Director of IT, Information Security & Data Privacy
$175,000–$185,000 year
On-siteExton, Pennsylvania, United States
Job Summary
Develop and continuously improve the company's Information Security strategy, roadmap, and security posture while leading operations for identity and access management, endpoint security, vulnerability management, and incident response. Partner with Product, Engineering, and IT Operations to integrate security into cloud infrastructure and the software development lifecycle, and manage vendor security reviews and third-party risk assessments. Own the Data Privacy and Governance program, ensuring compliance with ISO 27001, SOC 2, GDPR, and CCPA, and lead internal and external audits. Establish enterprise cybersecurity risk assessments, develop security metrics and executive reporting, and build scalable governance processes for a high-growth SaaS environment. Serve as the trusted advisor on technology risk while mentoring a high-performing security team.
Required Qualifications
- 10+ years of progressive Information Security, Cybersecurity, and Data Privacy leadership experience
- 5+ years of director-level or senior leadership responsibility
- Proven experience leading Information Security and Data Privacy programs within a fast-paced, high-growth SaaS or cloud-native organization
- Strong hands-on technical expertise in: Cloud security (AWS and/or Azure), Identity and Access Management (IAM), Security operations, Vulnerability management, Endpoint security, Security monitoring and incident response
- Demonstrated success building, mentoring, and leading high-performing technical teams
- Deep knowledge of cybersecurity frameworks, risk management, privacy regulations, and security best practices
- Proven success achieving, maintaining, and continuously improving ISO 27001, SOC 2, and similar compliance and certification programs
- Experience implementing and managing modern security technologies in cloud-based environments
- Strong project management, organizational, communication, and cross-functional leadership skills
- Must be available for remote work in Arizona, Delaware, Florida, Georgia, Maryland, Michigan, North Carolina, Nebraska, New Jersey, New York, Pennsylvania, South Carolina, Tennessee, Texas, or Wisconsin
- Must reside in one of the above locations (Arizona, Delaware, Florida, Georgia, Maryland, Michigan, North Carolina, Nebraska, New Jersey, New York, Pennsylvania, South Carolina, Tennessee, Texas, Wisconsin)
- Must not reside in New York State (NYC residents excluded)
Desired Qualifications
- Experience supporting hybrid and remote work environments
- Experience collaborating with Product and Engineering organizations to embed security into cloud-native application development
- Familiarity with modern SaaS technology ecosystems and cloud security platforms
- CISSP, CISM, CRISC, or comparable industry certifications
- Experience supporting mergers and acquisitions, organizational scaling, or rapid business growth
- Experience developing governance for emerging technologies, including AI
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.