Director of Information Security at jobgether

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director of Information Security based in the United States. As Director of Information Security, you will lead and mature a growing security program at a critical stage of organizational expansion. You will build on established ISO 27001 and SOC 2 foundations while developing a durable, operational security framework. The role combines strategic leadership with hands-on ownership across cloud, infrastructure, networks, applications, and security operations. You will strengthen governance, policies, risk management, compliance, incident response, and secure software development practices. A key part of the position is partnering closely with Engineering and Product to make security an integrated and practical part of how technology is built. You will also lead and develop the security team while communicating security risks and priorities clearly to executives and the board. This is an opportunity to shape a high-impact security function within a rapidly scaling SaaS and technology environment. Accountabilities: As the senior security leader, you will own the information security program end to end, balancing strong governance and risk management with practical security engineering and close partnership across the organization. Own and continuously mature the information security program in alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2. Develop, formalize, maintain, and operationalize security policies, standards, and procedures covering risk management, access control, incident response, third-party risk, change management, business continuity, and related areas. Manage the internal control environment, including risk assessments, control testing, audit evidence, remediation tracking, and ongoing certification readiness. Build and maintain effective relationships with external auditors, penetration testers, and security and compliance partners. Own security across infrastructure, networks, AWS/GCP cloud environments, endpoints, and applications. Define the strategy and roadmap for identity and access management, cloud and network security, endpoint protection, vulnerability management, logging, monitoring, and incident response. Establish and continuously improve secure SDLC practices, including threat modeling, secure code review, dependency and software supply-chain security, and CI/CD pipeline security. Develop and maintain an effective incident response program, including response plans, tabletop exercises, and leadership during significant incidents. Lead, coach, and develop the security team while establishing clear ownership, workflows, priorities, and operating standards. Build a collaborative security culture that enables engineering teams to work securely without unnecessary friction or delays. Define effective engagement models with Engineering and Product, including embedded reviews, self-service security tooling, and clear service-level expectations. Serve as the primary security partner for Engineering, Product, IT, Legal, and executive leadership. Translate technical security risks into clear business implications and provide pragmatic, risk-based recommendations to leadership and the board. Support customer trust and commercial activities through security questionnaires, customer audits, trust-center initiatives, and related security engagements. Establish measurable success criteria for security operations, including policy adoption, team ownership, audit readiness, incident response effectiveness, and security review efficiency. Requirements: The ideal candidate combines deep information security expertise with proven leadership experience in a scaling SaaS environment, along with the ability to operate comfortably between technical teams, compliance stakeholders, and executive leadership. Bachelor’s degree in Information Security, Computer Science, Computer Engineering, or a related field, or equivalent professional experience. 10+ years of experience in information security, including at least 3 years in a leadership role with end-to-end ownership of a security program. Direct operational experience with ISO 27001 and SOC 2, with a strong understanding of what maintaining audit readiness requires on an ongoing basis. Strong technical expertise in cloud security, particularly AWS and/or GCP. Strong understanding of network security and modern application security practices. Experience with secure SDLC, application security tooling, and security practices across development and deployment environments. Experience with container and Kubernetes security is a plus. Proven experience building or rebuilding security policies, procedures, and operating processes within a scaling SaaS organization. Demonstrated ability to build security teams and establish effective, collaborative relationships with Engineering and Product. Strong understanding of how security tooling, automation, communication, and practical processes can drive adoption more effectively than policy alone. Experience managing external auditors, penetration testers, and compliance vendors. Excellent written and verbal communication skills, with the ability to communicate effectively with engineers as well as senior executives and board-level stakeholders. Strong judgment and ability to make pragmatic, risk-based decisions in complex and rapidly changing environments. CISSP, CISM, or a comparable security certification is a plus. Experience with ISO 27701 is a plus. Experience with the NIST Cybersecurity Framework is a plus. Experience working in a post-certification, high-growth technology or SaaS environment is preferred. Benefits: Competitive compensation aligned with experience and qualifications. Remote opportunity within the United States. Opportunity to lead and shape a growing information security function. Strategic and hands-on ownership across governance, cloud security, application security, infrastructure, and security operations. Direct partnership with Engineering, Product, IT, Legal, and executive leadership. Opportunity to influence security strategy and risk decisions at the organizational level. Ability to build and develop a high-performing security team. Opportunity to strengthen established ISO 27001 and SOC 2 programs and lead the path toward SOC 2 Type 2. Collaborative environment focused on making security an effective enabler of technology development. Opportunity to work in a rapidly scaling SaaS and cloud technology environment. Professional growth through exposure to modern cloud, application, infrastructure, compliance, and security challenges.