field
- 10+ years of progressive cybersecurity experience
- at least 5 years leading enterprise security organizations
- Strong expertise in cloud security, Security Engineering, Security Operations, IAM, Zero Trust, DevSecOps, Kubernetes, network security, and modern enterprise security architectures
- Experience leading enterprise-wide security transformation
- Experience implementing automation to improve security operations
- Working knowledge of AI-powered security technologies for automation, threat detection, incident triage, and operational efficiency
- Strong understanding of AI security risks, including LLM security, prompt injection, AI governance, and secure enterprise AI adoption
- Proven ability to design security programs that effectively balance risk reduction with employee productivity, developer experience, and business velocity
- Demonstrated success leading large-scale security initiatives with thoughtful rollout strategies, change management, and user adoption planning
- Exceptional executive presence
- outstanding written, verbal, and presentation skills
- ability to communicate effectively with executives, board members, customers, auditors, and regulators
- ability to translate complex technical and security topics into concise, business-focused, decision-ready recommendations tailored to different audiences
- High attention to detail
- a strong sense of executive communication quality and presentation excellence
- 3 days in office and 2 days working remotely
Desired Qualifications
- CISSP, CISM, CCSP, or equivalent certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.