Are you a hands-on security leader ready to make a measurable impact in a mission-driven organization? We're looking for a Director of Information Security to lead and scale our security operations, incident response, and engineering efforts. In this role, you'll oversee our security ecosystem - from real-time monitoring to proactive threat hunting - and help shape the future of enterprise security at a growing company. This is a highly collaborative position where you'll work cross-functionally with teams across the business to protect our information assets, infrastructure, and services - especially within a SaaS and life sciences environment. What will you do?
- Shape and drive the enterprise security operations strategy in alignment with broader company goals.
- Serve as a trusted advisor to senior leadership on all things security.
- Manage our Security Operations Center (SOC), ensuring rapid incident detection, triage, and response.
- Oversee threat intelligence, vulnerability management, and operational risk mitigation initiatives.
- Partner with IT and engineering teams to deploy, tune, and optimize tools like SIEM, SOAR, EDR, and DLP.
- Implement automation and integrations that improve speed and efficiency.
- Lead cyber incident response efforts and continuously test and improve our disaster recovery and response plans.
- Coordinate cross-functional teams (e.g., Legal, HR, Communications) during major security events.
- Lead, mentor, and grow a high-performing team of security and infrastructure professionals.
- Support the development of a resilient, inclusive, and learning-driven culture across the department.
- Align programs with regulatory standards (HIPAA, SOX, GDPR, PCI-DSS) and frameworks (NIST, MITRE ATT&CK).
- Support audits and ensure documentation is ready and accurate.
How will you get there?
- Bachelor's degree in Computer Science, Information Security, or related field (Master's a plus).
- 12+ years of relevant experience, including 4+ years leading teams in complex enterprise environments.
- Hands-on expertise in SOC management, incident response, and threat intelligence.
- Experience in the Medical Device, Life Sciences, or highly regulated industries preferred.
- Professional certifications such as CISSP, CISM, GIAC, or CEH.
- Proficiency with security tools including SIEM, EDR, SOAR, IDS/IPS, and vulnerability management platforms.
- Strong knowledge of cloud (AWS, Azure, GCP), Windows/Linux systems, and network protocols.
- Familiarity with security frameworks and standards (NIST, MITRE, ISO 27001).
- Proven ability to build, lead, and retain high-performing technical teams.
- A proactive, solutions-oriented mindset with excellent communication and collaboration skills.
#GKOSUS
|