Post job

Information Security Director remote jobs

- 187 jobs
  • OT Security Architect

    First Quality 4.7company rating

    Remote job

    We are seeking an OT Security Architect to work remotely. This position will be responsible for safeguarding our operational technology infrastructure. This role offers the flexibility to work remotely with periodic travel to our manufacturing sites. First Quality is a growing manufacturing organization that has defined security as one of its key business values. Joining our team will provide you with unique personal and professional growth opportunities where you'll be hands-on and securing cutting-edge industrial automation and technologies contributing to a growing field where cybersecurity directly protects critical processes, manufacturing, and safety. Primary responsibilities include: • Primarily responsible for OT security event monitoring, management, and response • Create an IS reference architecture for our OT networks • Work with OT engineering team, as well as with SOC team and verify that the reference architecture fits the business processes and requirements • Work with OT engineering teams for defining security controls for their on-going projects • Provide technical guidance to the GRC team with assessing OT 3rd party vendor and supply chain • Integrate with OT engineering projects and verify that the required IS controls are properly implemented • Revise and develop processes to strengthen the current OT Security Operations Framework, review policies and highlight the challenges in managing SLAs • Perform threat management, threat modeling, identify threat vectors and develop use cases for OT security monitoring including red\blue penetrations tests • Responsible for developing, configuring, and maintaining OT security automation and orchestration IR's and tools. • Creation of reports, dashboards, metrics for OT security operations and presentation to Sr. Mgmt. • Create required standards and procedures (i.e. IS purchasing standard, sanitization process) in coordination with all relevant stakeholders The ideal candidate should possess the following: • Minimum of five (5) years of professional experience in OT security and operations. • Knowledge of controls and automation equipment and principles (i.e. PLCs, SCADA, DCS, HMIs, VFDs, etc.) • Familiarity with security frameworks and standards such as NIST, ICS Mitre ATT&CK, and IEC 62443 • Experience in defining and implementing security controls for OT engineering projects. • Experience managing projects with the abilities to prioritize tasks and manage time effectively. • Experience in developing, configuring, and maintaining OT security automation and orchestration tools. • Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related field. In lieu of degree, related experience will be considered. • Background in manufacturing controls is preferred What We Offer You We believe that by continuously improving the quality of our benefits, we can help to raise the quality of life for our team members and their families. At First Quality you will receive: • Competitive base salary and bonus opportunities • Paid time off (three-week minimum) • Medical, dental and vision starting day one • 401(k) with employer match • Paid parental leave • Child and family care assistance (dependent care FSA with employer match up to $2500) • Bundle of joy benefit (years' worth of free diapers to all team members with a new baby) • Tuition assistance • Wellness program with savings of up to $4,000 per year on insurance premiums • ...and more! First Quality is committed to protecting information under the care of First Quality Enterprises commensurate with leading industry standards and applicable regulations. As such, First Quality provides at least annual training regarding data privacy and security to employees who, as a result of their role specifications, may come in to contact with sensitive data. First Quality is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, sexual orientation, gender identification, or protected Veteran status. For immediate consideration, please go to the Careers section at ******************** to complete our online application.
    $85k-133k yearly est. 2d ago
  • Information Security Analyst

    Ispace, Inc.

    Remote job

    Title: Information Security Analyst Duration: 12+ months contract Hybrid role 3 days Office, 2 days work from home Pay rate$60 per hr on W2 Local to Los Angeles candidates only Summary This is a hands-on security position working within the Information Security group and with the internal IT department at large. This position's core focus is to ensure consistent, measurable end to end delivery of security services. The successful candidate will work to develop and deploy capabilities ensuring enterprise systems and data are protected with the security controls and tools required to meet policy and compliance requirements. We are looking for candidates who have a passion for cybersecurity, threat detection, risk mitigation and response. You will be a key part of our efforts to build and support a defensible environment where we are able to detect, contain and respond quickly to threats and compromises in ways that serve to enable the business needs of a highly collaborative organization. The environment is fast-paced and commonly on the leading edge of technology, including early adoption of various cloud services along with the challenges of integrating those services into our security practice. Responsibilities Support a Technology Vendor Management program, ensuring technology risk reviews across multiple disciplines, and monitoring for renewals and savings opportunities Participate in risk reviews of the IT control framework (NIST CSF, CIS, ITIL, ISO 270001, etc.) Conduct thorough vendor, product and applications security assessments partnering with systems owners to integrate security early during the project lifecycle. Coordinate, across service owners, the implementation of core security integrations (SSO, Event Logs, Secrets, Alerting, Threat Model and Backup/Recovery) with applications developed in-house and externally/SaaS hosted environments. Partner with business groups to review workflows, producing output to enhance security processes in support of those workflows. Support the development and implementation of a data protection program. Coordinate with IRM leadership to develop and deliver key security metrics to ensure technical security controls are meeting desired objectives; ensuring the measurable effectiveness of CAA's technical controls. Required Capabilities A minimum of 2-3 years in Information Technology A minimum of 2 years' experience in cybersecurity risk management A Bachelor's or Master's Degree in a relevant field of work Strong analytical skills in conducting due diligence to identify, assess and prioritize vendor risks Familiarity with information security frameworks (NIST, ISO27001), data privacy regulations (GDPR, CCPA), and information security certifications/attestations (SOC, ISO, PCIDSS, FedRAMP) Experience in coordinating technical integrations for security tooling and processes. Ability to review complex systems architectures to identify key security integration opportunities Produce a comprehensive, written, security assessment of vendors security posture Experience using security analytics tooling to produce operational metrics and dashboards A strong understanding of the fundamental operations of servers, operating systems, cloud applications, and infrastructure Desired Skills Core skills in Cybersecurity fundamentals and Third Party Risk Management Familiarity with using Third Party Risk Management tools/processes such as One Trust, SIG or similar GRC platforms. Hands-on experience in Azure, AWS Cloud environments and familiarity with core Cloud services and Cloud architecture Familiarity with core security concepts of Single Sign-on (e.g PingFed, SAML), Identity and Access Administration (Active Directory, Azure AD, AWS IAM), Event Management (Splunk), Expert skills in using Microsoft Office suite, JIRA. If you're interested in above role please send me your updated resume to *******************************
    $60 hourly 5d ago
  • Information Security - Governance, Risk, and Compliance (GRC) Director (Remote)

    Procter & Gamble 4.8company rating

    Remote job

    Information Technology at Procter & Gamble is where business, innovation and technology integrate to build a competitive advantage for P&G. Our mission is clear -- we deliver IT to help P&G win with the over 5 billion consumers we serve worldwide. Our IT professionals are diverse business leaders who apply IT expertise to deliver innovative, tech-focused business models and capabilities for our 65 iconic, trusted brands. From Day 1, you'll be trusted to dive right in, take the lead, use your initiative, and build billion-dollar brands that help make everyday activities easier and make the world a better place! Our company offers purposeful work that will take your career places you never envisioned, in creative workspaces where innovation thrives and where your technical expertise is recognized and rewarded. The Opportunity P&G is seeking a Governance, Risk, and Compliance Director passionate about safeguarding data, enabling business through smart risk management, and shaping the future of cybersecurity. The IT Governance, Risk, and Compliance (GRC) Organization at Procter & Gamble is responsible for risk identification, assessment, and remediation across the IT landscape, as well as driving automated governance and compliance breakthroughs. As the GRC expert, you'll play a critical role in maturing and maintaining the security risk and compliance posture of our organization. You will lead initiatives that align our security program with business goals, ensure regulatory and policy compliance, and creatively solve problems to manage risk for the company. Responsibilities: + Governance: + Maintain and evolve the information security policy framework and controls aligned with industry best practices (e.g., NIST, ISO 27001, CIS). + Establish and track metrics to measure policy adherence and program maturity. + Drive internal alignment on security roles, responsibilities, and expectations. + Risk Management: + Manage the enterprise risk management process including risk identification, analysis, treatment planning, and reporting. + Conduct security risk assessments for internal systems, projects, vendors, and business processes. + Facilitate risk-based decision-making at all levels of the organization. + Compliance: + Ensure ongoing compliance with applicable regulations and frameworks (e.g., GDPR, HIPAA, CCPA, SOX). + Maintain a library of evidence and documentation to support audit and regulatory needs. + Monitor the effectiveness of IT controls and identify gaps in compliance. Analyze control measurements for negative trends and reoccurrence frequency. Collaborate with internal/external auditors on compliance audits, audit findings, and issue remediation + Awareness & Enablement: + Contribute to the continuous improvement of the risk and compliance mindset across P&G. Build IT risk awareness by providing support and training to others. + Collaborate cross-functionally with IT, Legal, Privacy, and Business Operations teams. + Stay up to date with how current events, security focus areas, and the regulatory environment may impact P&G's compliance processes Estimated Percent of Time Spent on Work 25% - Risk identification, analysis, and assessment 40% - Plan and drive enterprise-wide initiatives to reduce risk and improve compliance across the organization 25% - Assess and improve the effectiveness of IT controls and compliance across the enterprise 10% - Collaboration with internal/external auditors, driving a risk-aware compliance mindset Job Qualifications Required: + Bachelor's degree in Computer Science, Computer Systems Engineering, Cybersecurity, Industrial Engineering, Business Management Information Systems, Software Development, or related field + Prior hands on experience working in a security-focused role, such as Information Security Analyst, SOC Analyst, Security Engineer, etc. + 8+ years of experience in Governance, Risk, and Compliance with a focus on Information Security + In-depth knowledge of major security frameworks (e.g., NIST CSF, ISO 27001, SOC 2). + Experience conducting risk assessments, audits, and control testing. + Strong understanding of regulatory compliance requirements (e.g., GDPR, HIPAA, SOX, PCI DSS). + Proven ability to write policies, manage documentation, and communicate clearly to both technical and non-technical stakeholders. + Ability to influence and build relationships with business unit stakeholders, external service providers, and architecture teams. + The ability to work independently, collaborate, and learn quickly. + English fluency (speak, write, and read) Preferred Skills: + Certified in CISSP, ISACA CRISC, CGEIT, CISA, or similar Pay Range: $160,000 - $220,000 Compensation for roles at P&G varies depending on a wide array of equal opportunity factors including but not limited to the specific office location, role, degree/credentials, relevant skills, and level of experience. At P&G compensation decisions are dependent on the facts and circumstances of each case. Total rewards at P&G include salary + bonus (if applicable) + benefits. Your recruiter may be able to share more about our total rewards offerings and the specific salary range for the relevant location(s) during the hiring process. Our company is committed to providing equal opportunities in employment. We value diversity and do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. Immigration Sponsorship is not available for this role. For more information regarding who is eligible for hire at P&G along with other work authorization FAQ's, please click HERE (******************************************************* . P&G participates in e-verify as required by law. Qualified individuals will not be disadvantaged based on being unemployed. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation. Job Schedule Full time Job Number R000136880 Job Segmentation Experienced Professionals Starting Pay / Salary Range $160,000.00 - $220,000.00 / year
    $160k-220k yearly 60d+ ago
  • Director, Security Operations & Information Security

    Figma 4.4company rating

    Remote job

    Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma's platform helps teams bring ideas to life-whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere in the world. If you're excited to shape the future of design and collaboration, join us! The role of Director, Security Operations & Information Security is a new and critical addition to our organization. This leader will be responsible for driving our enterprise-wide security strategy and ensuring operational excellence across our systems, from GTM and Finance platforms to IT, Compliance, and Risk. Our broader Information Security function is expanding its scope to align more deeply with business priorities. This includes building scalable frameworks for threat management, compliance, and governance, and ensuring that every team - from Sales to Engineering - has the tools and guidance needed to operate securely and confidently. We're looking for a proven security leader who has built and scaled SecOps and InfoSec programs, partnered effectively with senior leaders across the business, and can ensure that we continue to deliver resilience, trust, and protection for Figma and our customers. This is a full time role that can be held from one of our US hubs or remotely in the United States. What you'll do at Figma: Lead and scale the Information Security and Enterprise Security functions, including Security Operations, Third-Party Risk Management, Incident Response, Threat Detection, Vulnerability Management, and GRC Define and drive the security strategy and roadmap, balancing innovation and risk in close partnership with Engineering and Product leadership Collaborate cross-functionally to ensure comprehensive security governance across the organization Develop and uphold security incident response plans, tabletop exercises, and post-mortem processes throughout the organization Establish metrics and KPIs to monitor the effectiveness of security programs and continuously improve them Build and manage an impactful team, hiring world-class talent and fostering a culture of collaboration and accountability Serve as a trusted advisor to the leadership team and board members on security risks, trends, and incidents Lead vendor and third-party risk, including security evaluations and contract reviews We'd love to hear from you if you have: 10+ years of experience in information security, with 5+ years in a senior leadership role overseeing security operations or infosec Strong background in building and scaling security programs in SaaS/cloud-native environments Deep knowledge of modern threat landscapes, detection and response strategies, and vulnerability management practices Understanding of compliance and regulatory frameworks relevant to enterprise SaaS (SOC 2, ISO, FedRAMP, etc.) Experience engaging with auditors, regulators, and customer security teams At Figma, one of our values is Grow as you go. We believe in hiring smart, curious people who are excited to learn and develop their skills. If you're excited about this role but your past experience doesn't align perfectly with the points outlined in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles. Pay Transparency Disclosure If based in Figma's San Francisco or New York hub offices, this role has the annual base salary range stated below. Job level and actual compensation will be decided based on factors including, but not limited to, individual qualifications objectively assessed during the interview process (including skills and prior relevant experience, potential impact, and scope of role), market demands, and specific work location. The listed range is a guideline, and the range for this role may be modified. For roles that are available to be filled remotely, the pay range is localized according to employee work location by a factor of between 80% and 100% of range. Please discuss your specific work location with your recruiter for more information. Figma offers equity to employees, as well a competitive package of additional benefits, including health, dental & vision, retirement with company contribution, parental leave & reproductive or family planning support, mental health & wellness benefits, generous PTO, company recharge days, a learning & development stipend, a work from home stipend, and cell phone reimbursement. Figma also offers sales incentive pay for most sales roles and an annual bonus plan for eligible non-sales roles. Figma's compensation and benefits are subject to change and may be modified in the future. Annual Base Salary Range (SF/NY Hub):$250,000-$338,000 USD At Figma we celebrate and support our differences. We know employing a team rich in diverse thoughts, experiences, and opinions allows our employees, our product and our community to flourish. Figma is an equal opportunity workplace - we are dedicated to equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity/expression, veteran status, or any other characteristic protected by law. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. We will work to ensure individuals with disabilities are provided reasonable accommodation to apply for a role, participate in the interview process, perform essential job functions, and receive other benefits and privileges of employment. If you require accommodation, please reach out to accommodations-ext@figma.com. These modifications enable an individual with a disability to have an equal opportunity not only to get a job, but successfully perform their job tasks to the same extent as people without disabilities. Examples of accommodations include but are not limited to: Holding interviews in an accessible location Enabling closed captioning on video conferencing Ensuring all written communication be compatible with screen readers Changing the mode or format of interviews To ensure the integrity of our hiring process and facilitate a more personal connection, we require all candidates keep their cameras on during video interviews. Additionally, if hired you will be required to attend in person onboarding. By applying for this job, the candidate acknowledges and agrees that any personal data contained in their application or supporting materials will be processed in accordance with Figma's Candidate Privacy Notice.
    $250k-338k yearly Auto-Apply 28d ago
  • Information Security, Director

    Panorama Education 4.1company rating

    Remote job

    About Panorama: Panorama Education is a fast-growing technology company partnering with K-12 school districts to help students succeed in the classroom and beyond. Today, 2,000 districts serving 15 million students across all 50 states rely on our secure, research-backed platform for AI, student support, and community voice and engagement. We also provide professional development and hands-on support to help schools to achieve their strategic goals and improve student outcomes. When you join Panorama, you become part of a mission-driven team making a real impact for students every day. Panoramians can choose to work fully remote anywhere within the Continental United States. About the Role: Every day, teachers, principals, and school district leaders nationwide use Panorama's platform to improve student outcomes across academics, family engagement, attendance, well-being, and college-career readiness. As a result, Panorama is the fastest growing platform in K-12 education, and 1 in 4 American students attends a school that has adopted Panorama. Panorama is seeking a Information Security DIrector to lead and continuously improve our security program. This role sits at the intersection of policy, compliance, engineering, client enablement, and business risk management. The position requires a thoughtful, strategic, and hands-on professional who can manage competing priorities, adapt to shifting client expectations, and ensure Panorama continues to earn and maintain the trust of school districts nationwide. In this mission-driven environment centered on equity and student outcomes, you'll play a pivotal role in shaping the evolving security posture of an AI-forward company serving enterprise-level education clients. This highly cross-functional role provides broad organizational visibility, influence, and ownership of a security program that is both mature and evolving, with meaningful connections to teams across Sales, Client Success, Legal, IT, and Engineering. Responsibilities: Own and evolve Panorama's security program, ensuring high standards across compliance, vendor and tool reviews, secure operational practices, incident response, and documentation. Maintain and renew existing certifications, such as SOC 2 Type 2, while preparing for future certifications, including support for associated activities such as cyber insurance renewals, policy updates, audit evidence gathering, and internal assessments. Own Panorama's security posture representation in client-facing materials such as RFPs, procurement checklists, and due diligence questionnaires-scaling up to lead more involved efforts such as third-party penetration testing when required by strategic accounts. Create and maintain clear, externally consumable summaries of our security practices, helping Sales and Client Success accelerate deals and retain client confidence. Equip senior leaders with a clear view of security posture and progress by synthesizing operational data-including KPIs-into briefings that support planning, prioritization, and investment decisions. Refine and execute processes for secure evaluation of new vendors, integrations, AI applications, browser extensions, and system-level tools-ensuring thoughtful adoption of tools while preserving a strong security posture. Guide Panorama's secure and responsible use of AI, including product integrations, employee tools, and external messaging around security implications. Sustain Panorama's strong international compliance posture, particularly around client-specific data residency requirements. Lead annual security awareness training and other internal enablement activities to promote a security-conscious culture and behavior across the organization. Continuously review and improve internal security policies and practices to stay aligned with client expectations, compliance standards, and industry best practices. Our Ideal Candidate Has: 3+ years of experience in information security roles, including responsibility for audits, vendor reviews, and program-level decisions. Expertise in Platform and Application Security with strong GRC, Security Operations, and Enterprise Security experience. Extensive knowledge of information security, including deep expertise in security policy, risk management, vulnerability management, incident response, and compliance regulations. General knowledge of FERPA, PPRA, and COPPA. Experience preparing organizations for SOC2. The ability to learn quickly and hit the ground running. Strong communication skills. Demonstrated desire to be a continuous learner. Salary: The starting range for this role is $202,500 - $270,000. Actual offers depend on experience, skill and location. Our salary is just one component of Panorama's competitive total rewards strategy that also includes annual bonuses or commission awards, equity awards, as well as other region-specific health and welfare benefits #LI-Remote
    $202.5k-270k yearly Auto-Apply 26d ago
  • Consultant - Chief Information Security Officer (Fractional/Contract Role)

    Arootah

    Remote job

    Arootah is a rapidly growing advisory and coaching firm specializing in Alternative Investment & Family Office Advisory, Executive & Leadership Coaching, and Talent Acquisition & Development. Founded by Rich Bello, co-founder and COO of Blue Ridge Capital, Arootah leverages deep industry expertise to drive peak performance for executives, teams, and firms across the alternative investments landscape. Join Arootah's Network of Business Advisors serving Arootah's clients on a project basis in the alternative investment industry, including hedge funds, private equity firms, and family offices. Our mission is to deliver top-tier business advisory services tailored to the multifaceted needs of the alternative investments landscape. As part of the network, you will take on project-based assignments that let you apply your expertise directly to our client initiatives. These consulting roles provide the opportunity to work on varied and impactful projects across the alternative investments industry. Our Services Include: Advising alternative investment managers with front-to-back office services, including but not limited to operations, business development strategy, due diligence, human resources, and compliance Providing fractional expert advisors in key operational areas for emerging and established investment firms Offering executive, life, health, and career coaching for individuals Delivering talent acquisition and leadership development solutions Developing SaaS applications for enterprise and consumer use Visit us at ******************************* more information. WHO WE NEED: Arootah is searching for experienced Chief Financial Officers to consult our client base across the alternative investment landscape. As a consultant, you will work with our Alternative Asset Firm and Family Office clients to provide expert advice. Having previously served in the role of Chief Information Security Officer you have specific, hands-on experience building, maintaining, and operating the full Cybersecurity Program for leading Alternative Asset Firms or Family Offices. What You'll Do Provide advice and guidance to Arootah clients who seek help with their Cybersecurity needs. This will involve consulting to some of the leading Alternative Asset Firms and Family Offices in the world and sharing your experience as a Chief Information Security Officer in helping clients to: Serve as strategic cybersecurity advisor to the Principal/Founder, providing expert guidance on information security strategy, risk management, and cyber threat mitigation for alternative asset firms and family offices. Develop and implement comprehensive cybersecurity programs, establishing security policies, procedures, standards, and control frameworks aligned with industry best practices and regulatory requirements (SEC cybersecurity rules, NYDFS, GDPR, etc.). Design enterprise-wide security architecture, assessing technology infrastructure, application security, cloud environments, network security, and data protection to identify vulnerabilities and implement risk mitigation strategies. Establish incident response and business continuity protocols, creating detection and response procedures, breach notification plans, disaster recovery frameworks, and conducting tabletop exercises to ensure preparedness. Build security awareness and training programs, developing onboarding materials, phishing simulations, ongoing education, and compliance training to foster a security-conscious culture across the organization. Conduct comprehensive risk assessments, performing vulnerability testing, penetration testing, security audits, and gap analyses to identify weaknesses and prioritize remediation efforts based on risk severity. Evaluate and manage vendor security, conducting third-party risk assessments for fund administrators, cloud providers, prime brokers, and other service providers to ensure adequate security controls and data protection. Implement security monitoring and threat intelligence, establishing security information and event management (SIEM) systems, intrusion detection, endpoint protection, and continuous monitoring to detect and respond to threats. Develop data governance and privacy frameworks, creating data classification policies, access controls, encryption standards, data loss prevention measures, and ensuring compliance with privacy regulations. Partner with IT and operations teams to integrate security into system implementations, application development, infrastructure changes, and business processes while balancing security requirements with operational efficiency. Advise on security technology and automation, recommending tools for identity and access management, multi-factor authentication, security orchestration, and leveraging AI/machine learning to improve scalability and threat detection. Report to executive leadership and boards on cybersecurity posture, emerging threats, security metrics, incident status, and budget requirements with clear, non-technical communications tailored to business decision-makers. Lead special projects including security assessments, regulatory compliance implementations, security tool selections, cloud migrations, merger integrations, and preparation for regulatory examinations. QUALIFICATIONS & REQUIREMENTS A Bachelor's degree in Computer Science, Computer/Electrical Engineering, Information Systems, Information Sciences, or a related field with a strong academic record. MBA or other relevant graduate degree is a plus. Certified Information Systems Security Professional (CISSP) or similar (CISA, CISM, etc.) is a plus. 7+ years of relevant experience at a hedge fund, family office, or financial institution serving as a Chief Information Security Officer. 5 or more years of IT implementation experience. Experience in cloud only, cloud first infrastructure, and deploying cloud information security solutions. Firm understanding and ability to implement zero-trust security. Firm understanding and experience with Software Defined Networking and Cloud Networking. Firm understanding of single sign-on and multi-factor authentication platforms. Experience driving discussions with senior personnel regarding trade-offs, best practices, project management, and risk mitigation. Firm understanding of work from anywhere models. Experience with IT compliance and risk management requirements. Job Status Contractor Hours are based on the needs of the assigned client (0-40 hours per week). Join a well-funded disruptor in finance and technology. Enjoy the flexibility of remote work and choosing your assignments. Be part of a dynamic, high-energy company in its expansion stage. Now is the time to join! For more information, visit us at Arootah.com.
    $109k-162k yearly est. Auto-Apply 60d+ ago
  • Director of Information Security

    National Debt Relief 4.5company rating

    Remote job

    Our Director of Information Security provides strategic leadership and vision for enterprise-wide security operations. This role oversees and matures the organization's operations security program, ensuring alignment with business objectives, regulatory requirements, and industry best practices. The Director partners with senior leadership, technology leaders, and business stakeholders to embed security into products, services, and culture. This position reports to the Vice President of Information Security and leads a growing team (4-6 ICs) of security professionals across operational security, incident response, compliance, and governance. Responsibilities Strategic Leadership & Vision Help define and execute the enterprise information security strategy, ensuring alignment with corporate objectives and customer trust. Serve as an advisor to the various teams, technology leaders, and business stakeholders on emerging threats, risks, and security requirements. Lead the evolution of security as a business enabler and differentiator, ensuring resilience, trust, and compliance are built into tools and operations Team & Program Leadership Manage, mentor, and scale a high-performing security team across security operations, incident response, and data security functions. Establish clear career paths, KPIs, and success metrics to drive accountability, engagement, and professional growth. Foster a culture of continuous improvement, innovation, and proactive risk management. Operational Security & Incident Response Oversee enterprise security operations, including SIEM, log correlation, endpoint security, threat hunting, and vulnerability management. Direct incident response efforts, ensuring effective playbooks, rapid resolution, and post-incident learning. Drive automation, orchestration, and AI/ML-enabled threat detection to increase efficiency and reduce response times. Governance, Risk, & Compliance Partner with the GRC Team with security compliance frameworks (e.g., SOC 2, ISO 27001, PCI-DSS, HIPAA, FedRAMP, etc.) and ensure continuous readiness for audits. Develop and maintain enterprise security procedures, standards, and controls aligned to NIST, CIS, and OWASP frameworks. Participate in third-party risk management, vendor security assessments, and business continuity planning. Innovation & Emerging Technologies Provide guidance on secure adoption of cloud, SaaS, and SASE platforms. Champion responsible and secure use of emerging technologies (e.g., AI/ML, automation, zero trust, secure access). Anticipate future risks and proactively shape organizational security posture. Qualifications Education/Experience 10+ years of progressive information security experience, including significant leadership responsibility. 5+ years leading security teams in enterprise environments. Industry-recognized certifications strongly preferred (CISSP, CCISO, CISM, GSEC, GCIH, CEH, etc.). Required Skills/Abilities Proven success in building and maturing security programs that align with business strategy. Strong knowledge of security technologies (firewalls, DLP, IDS/IPS, MDM, SIEM, EDR, etc.) and modern architectures (SaaS, SASE, Zero Trust). Deep technical foundation across cloud/SaaS systems, network and endpoint security, cloud security, and secure configurations. Familiarity with penetration testing, forensic practices, and threat modeling. Strong executive communication skills with experience presenting to leadership, audit committees, and regulators. Demonstrated ability to lead cross-functional initiatives and drive measurable risk reduction. National Debt Relief Role Qualifications: Computer competency and ability to work with a computer. Prioritize multiple tasks and projects simultaneously. Exceptional written and verbal communication skills. Punctuality expected, ready to report to work on a consistent basis. Attain and maintain high performance expectations on a monthly basis. Work in a fast-paced, high-volume setting. Use and navigate multiple computer systems with exceptional multi-tasking skills. Remain calm and professional during difficult discussions. Take constructive feedback. Compensation Information Our salary ranges are determined by role, level, and location. The range displayed on each job posting reflects the minimum and maximum target for each position across the US. Within the range, individual pay is determined by work location, job-related skills, experience, and relevant education or training. This good faith pay range is provided in compliance with NYC law and the laws of other jurisdictions that may require a salary range in job postings. The salary for this position is $198,500 - $228,500. About National Debt Relief National Debt Relief was founded in 2009 with the goal of helping an expanding number of consumers deal with overwhelming debt. We are one of the most-trusted and best-rated consumer debt relief providers in the United States. As a leading debt settlement organization, we have helped over 450,000 people settle over $10 billion of debt, while empowering them to lead a healthier financial lifestyle and feel free to live their best life. At National Debt Relief, we treat our clients like real people. Our purpose is to elevate, empower, and transform their lives. Rated A+ by the Better Business Bureau, our goal is to help individuals and families get out of debt with the least possible cost through conducting financial consultations, educating the consumer and recommending the appropriate solution. We become our clients' number one advocate to help them reestablish financial stability as quickly as possible. Benefits National Debt Relief is a team-oriented environment full of rewards and growth opportunities for our employees. We are dedicated to our employee's success and growth within the company, through our employee mentorship and leadership programs. Our extensive benefits package includes: Generous Medical, Dental, and Vision Benefits 401(k) with Company Match Paid Holidays, Volunteer Time Off, Sick Days, and Vacation 12 weeks Paid Parental Leave Pre-tax Transit Benefits No-Cost Life Insurance Benefits Voluntary Benefits Options ASPCA Pet Health Insurance Discount Access to your earned wages at any time before payday National Debt Relief is a certified Great Place to Work ! National Debt Relief is an equal opportunity employer and makes employment decisions without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or any other status protected by law. For information about our Employee Privacy Policy, please see here For information about our Applicant Terms, please see here #LI-REMOTE
    $198.5k-228.5k yearly Auto-Apply 27d ago
  • Director, Information Security and Risk (Identity & Access Management)

    Cardinal Health 4.4company rating

    Remote job

    **_What Information Security and Risk contributes to Cardinal Health_** Information Security and Risk develops, implements, and enforces security controls to protect the organization's technology assets from intentional or inadvertent modification, disclosure or destruction. This job family develops system back-up and disaster recovery plans. Information Technology also conducts incident response, threat management, vulnerability scanning, virus management and intrusion detection and completes risk assessments. The _Director, Information Security and Risk (Identity & Access Management)_ is responsible for leading the organization's Identity & Access Management (IAM) strategy, governance, and operations to ensure secure, efficient, and compliant access to technology resources. This role requires a leader with proven ability to execute large-scale enterprise IAM programs that directly impact how employees, contractors, and customers interact with Cardinal Health technology. Success in this role demands a balance between delivering a frictionless, user-friendly experience and maintaining the highest standards of security. The Director must also excel at building partnerships across the organization and collaborating on program delivery, while driving operational excellence and anticipating business risks associated with IAM changes. **Location** - Ideally targeting individuals local to Central Ohio, but open to candidates located nationwide (fully remote). If living within commutable distance of our corporate HQ in Dublin, OH - the expectation would be to come in-office two or three days a month for team meetings. **Responsibilities** + Act as a visionary in designing and executing multi-year IAM strategy that aligns with business goals and customer needs + Develop and oversee enterprise IAM policies, standards, and procedures, ensuring consistent enforcement across the organization. + Lead IAM initiatives including identity lifecycle management (provisioning, de-provisioning, role-based access, entitlement reviews). + Direct privileged access management (PAM) programs to safeguard critical systems and sensitive data. + Ensure compliance with internal policies and external regulatory requirements (e.g., SOX, HIPAA, GDPR, PCI-DSS) through strong access controls. + Execute enterprise IAM programs with significant business impact, ensuring seamless access for employees, contractors, and customers. + Balance user experience with security by designing IAM solutions that are simple, intuitive, and resilient. + Drive operational excellence by establishing repeatable processes, KPIs, and service delivery models for IAM functions. + Build strong partnerships across IT, Security, HR, and business units to align IAM delivery with organizational priorities. + Establish metrics and reporting mechanisms to monitor IAM effectiveness, operational performance, and program maturity for executive leadership. + Lead training and awareness programs related to IAM policies, secure access practices, and identity governance. **Qualifications** + Bachelor's degree in Information Technology, Computer Science, Cybersecurity, or a related field preferred. + Ideally targeting individuals with 12+ years of IT/security experience with at least 5 years in IAM leadership roles preferred. + Proven track record of executing enterprise IAM programs with measurable business impact. + Prior people leadership experience and demonstrated ability to manage operational IAM teams, highly preferred. + Expertise with IAM tools and platforms (e.g., Okta, SailPoint, CyberArk, Azure AD). + Strong understanding of relevant Regulatory and Compliance requirements (HIPAA, SOX, HITRUST CSF, etc.). + Strong understanding of authentication protocols (SAML, OAuth, OpenID Connect, Kerberos) and cloud IAM (AWS IAM, Azure RBAC, GCP IAM). + Certifications such as CISSP, CIAM, or CISM preferred. + Strong analytical, relationship management, and communication skills (both written and verbal). + Ability to collaborate across functions and influence stakeholders to achieve IAM program success. **What is expected of you and others at this level** + Provides leadership to managers and experienced professional staff; may also manage front line supervisors + Manages an organizational budget + Develops and implements policies and procedures to achieve organizational goals + Assists in the development of functional strategy + Decisions have an extended impact on work processes, outcomes, and customers + Interacts with internal and/or external leaders, including senior management + Persuades others into agreement in sensitive situations while maintaining positive relationships _\#LI-LP_ _\#LI-Remote_ **Anticipated salary range:** $135,400 - $228,910 **Bonus eligible:** Yes **Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being. + Medical, dental and vision coverage + Paid time off plan + Health savings account (HSA) + 401k savings plan + Access to wages before pay day with my FlexPay + Flexible spending accounts (FSAs) + Short- and long-term disability coverage + Work-Life resources + Paid parental leave + Healthy lifestyle programs **Application window anticipated to close:** 12/25/2025 *if interested in opportunity, please submit application as soon as possible. The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity. _Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._ _Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._ _To read and review this privacy notice click_ here (***************************************************************************************************************************
    $135.4k-228.9k yearly 14d ago
  • Chief Information Security Officer (CISO)

    Optery, Inc.

    Remote job

    The Role Optery is seeking a hands-on, entrepreneurial CISO to lead and extend our security program end-to-end. This is a hands-on builder role for someone who not only sets the strategy, but also executes the plan, manages controls, reviews data, and interacts directly with employees, customers and auditors. You will partner closely with company leadership to advance our security, privacy, compliance, and controls programs. Optery's security program is already well-established, having successfully completed its SOC 2 security audits every year since 2022 through to today. You will be responsible for policies, risk, security operations, third-party/vendor security, application/product security, incident response, and supporting customer/security questionnaires. You will also be the internal champion for securing the organization and its people, customers, systems, and processes. Key Responsibilities Own Optery's information security strategy, roadmap, and policies, aligned to our industry-leading security and privacy products Lead and extend Optery's security program mapped to common frameworks (SOC 2, ISO 27001, CIS, NIST), appropriate for a high-growth, remote-first company Partner with engineering to embed secure SDLC practices: threat modeling, code scanning, secrets management, access controls, and secure cloud configuration Design and run an incident response program, including playbooks for data handling, data broker interactions, ransomware/social engineering scenarios, and customer notifications Oversee identity and access management across core systems (SaaS, cloud, data, admin apps) following least-privilege principles Lead vendor and third-party security reviews, especially for data- or privacy-impacting services Partner with GTM, finance, ops, and sales to complete security questionnaires, DPAs, and customer diligence to unblock deals Work with product/legal to ensure our data flows and retention/erasure practices align with CCPA, GDPR, and other consumer privacy laws we help our customers exercise Define, track, and report security KPIs/KRIs to leadership and the board Train and evangelize security practices across a distributed team so security is part of onboarding and day-to-day work Qualifications 8+ years in information security, with increasing ownership across GRC, security engineering, and/or product/app security Experience building or maturing a security program at a SaaS, data, cybersecurity, or privacy-focused company Practical experience with SOC 2 and/or ISO 27001 (authoring policies, gathering evidence, working with auditors, driving remediation) Strong understanding of cloud security (preferably AWS): networking, IAM, secret management, logging/monitoring Comfortable meeting with customers, prospects, and partners to explain Optery's security posture and win trust Excellent written and verbal communication skills; able to write policies people can actually follow Startup-friendly mindset: willing to prioritize, right-size controls, and make progress quickly Nice to have Experience at a company that handles PII Experience securing distributed/remote teams and mixed contractor/employee environments Background in data protection technologies (DLP, EDR, MDM, SSO, CASB) and how to roll them out in stages Experience supporting enterprise sales cycles by answering security questionnaires Recognized thought leader in security, fluent public speaker, and active participant in public-facing security communities and conferences Location Optery is a fully remote global team. This role is based in the United States and requires working U.S. business hours (Eastern, Central, Mountain, or Pacific). Compensation and Benefits Base Salary: $200,000 - $220,000 Competitive Equity Health, dental, and vision insurance 401(k) with employer match Paid time off Home office stipend Equal Opportunity Optery values diversity and is an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, sexual orientation, marital status, disability, genetic information, age, parental status, military service, or any other non-merit factor.
    $200k-220k yearly Auto-Apply 39d ago
  • Chief Information Security Officer (Veterans Affairs Business Area)

    GDIT

    Remote job

    Type of Requisition: Regular Clearance Level Must Currently Possess: None Clearance Level Must Be Able to Obtain: None Public Trust/Other Required: MBI (T2) Job Family: Cyber and IT Risk Management Job Qualifications: Skills: Data Security, Federal Government, Security Standards Certifications: None Experience: 15 + years of related experience US Citizenship Required: No Job Description: Join GDIT where your work will improve outcomes for our Veterans. You will support the Veterans Affairs Business Area within GDIT to ensure strict compliance of cloud hosting environments meet both GDIT security controls as well as Department of Veterans Affairs (VA). Together, we're building a secure future of managed services solutions that includes customer data in company-owned and company-controlled environment. GDIT's high-impact solutions improve the delivery of VA services to our Veterans and their families. As GDIT's VA Business Area Chief Information Security Officer (CISO), you will lead a team of Cyber Security Engineers, System Engineers and Architects supporting current and future state of our cloud environments under a VA authority-to-operate (ATO). You will create and implement cyber security best practices and refine their strategies and approaches to meet long-term needs. You will also help to grow our business, supporting proposals and meeting with customers to strategize on best practices for both their Cyber Security and Data Privacy needs. HOW YOU WILL MAKE AN IMPACT: Develop and implement security and privacy solutions, best practices, controls and reporting mechanisms for the VA Business Area portfolio. Coordinate all security and privacy activities across all the VA Business Area contracts; as well as track improvements and ensure minimized risk profiles, etc. Serve as the single POC for GDIT corporate reporting and data calls within the Federal Health sector, coordinating corporate security standards. Serve as advisor for Cyber Incidents and Incident Response affecting VA Business Area. Champion Cyber and IT KPIs across the VA Business Area, working closely with FedHealth Risk team. Lead and/or support solutions for cybersecurity aspects for proposals across the VA Business Area. Serve as a trusted advisor to our VA customer and other CISO's across the Federal Health division Collaborate and support security activities across the broader Federal Health division. Lead and coordinate the activities of a team of security engineers and system administrators responsible for security on individual VA contracts. Create a communities of practice, ensure appropriate training to keep our teams up to date, create career paths, etc. Prepare and provide various reports and technical cyber security reviews to senior management as requested. Ensures compliance with relevant corporate and VA policies and standards. WHAT YOU'LL NEED (required): Bachelor's degree or equivalent. 15+ years related experience. 5+ years direct FISMA data security for Federal Agencies. 4+ years of direct experience supporting the cyber security controls of solutions into an AWS or Azure cloud environment for Government Contracts CISSP or equivalent professional certification. Experience managing a cyber-practice/cyber security program portfolio across multiple customer bases within the Federal government health sector (and preferably across Federal Civilian customers as well) Experience leading cyber solutions for major government proposals / solicitations Experience managing and developing a team of cyber professionals. Demonstrable experience building and growing exceptional customer relationships. Expertise with government Authorization to Operate (ATO) and Security Control Assessment (SCA) processes for traditional data centers and FedRAMP space Strong technical understanding and abilities in both cyber security and data privacy Experience managing the client interface at senior levels of an organization Outstanding written and verbal communication skills with the ability to present to business leaders Must be able to obtain a MBI (T2) and successfully pass a thorough a government background screening process requiring the completion of detailed forms and fingerprinting WHAT WOUDL BE EVEN BETTER (preferred): Current or previous Veterans Affairs experience Recognition as a leader in the Federal cyber industry (i.e. speaking engagements, published articles, quotes on current cyber topics, etc.) is strongly preferred Experience developing technical presentations and/or writing WHY GDIT: Work on a mission that matters-delivering outcomes for Veterans and their families. Access the latest cloud and automation technologies in a modern engineering environment. Enjoy flexible work options, continuous learning, and a strong culture of purpose and performance. Be part of a collaborative team driving innovation in government IT. The likely salary range for this position is $129,625 - $175,375. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range. Scheduled Weekly Hours: 40 Travel Required: Less than 10% Telecommuting Options: Remote Work Location: Any Location / Remote Additional Work Locations: Total Rewards at GDIT: Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. GDIT typically provides new employees with 15 days of paid leave per calendar year to be used for vacations, personal business, and illness and an additional 10 paid holidays per year. Paid leave and paid holidays are prorated based on the employee's date of hire. The GDIT Paid Family Leave program provides a total of up to 160 hours of paid leave in a rolling 12 month period for eligible employees. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.We are GDIT. A global technology and professional services company that delivers consulting, technology and mission services to every major agency across the U.S. government, defense and intelligence community. Our 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50 countries worldwide, offering leading capabilities in digital modernization, AI/ML, Cloud, Cyber and application development. Together with our clients, we strive to create a safer, smarter world by harnessing the power of deep expertise and advanced technology.Join our Talent Community to stay up to date on our career opportunities and events at gdit.com/tc. Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
    $129.6k-175.4k yearly Auto-Apply 3d ago
  • Chief Information Security Officer (CISO)

    Enterprise Mangement Solutions Inc.

    Remote job

    ABOUT ENTERPRISE MANAGEMENT: Enterprise Management Solutions, LLC. (Enterprise) is a full-spectrum administrative and operational management firm headquartered in Baltimore, Maryland. We provide contracted infrastructure support to independently governed organizations in sectors such as behavioral health, primary care, supportive housing, food service, commercial real estate, and nonprofit development. Enterprise does not own or govern the organizations we serve. Instead, we operate as a trusted administrative services provider under formal contractual agreements, offering high-level back-office services that allow our clients to focus on mission execution and program delivery. Our scope of service includes: Comprehensive fiscal systems and multi-entity accounting Human resource infrastructure and staff onboarding Legal compliance and audit readiness Technology integration and IT systems governance Organizational growth planning and fiscal sustainability analysis Federal and state grant compliance, budget monitoring, and reporting Financial and operational performance dashboards CEO- and executive-level strategy support Our goal is to relieve mission-driven companies of administrative burden by overseeing financial and operational systems that allow leadership teams to focus on quality care and innovation. DISCLOSURES: The specific statements shown in each section of this are not intended to be all-inclusive. They represent typical elements and criteria considered necessary to perform the job successfully. The job's responsibilities/tasks may be modified and/or expanded over time. Company will inform the personnel member when changes in the respective job description are made. COMPANY WEBSITE: ********************************* COMPANY PHONE NUMBER: ************** HUMAN RESOURCES PHONE NUMBER: ************** ext. 10 POSITION TITLE: Chief Information Security Officer (CISO) ALTERNATE TITLE(S): Chief Cybersecurity Officer (CCSO), Chief Security Officer (CSO - Cybersecurity), Senior Cybersecurity Executive COMPANY: Enterprise Management Solutions, LLC. (in support of all customer companies under contract) DIVISION: Technology & Information Security DEPARTMENT: n/a UNIT: n/a BENEFITS PACKAGE: In addition to hourly wages, eligible employees may receive a comprehensive benefits package that includes: Paid Time Off (PTO) Family and Medical Leave Health, Medical, and Dental Insurance Reimbursement or health insurance coverage, as available Supplemental Health and Disability Insurance Options Retirement Savings Plan Professional Development Support and Continuing Education Opportunities WORK SCHEDULE: Two days per week: Tuesday and Thursday, 8:00 AM - 5:00 PM (daily lunch break from 12:00 PM - 1:00 PM) ACCOUNTABLE TO: Chief Executive Officer (COO, in absence of CEO) ACCOUNTABLE FOR: Oversight of cybersecurity strategy, data protection, regulatory compliance, and the supervision of all information security systems, personnel, and vendors across all affiliated companies. This role is responsible for ensuring uninterrupted cybersecurity operations, incident response readiness, and cross-training protocols to protect critical client and company assets. CLASSIFICATION: W-2 employee; part-time hourly COMPENSATION RANGE: Ranges between $55.00 per hour to $90.00 per hour, and is commensurate with experience, expertise, verified credentials, and available company budget. ANTICIPATED TRAVEL: Up to 10% of the time (interoffice and site-based meetings) WORKPLACE POLICY: This is a 100% in-office role at Baltimore HQ, two days per week. Remote work or telework is prohibited unless explicitly pre-approved in writing by the CEO. SUMMARY OF POSITION RESPONSIBILITIES: The Chief Information Security Officer (CISO) serves as the organization's highest-ranking cybersecurity executive, responsible for designing, implementing, and maintaining a resilient information security program that safeguards company and client systems against internal and external threats. The CISO oversees all areas of cybersecurity including policy development, risk management, threat detection, incident response, and compliance with federal and state regulations (HIPAA, HITECH, GDPR, SOC2, PCI-DSS, NIST, and others as applicable). This role also ensures that Enterprise delivers all contracted Information Security, IT Governance, and Cybersecurity Risk Management services to affiliated entities, protecting sensitive healthcare, housing, financial, and client records. The CISO plays a critical role in aligning technology security with enterprise goals, while proactively mitigating risks across all operational areas. SCHEDULED DUTIES AND RESPONSIBILITIES: Cybersecurity Strategy & Leadership Develop and execute a company-wide cybersecurity program aligned with business and client requirements. Translate the CEO's strategic vision into measurable, risk-based security initiatives. Conduct long-term security planning, including disaster recovery and business continuity. Risk Management & Regulatory Compliance Ensure strict compliance with HIPAA, HITECH, GDPR, SOC2, PCI-DSS, NIST, and state regulations. Perform enterprise-wide risk assessments and vulnerability scans. Maintain and update incident response, breach notification, and audit readiness protocols. Threat Monitoring & Incident Response Direct the Security Operations Center (SOC) or equivalent vendor-managed services. Oversee intrusion detection, SIEM monitoring, log review, and malware defense. Lead incident response, forensic investigation, and breach communication with executive leadership. Identity, Access, and Data Security Manage identity and access management systems, including MFA and privileged access controls. Oversee endpoint, mobile device, and server security configurations. Ensure encryption, secure backups, and data loss prevention across all platforms. Vendor & Third-Party Oversight Review vendor contracts, security certifications, and compliance attestations. Establish standards for secure integration with external technology providers. Lead vendor risk management and third-party security audits. Internal Policies & Training Develop internal cybersecurity policies, acceptable use guidelines, and SOPs. Deliver quarterly staff training on phishing, ransomware, and cybersecurity awareness. Conduct simulated incident drills and security tabletop exercises. Collaboration & Executive Support Advise the CEO and COO on cybersecurity risks and budget needs. Partner with CFO, HR, and Operations Managers to ensure cross-department compliance. Provide security briefings to the Board of Directors and client executives. UNSCHEDULED DUTIES AND RESPONSIBILITIES: Respond to emergent cybersecurity threats or system alerts. Support investigations of insider threats, fraud, or data misuse. Participate in interdepartmental workgroups to integrate new systems securely. Maintain active knowledge of evolving threats, ransomware tactics, and industry best practices. Lead recovery efforts in the event of a cyber-attack or natural disaster affecting IT infrastructure. PHYSICAL DEMANDS: Prolonged periods sitting at a desk and working on a computer. Occasional lifting up to 25 pounds. WORKING CONDITIONS: Cross-functional collaboration with executives and technical staff. 100% in-office role at Baltimore HQ (two days per week, no remote or hybrid unless CEO approved). Travel up to 10% may be required for audits, client meetings, or incident response. Must be available during scheduled hours with flexibility for emergent needs. COMPETENCIES AND SKILLS: Visionary leadership with deep technical and cybersecurity acumen. Expertise in risk management, incident response, and compliance frameworks. Skilled in cloud security (AWS, Azure, Google Cloud), SaaS protection, and on-premises systems. Strong command of cybersecurity frameworks: NIST CSF, ISO 27001, COBIT. Familiarity with healthcare IT and HIPAA/HITECH security requirements. Effective communicator able to brief executives and train staff. Demonstrated ability to lead multidisciplinary teams and manage security vendors. LEVEL OF EDUCATION / TRAINING / QUALIFICATIONS: Master's degree in Cybersecurity, Computer Science, or Information Technology (required). Certified Information Systems Security Professional (CISSP) in good standing (required). Additional certifications (CISM, CISA, CCSP, CRISC) strongly preferred. Minimum 8-10 years of progressive cybersecurity leadership experience, with at least 5 years in a senior or CISO role. Experience overseeing security in healthcare, housing, financial, or government environments strongly preferred. Demonstrated track record of regulatory compliance, successful incident response, and enterprise-level security program development.
    $55-90 hourly 60d+ ago
  • Vice President, Chief Information Security Officer

    Kldiscovery 2.7company rating

    Remote job

    Introduction KLDiscovery offers a fantastic opportunity for you to use your talents to make a meaningful impact in a fast-paced, growing technology and services organization! KLDiscovery is a global leader in eDiscovery, compliance, and data management solutions, empowering law firms, corporations, and government agencies to tackle their most complex legal and regulatory challenges. We are looking for a Vice President, Chief Information Security Officer to join our team who is passionate about our mission and brings initiative, authenticity, and collaborative spirit to everything they do. If you're fueled by innovation and committed to delivering exceptional results, KLDiscovery is the perfect place to grow your career. Work Status: Remote, work from home opportunity. Is This Role For You? The Vice President, Chief Information Security Officer provides strategic and operational direction to the organization to ensure the attainment of business objectives. Ensure that all revenue and profit goals are met. Revise objectives and policies in response to changes in internal and external conditions. Coordinate operations between divisions and departments. Establish responsibilities and procedures for attaining objectives. Establish strategies and objectives, coordinating with all organizational goals and standards. Responsible for financial performance and attainment of profit goals. A Day in The Life Development of policies and standards aimed at minimizing costs related to acquisition, implementation, and operation of IT systems across business units. This includes the management of vendor relationships and ensuring this is leveraged across business units. Manage and develop key performance indicators to assure customer satisfaction and operational performance; manage problem escalation and communication with senior management and customers where appropriate. Ensure software and hardware license compliance through documented, established process. Coordinate gap analysis to identify training needs for department. Define requirements and ensure compliance for next level of advancement. Direct, coach, and mentor management staff in performance management skills. Build a department that optimizes senior talent, while promoting the growth of junior talent. Performance Management including collecting data on regular basis, organize and create annual reviews, provide regular coaching of individuals. Manage the timeliness of reviews for the department. Provide daily operational direction and oversight in meeting committed service level agreements (SLAs). Maintain and improve operational policies and procedures. Provide quarterly updates to the BoD and Senior Level Management. Travel as necessary for internal needs as well as client requested audits. What You Will Bring To The Role Bachelor's degree in technology-related field or equivalent work experience. 15+ years' experience; Ten to Thirteen years management. This experience should include: Management of production data centers and external customer SLA support Demonstrated success in providing best practice process and support implementation Proven track record and managing teams of 20 or more people Demonstrated knowledge of global telecommunications Demonstrated quality control implementation experience Demonstrated success in change management Extensive experience with the build out, growth, management, and support of high-volume Data Centers Fiscal responsibility, including creating and managing to a budget Demonstrated ability to create a vision for IT Operations focused on IT Service Management and ITIL Demonstrated success in defining, tracking, and communicating internal and business focused metrics Demonstrated success in defining and implementing a global IT shared services model Coaching, developing, and mentoring direct reports and ensure processes are in place to develop the future leaders of the IT organization Skills: Must be able to synthesize large amounts of data/concepts effectively into understandable terms both written and oral Must be capable of communicating with Sr. Level Management both verbally and in written communications Must be adaptive with varied skill sets that can fit into a variety of project situations Must be quick learning and possess a high comfort-level with non-repetitive projects and new challenges Must be quick thinking: ability to listen, grasp concepts and engage during interactive discussions Should be able to work with limited supervision Should have strong organizational and time management skills Should be well rounded with an exceptional work ethic Should be results-oriented with an exceptional ability to be independent, motivated, and proactive Should be customer-focused and possess resilient interpersonal talents and poise to manage change Excellent communication (oral, listening, and writing) skills Strong problem solving, time management and organizational skills Understanding of data center commercial market space General knowledge of applications management processes and methodologies Expert knowledge of system management and process methodologies and practices Strong understanding with practical application of WAN/LAN and internet connectivity and concepts. Driving Career Growth, Benefit Excellence: The KLD Advantage At KLD we invest in employees and their families by placing their wellbeing first. We offer competitive total compensation that includes base pay, bonus potential, inclusive benefits, wellness programs, and perks. We use market and industry data to inform pay decisions while considering geography and labor markets, individual experience, and business needs. Individual compensation will vary, although a reasonable estimate of the current annualized base pay range for this position is $200,000 to $250,000. We offer a high-performance laptop computer, options for wireless headset or external speaker, up to two 24” 2K monitors, and a mobile phone for business use. Generous paid time off, offering various time off options to help employees maintain a work-life balance, such as vacation, paid sick leave, parental leave, paid jury leave, and more! Comprehensive health, dental, vision and supplemental benefits packages that include life insurance, short- and long-term disability, to promote the health of our employees. Remote-friendly, flexible working culture, where you can apply to work from several global locations. A focus on continuous professional development through various training and education reimbursement programs. A diverse and inclusive workplace where we all learn, grow, and achieve the greatest heights…together. A surrounding team of mission-driven individuals who genuinely love what they do. Equity incentives and company bonus programs; that way, we all share in the success of KLDiscovery. Free, fun, interactive and incentivized global wellness program that promotes the wellbeing of our employees plus offers a wide range of perks and discounts! Free Employee Assistance Program (EAP) because we all could use a little help and support every now and then. 401(k) with employer match, to help our employees achieve financial success. KLD supports the communities where our employees live and offers a paid community service day for employees to volunteer with what resonates with them. To keep our furry, 4-legged family members healthy, KLD employees can opt for Pet Insurance. Who We Are KLDiscovery provides technology-enabled services and software to help law firms, corporations, and government agencies solve complex data challenges. With offices in 26 locations across 17 countries, KLDiscovery is a global leader in delivering best-in-class data management, information governance, and eDiscovery solutions to support the litigation, regulatory compliance, and internal investigation needs of clients. Our Nebula Ecosystem provides powerful end-to-end eDiscovery and enterprise-grade information governance. Through its global Ontrack data recovery business, KLDiscovery delivers world-class data recovery, disaster recovery, email extraction and restoration, data destruction, and tape management. We Provide Equal Employment Opportunity At KLDiscovery we believe that inclusion and diversity make us stronger. We are committed to fostering an inclusive environment for all employees that enhances wellbeing and belonging. We welcome and celebrate individuals of all backgrounds, experiences, and perspectives. We do not discriminate on the basis of race, color, religion, gender, pregnancy, gender identity, sexual orientation, national origin, age, disability, genetic information, veteran status, or any other protected status. We are happy to support you with any accommodation request at any stage in our hiring process. Texas PI# A04094801 #LI-TF1 #LI-Remote
    $200k-250k yearly Auto-Apply 20d ago
  • Principal, Business Information Security Officer (BISO)

    LPL Financial Services 4.7company rating

    Remote job

    What if you could build a career where ambition meets innovation? At LPL Financial, we empower professionals to shape their success while helping clients pursue their financial goals with confidence. What if you could have access to cutting-edge resources, a collaborative environment, and the freedom to make an impact? If you're ready to take the next step, discover what's possible with LPL Financial. Job Overview: The Principal, Business Information Security Officer (BISO) plays a crucial role in ensuring the secure evolution of LPL Financial's product portfolio. Aligned with specific executives across the business, this role is responsible for the alignment with their business unit's cybersecurity strategy with the overall corporate cybersecurity strategy. The BISO will drive risk remediation efforts, educate members of their business unit on operationalization of cybersecurity policies and procedures, and be the primary interface point for the business unit. They become the cybersecurity subject matter expert for their domain and use that knowledge to report back to the cybersecurity team on the direction the business is going, and vice-versa. Responsibilities: * Act as the primary InfoSec liaison for Product, Business, and Technology Leadership, ensuring security integration into business strategies. * Serve as the primary point of contact for the assigned business unit. * Drive security-related change management, ensuring transparent communication with advisors and key stakeholders. * Provide technical and business guidance on cybersecurity risk, including application security (OWASP), cloud security (AWS/Azure), and IAM principles. * Facilitate risk-adjusted security exception management, supporting product leaders in remediation efforts. * Collaborate with security and product teams to reduce friction and improve alignment between InfoSec practices and business goals. * Understand cybersecurity objectives and assist business leaders with resource planning * Offer executive-level reporting on security posture and risk management efforts. What We Are Looking For: We seek innovative, strategic thinkers who thrive in fast-paced environments, are highly collaborative, and can translate complex security concepts for executive and non-executive audiences. Requirements: * 7+ years of cybersecurity risk management experience, including identification, synthesis, and remediation strategies. * Strong knowledge of NIST CSF 2.0 and other industry security frameworks. * Extensive experience working in a matrix reporting model, supporting both operational and transformational cybersecurity initiatives. * Executive presence with a proven ability to engage stakeholders, influence decision-making, and communicate security strategies effectively. * Technical expertise across cloud security (AWS/Azure), DevSecOps, application security, and secure data-handling processes. Preferences: * Bachelor's degree in Computer Science, Information Systems, or a related field. * 10+ years in cybersecurity, risk management, or security program management. * Strong relationship-building and cross-functional collaboration skills. * Certifications such as CISSP, GIAC, CCSP, or other cloud security credentials. * Experience in Agile security methodologies and understanding of Software Development Life Cycle (SDLC). * Practical offensive security experience such as penetration testing or red teaming #LI-Hybrid Pay Range: $143,100-$238,500/year Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location. Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play - such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more. Your recruiter will be happy to discuss all that LPL has to offer! Company Overview: LPL Financial Holdings Inc. (Nasdaq: LPLA) is among the fastest growing wealth management firms in the U.S. As a leader in the financial advisor-mediated marketplace. LPL supports over 29,000 financial advisors and the wealth-management practices of 1,100 financial institution, servicing and custodying approximately $1.9 trillion in brokerage and advisory assets on behalf of approximately 7 million Americans. The firm provides a wide range of advisor affiliation models, investment solutions, fintech tools and practice management services, ensuring that advisors and institutions have the flexibility to choose the business model, services, and technology resources they need to run thriving businesses. At LPL, independence means that advisors and institution leaders have the freedom they deserve to choose the business model, services, and technology resources that allow them to run a thriving business. They have the flexibility to do business their way. And they have the freedom to manage their client relationships, because they know their clients best. Simply put, we take care of our advisors and institutions, so they can take care of their clients. For further information about LPL, please visit ************ Join LPL Financial: Where Your Potential Meets Opportunity At LPL Financial, we believe that everyone deserves objective financial guidance. As the nation's leading independent broker-dealer, we offer an integrated platform of cutting-edge technology, brokerage, and investment advisor services. Why LPL? * Innovative Environment: We foster creativity and growth, providing a supportive and responsive leadership team. Learn more about our leadership team here! * Limitless Career Potential: Your career at LPL has no limits, only amazing potential. Learn more about our careers here! * Unified Mission: We are one team on one mission-taking care of our advisors so they can take care of their clients. Learn more about our mission and values here! * Impactful Work: Our size is just right for you to make a real impact. Learn more here! * Commitment to Equality: We support workplace equality and embrace diverse perspectives and backgrounds. Learn more here! * Community Focus: We care for our communities and encourage our employees to do the same. Learn more here! * Benefits and Total Rewards: Our Total Rewards package goes beyond just compensation and insurance. It includes a mix of traditional and unique benefits, perks, and resources designed to enhance your life both at work and at home. Learn more here! Join the LPL team and help us make a difference by turning life's aspirations into financial realities. Please log in or create an account to apply to this position. Principals only. EOE. Information on Interviews: LPL will only communicate with a job applicant directly from ******************** email address and will never conduct an interview online or in a chatroom forum. During an interview, LPL will not request any form of payment from the applicant, or information regarding an applicant's bank or credit card. Should you have any questions regarding the application process, please contact LPL's Human Resources Solutions Center at **************. EAC1.22.25
    $143.1k-238.5k yearly Auto-Apply 48d ago
  • Chief Information Security Officer

    Creditly Corp

    Remote job

    Company Credit Genie is a mobile-first financial wellness platform designed to help individuals take control of their financial future. We leverage artificial intelligence to provide personalized insights and are building a financial ecosystem by offering tools and services that provide instant access to cash, and building credit. Our goal is to empower every customer to achieve long-term financial stability. Founded in 2019 by Ed Harycki, former Swift Capital Founder (acquired by PayPal in 2017). Backed by Khosla Ventures and led by industry pioneers from companies such as; PayPal, Square, and Cash App, we are well positioned to build the future of inclusive finance through cutting-edge technology and customer-centric solutions. Overview As Chief Information Security Officer (CISO), you will be the primary leader responsible for developing and implementing our information security strategy. You'll protect our systems, data, and customer trust by overseeing cybersecurity operations, ensuring compliance with regulatory standards, and mitigating risks in a dynamic fintech environment. This role demands a visionary leader with deep expertise in cybersecurity, preferably in fintech, and a passion for securing innovative financial products. What you'll do * Develop and execute a comprehensive cybersecurity strategy to protect our platform, customer data, and intellectual property. * Ensure compliance with fintech and data privacy regulations, including GDPR, CCPA, PCI-DSS, and other relevant standards. * Oversee the design, implementation, and monitoring of security controls for payment processing, lending platforms, and other financial products. * Lead incident response, including managing and mitigating cybersecurity breaches, vulnerabilities, and regulatory inquiries. * Collaborate with product, engineering, and compliance teams to embed security-by-design principles into new features and services. * Build and maintain a robust security framework for credit and lending operations, ensuring protection against fraud and data breaches. * Conduct risk assessments and implement mitigation strategies for emerging threats in the fintech landscape. * Manage relationships with external security vendors, auditors, and regulatory bodies. * Develop and lead a high-performing security team, fostering a culture of proactive risk management. * Support international expansion by aligning security practices with global data protection and financial regulations. * Stay ahead of cybersecurity trends, advising the executive team on evolving threats and technologies. Who you are * Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Technology, or a related field. * 10+ years of progressive experience in cybersecurity, with at least 5 years in a senior leadership role at a fintech or high-growth tech company. * Deep expertise in securing credit and lending platforms, preferably in the fintech industry, with knowledge of fraud prevention, secure payment processing, and regulatory compliance (e.g., Truth in Lending Act, Fair Credit Reporting Act). * Proven track record in designing and implementing security architectures for cloud-based systems, APIs, and financial applications. * Strong understanding of data privacy, encryption, and consumer protection laws in a fintech context. * Experience leading incident response, penetration testing, and vulnerability management programs. * Exceptional communication skills, with the ability to explain complex security concepts to non-technical stakeholders, from engineers to board members. * Strategic mindset with the ability to balance security rigor with business innovation in a fast-paced startup environment. Nice to have * Experience at a fintech company with exposure to payment processing, lending, or brokerage platforms. * Familiarity with SOC 2, ISO 27001, or other cybersecurity certifications and frameworks. * Knowledge of international cybersecurity regulations to support global operations. * Experience building and scaling security teams in high-growth environments. Benefits and Perks Our goal is to provide a comprehensive offering of benefits and perks that promote better financial, mental, and physical wellness. We believe working alongside each other in person is the best way to build a great product and foster a strong company culture. Our expectation is that employees are in the office five days a week, allowing for optimal collaboration, inclusivity, and productivity. At the same time, we understand that life happens and recognize the importance of flexibility. We are committed to supporting our employees when circumstances arise that require remote work or adjusted schedules. Our goal is to ensure everyone can effectively balance personal and professional responsibilities while maintaining our collaborative and productive environment. Here are some highlights of our benefits and perks offerings, feel free to ask your recruiting partner for more details on our comprehensive offering for employees. * 100% company-paid medical, dental, and vision coverage for you and your dependents on your first day of employment. * Monthly fitness reimbursement up to $100 or a full membership to LifeTime Fitness * 401(k) with a 2.5% match and immediate vesting * Meal program for breakfast, lunch, and dinner * Life and accidental insurance * Flexible PTO Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, and experience. Base salary is just one part of your total compensation and rewards package at Credit Genie. You may also be eligible to participate in the bonus and equity programs. You will also have access to comprehensive medical, vision, and dental coverage, a 401(k) retirement plan with company match, short & long term disability insurance, life insurance, and flexible PTO along with many other benefits and perks. Credit Genie is a proud Equal Opportunity Employer where we welcome and celebrate differences. We are committed to providing a workspace that is safe and inclusive, where everyone feels supported, connected, and inspired to do their best work. If you require any accommodations to participate in our recruitment process, please inform us of your needs when we contact you to schedule an interview.
    $108k-162k yearly est. 60d+ ago
  • Chief Information Security Officer

    Credit Genie

    Remote job

    Company Credit Genie is a mobile-first financial wellness platform designed to help individuals take control of their financial future. We leverage artificial intelligence to provide personalized insights and are building a financial ecosystem by offering tools and services that provide instant access to cash, and building credit. Our goal is to empower every customer to achieve long-term financial stability. Founded in 2019 by Ed Harycki, former Swift Capital Founder (acquired by PayPal in 2017). Backed by Khosla Ventures and led by industry pioneers from companies such as; PayPal, Square, and Cash App, we are well positioned to build the future of inclusive finance through cutting-edge technology and customer-centric solutions. Overview As Chief Information Security Officer (CISO), you will be the primary leader responsible for developing and implementing our information security strategy. You'll protect our systems, data, and customer trust by overseeing cybersecurity operations, ensuring compliance with regulatory standards, and mitigating risks in a dynamic fintech environment. This role demands a visionary leader with deep expertise in cybersecurity, preferably in fintech, and a passion for securing innovative financial products. What you'll do Develop and execute a comprehensive cybersecurity strategy to protect our platform, customer data, and intellectual property. Ensure compliance with fintech and data privacy regulations, including GDPR, CCPA, PCI-DSS, and other relevant standards. Oversee the design, implementation, and monitoring of security controls for payment processing, lending platforms, and other financial products. Lead incident response, including managing and mitigating cybersecurity breaches, vulnerabilities, and regulatory inquiries. Collaborate with product, engineering, and compliance teams to embed security-by-design principles into new features and services. Build and maintain a robust security framework for credit and lending operations, ensuring protection against fraud and data breaches. Conduct risk assessments and implement mitigation strategies for emerging threats in the fintech landscape. Manage relationships with external security vendors, auditors, and regulatory bodies. Develop and lead a high-performing security team, fostering a culture of proactive risk management. Support international expansion by aligning security practices with global data protection and financial regulations. Stay ahead of cybersecurity trends, advising the executive team on evolving threats and technologies. Who you are Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Technology, or a related field. 10+ years of progressive experience in cybersecurity, with at least 5 years in a senior leadership role at a fintech or high-growth tech company. Deep expertise in securing credit and lending platforms, preferably in the fintech industry, with knowledge of fraud prevention, secure payment processing, and regulatory compliance (e.g., Truth in Lending Act, Fair Credit Reporting Act). Proven track record in designing and implementing security architectures for cloud-based systems, APIs, and financial applications. Strong understanding of data privacy, encryption, and consumer protection laws in a fintech context. Experience leading incident response, penetration testing, and vulnerability management programs. Exceptional communication skills, with the ability to explain complex security concepts to non-technical stakeholders, from engineers to board members. Strategic mindset with the ability to balance security rigor with business innovation in a fast-paced startup environment. Nice to have Experience at a fintech company with exposure to payment processing, lending, or brokerage platforms. Familiarity with SOC 2, ISO 27001, or other cybersecurity certifications and frameworks. Knowledge of international cybersecurity regulations to support global operations. Experience building and scaling security teams in high-growth environments. Benefits and Perks Our goal is to provide a comprehensive offering of benefits and perks that promote better financial, mental, and physical wellness. We believe working alongside each other in person is the best way to build a great product and foster a strong company culture. Our expectation is that employees are in the office five days a week, allowing for optimal collaboration, inclusivity, and productivity. At the same time, we understand that life happens and recognize the importance of flexibility. We are committed to supporting our employees when circumstances arise that require remote work or adjusted schedules. Our goal is to ensure everyone can effectively balance personal and professional responsibilities while maintaining our collaborative and productive environment. Here are some highlights of our benefits and perks offerings, feel free to ask your recruiting partner for more details on our comprehensive offering for employees. 100% company-paid medical, dental, and vision coverage for you and your dependents on your first day of employment. Monthly fitness reimbursement up to $100 or a full membership to LifeTime Fitness 401(k) with a 2.5% match and immediate vesting Meal program for breakfast, lunch, and dinner Life and accidental insurance Flexible PTO Your actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, and experience. Base salary is just one part of your total compensation and rewards package at Credit Genie. You may also be eligible to participate in the bonus and equity programs. You will also have access to comprehensive medical, vision, and dental coverage, a 401(k) retirement plan with company match, short & long term disability insurance, life insurance, and flexible PTO along with many other benefits and perks. Credit Genie is a proud Equal Opportunity Employer where we welcome and celebrate differences. We are committed to providing a workspace that is safe and inclusive, where everyone feels supported, connected, and inspired to do their best work. If you require any accommodations to participate in our recruitment process, please inform us of your needs when we contact you to schedule an interview.
    $108k-162k yearly est. Auto-Apply 14d ago
  • Chief Information Security Officer

    Skylights of Hawaii 4.2company rating

    Remote job

    About Skylight Skylight is a digital consultancy using design and technology to help government agencies deliver better public services. We're at the forefront of a civic movement to reinvent how all levels of government serve families, patients, and many others in today's digital world. If you want to play a part in driving this critical movement forward, we'd love for you to join our growing team of public interest technologists. The work we do matters. About the job As Skylight's Chief Information Security Officer (CISO), you'll lead Skylight's security, compliance, and policy efforts, ensuring they align with Skylight's business, technical, and regulatory requirements. As a trusted advisor and partner across the organization, you'll balance deep technical understanding with clear communication and strong relationship-building skills. Because Skylight supports multiple federal clients, our work must comply with CMMC Level 2, NIST 800-171, and, potentially, HIPAA. You'll play a pivotal role in maintaining compliance with these regulations by developing organizational readiness, guiding engineering teams, and ensuring secure, compliant operations across all systems. In this role, you'll report directly to the Chief Information Officer (CIO). This is a hands-on, collaborative leadership role where you'll partner closely with the CIO on priorities, decisions, and direction. You'll also collaborate with the CIO on key aspects of Skylight's IT infrastructure, including onboarding/offboarding, account management, and role-based access controls. While you don't need to be an expert administrator for every tool we use, your partnership in this area is essential to maintaining both operational integrity and regulatory compliance. What you'll do Lead the design, implementation, and day-to-day operation of Skylight's information security and compliance efforts Maintain and continuously improve compliance with Skylight's regulatory requirements, including NIST 800-171, CMMC Level 2, and HIPAA Represent Skylight externally for security audits, risk assessments, and communication with external assessors Collaborate with the Chief Operating Officer (COO) and CIO to achieve and maintain Skylight's facility security clearance (FCL) Administer and enforce identity and access management across Skylight's IT infrastructure, including AWS, Azure, Google Cloud Platform (GCP), Google Workspace, and Slack Partner with project and delivery teams to integrate security and compliance into project planning, delivery, and client communications Lead periodic risk assessments and report findings to the CIO and leadership team to inform decision-making Develop and maintain internal security and IT policies, ensuring they're accessible, practical, and actionable Deliver annual security awareness training across the organization Collaborate with the CIO to align security priorities with company strategy and resource planning Stay current on evolving security practices, technologies, and emerging threats What we're looking for Minimum qualifications An active security clearance or the eligibility to obtain one Hands-on experience with identity and access management (IAM), role-based access control (RBAC), and related concepts in AWS, Azure, and GCP Demonstrated success leading security audits or compliance assessments Excellent communication and documentation skills, with the ability to explain technical and regulatory concepts in plain language Experience enumerating and mitigating organizational vulnerabilities Experience mitigating security risks in the software development life cycle at the organizational level Ability to interpret and translate non-technical material, such as regulations, into business and technical requirements Deep understanding of and achieving compliance with NIST 800-171 Proven ability to foster trust and collaboration across technical and non-technical teams Ability to work successfully within a professional services environment (e.g., can communicate effectively with clients) A passion for creating better public outcomes through great government services A mindset and work approach that aligns with our core values Ability to travel for work from time to time Nice-to-have qualifications Expertise in other relevant regulatory frameworks like CMMC, HIPAA, or FISMA Hands-on experience administering Google Workspace Professional development experience in at least one programming language Professional experience working with infrastructure-as-code Prior experience working in the civic tech space Experience working in a remote-team environment Don't meet 100% of the criteria but think you can do the job? We'd love to chat anyway! We're on a mission to build diverse teams, and studies have shown that women and marginalized folks are less likely to apply to jobs if they don't check every box. Other requirements All work must be conducted within the U.S., excluding U.S. territories. Some federal contracts require U.S. citizenship to be eligible for employment. You must be legally authorized to work in the U.S. now and in the future without sponsorship. As a government contractor, you may be required to obtain a public trust or security clearance. You will be required to complete a company background check successfully. Position type This is a full-time, exempt position. Location This is a fully remote position. Care package Salary The salary range for this position is between $170,000 and $240,000. Benefits Your well-being is important to us, so we focus on supporting you in a variety of ways: Medical insurance, dental insurance, vision insurance Short-term and long-term disability insurance Life and AD&D insurance Dependent care FSA, healthcare FSA, health savings account Dollar-for-dollar 401(k) match up to 10% of your salary with no vesting period Flexible paid-time-off policy (generally around 25 days per year), plus 11 paid federal holidays Up to 12 weeks paid-time-off for all eligible new birth, adoption, or foster parents Performance rewards, including annual salary increase, annual performance bonus, spot bonuses, and stock options Business development / sales bonuses Referral bonuses Annual $2,000 allowance for professional development Annual $750 allowance for tech-related purchases Annual swag budget of $100 to display your Skylight pride with some merchandise (hoodies, hats, and more) Dollar-for-dollar charity donation matching, up to $500 per year Flexible, remote-friendly work environment An environment that empowers you to unleash your superpowers for public good Interview tips Visit our join page to learn more about how our interview process works. Check out our Career Pathways framework to learn more about the different roles within Skylight and the skills needed to do them. If you'd like to request reasonable accommodations during the application or interviewing process, please contact our recruiting team at recruiting@skylight.digital. We participate in E-Verify and upon hire, will provide the federal government with your Form I-9 information to confirm that you're authorized to work in the U.S. We are an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, national origin, sex, religion, age, disability, veteran status, or any other category protected by applicable law.
    $170k-240k yearly Auto-Apply 38d ago
  • Chief Clinical Officer

    Covera Health

    Remote job

    About the company At Covera, we're committed to ensuring high-quality healthcare is more than just a promise. That's why we're leading the way in the emerging science of quality, and connecting providers and payers in their shared quest to improve patient outcomes and care quality. By tackling this challenge, we have the ability to impact millions of lives by raising the standard of care nationwide. Our initial focus is radiology, where an early and accurate diagnosis has a profound impact on the rest of a patient's care journey. Through our work, which uses clinically-validated science-based tools, we're helping doctors enhance their care, ensuring patients get the right diagnosis, and enabling the healthcare system to support quality improvement at scale. Through our clinical intelligence platform, we have launched programs that help people access the most effective care and provide doctors with AI-powered quality insights and tools to enhance their care. Today, Covera is partnered with leading employers, payers and healthcare organizations across the US, including Walmart and Microsoft. And, with a pipeline representing over 25% of insured Americans, we are in the early stages of improving care quality for all patients across the globe. About the role The Chief Clinical Officer (CCO) will serve as Covera's senior clinical leader, positioned at the intersection of clinical practice, payer and employer quality programs, and AI product validation. The CCO will ensure the integrity, consistency, and impact of Covera's flagship initiatives, including Guide and Match, the Radiology Centers of Excellence program, and Protect AI, the company's AI oversight and quality assurance platform. This leader will oversee clinical standards and validation of AI findings, guide radiologist partners who review and provide feedback on diagnostic quality, and ensure that Covera's programs deliver measurable value across patients, providers, health plans, employers, and government payers. The CCO will also represent Covera's clinical leadership externally, reinforcing the company's position as the trusted partner in advancing diagnostic quality through AI-enabled innovation. In this role, you will be expected to: Clinical Quality & Standards Oversight Ensure that AI-identified errors and omissions are validated through rigorous clinical review by radiologists engaged with Covera. Oversee onboarding, training, and monitoring of radiologist partners who validate findings and provide structured feedback to participating practices. Implement systems for peer review, interpretive consistency, and ongoing case-based and aggregate feedback. Maintain a limited level of personal reads/validations to reinforce credibility and hands-on expertise. AI Validation & Clinical Integration Lead clinical validation of new AI tools, ensuring they meet standards for diagnostic accuracy, reliability, and patient impact. Partner with product, AI, and data science teams to integrate validated tools into Protect AI and payer/employer-facing programs. Maintain clinical oversight of AI performance in production workflows, ensuring feedback loops to radiologists, practices, and product teams. Clinical Program Leadership (Guide and Match & Protect AI) Provide clinical governance for Guide and Match, ensuring participating practices consistently deliver high-quality diagnostic care. Lead clinical oversight for Protect AI, ensuring AI tools and workflows operate under rigorous quality and safety standards. Develop and oversee reporting frameworks that measure and communicate quality outcomes at both the practice level and across networks. Continuously update clinical guidelines and quality standards to reflect emerging best practices, ensuring continuous improvement across both programs. Cross-Functional Collaboration Represent the clinical perspective in collaboration with product, AI, and operations leaders, influencing roadmap and program design. Work closely with payer and employer partners, ensuring quality measures are aligned with their needs across government, health plan, and employer programs. External Engagement & Market Representation Serve as Covera's clinical ambassador in payer, provider, and employer discussions. Represent Covera's clinical leadership at conferences, regulatory forums, and industry events. Share results and case studies from Guide and Match and Protect AI to highlight Covera's impact on diagnostic quality improvement. Talent & Culture Contribution Play an active role in further building the Covera team by joining interview panels and contributing to cross-company projects after onboarding Requirements: M.D. or D.O. degree with at least 5+ years of clinical experience in radiology. Experience in healthcare innovation (e.g., deploying AI tools) and payer/provider collaboration (not solely clinical practice). Demonstrated leadership in quality oversight, clinical governance, or program development. Experience validating and integrating AI or digital tools in healthcare. Prior start-up or growth-stage company experience is strongly preferred. Familiarity with radiology quality improvement programs (e.g., peer review/peer learning frameworks). Strong communication, collaboration and presentation skills, with ability to bridge clinicians, product/AI teams, payers, and employers. Established credibility within the radiology community and relationships across providers, health systems, or academic centers. Passion for advancing diagnostic quality through clinically rigorous, AI-enabled healthcare innovation AI at Covera Covera uses AI to elevate how we think, build, and execute. Every person on our team is responsible for using AI to accelerate workflows, strengthen communication, and uncover insights that drive better outcomes. AI enables us to focus on the work that creates the most value for our internal teams, partners, and patients, and it supports our mission to improve clinical quality at scale. Benefits Comprehensive medical plans - choose from three plans, including one with 100% of premiums covered for you and your dependents Vision & Dental Flexible Time Off - take the time you need, when you need it Covera Fridays - once a month, Covera takes a fully paid day off to unplug and recharge 401(k) Retirement Plan Annual Professional Development Stipend to invest in courses, books, or any other professional development related activity Annual Wellness stipend for fitness, mental health or other wellness expenses The minimum and maximum base salary for this position ranges from $375,000 - $475,000+, in addition to a discretionary bonus and comprehensive benefits package. Final salary will be based on a number of factors including but not limited to, a candidate's qualifications, skills, competencies, experience, expertise and location. Final compensation decisions may occasionally fall outside of the posted range. Salary ranges are periodically reviewed and may be adjusted in response to market trends and company needs. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, or Veteran status. Equal Opportunity is the Law, and Covera Health is proud to be an equal-opportunity workplace and affirmative action employer. If you have a specific need that requires accommodation, please let a member of the People Team know.
    $119k-173k yearly est. Auto-Apply 16d ago
  • Chief Information Security Officer

    Amalgamated Bank of Ny 4.5company rating

    Remote job

    Job DescriptionAmalgamated Bank seeks a dedicated Chief Information Security Officer to be responsible for designing and implementing the Bank's Information Security program while protecting the business from cyber security threats. This is a hybrid role reporting to our NYC headquarters. By joining our team, you'll be joining a Bank that believes that maintaining a diverse and inclusive workplace where everyone feels valued and respected is essential for us to grow as a company. We are dedicated to building a more equitable world in our everyday practices by embracing the values of our employees and customers. Essential Job Functions: Develop and maintain an Enterprise Information Security Program Design a critical response process for Cyber Security incidents Identify, report and control Cyber Security incidents Manage and train Information Security staff and develop and deliver Information Security training to the Bank's employees Continuously monitor threats to the Bank's operating environment Approve and administer identity access policies Maintain a current understanding of the IT and Cyber Security threat landscape for the industry Ensure Bank compliance with relevant Information Security laws and applicable regulations Lead, and assess the results of periodic security tests, including internal and external penetration testing and phishing Schedule table-top exercises for Crisis Team and senior management and report findings to management, including implementation of recommendations Review and approve Information Security policies, procedures and controls Ensure that they are kept current and are communicated to staff/consultants Ensure staff/vendor compliance with the Bank's security policies and procedures Manage a team of employees, contractors and vendors involved in Information Security Brief the Executive Team on status and risks, overall strategy and necessary budget Communicate best practices and risks to the Bank Perform a risk assessment of the Bank's vulnerabilities in the Cybersecurity landscape and develop the Bank's risk appetite for Information Security Develop Key Risk Indicators (KRIs) and dashboard metrics reporting to both the Management Team and the Board of Directors Establish strong working relationships with the Heads of IT and business lines Develop and present quarterly reports to the Board of Directors. Knowledge, Skills and Experience Requirements: Master's degree or equivalent experience Minimum of ten (10) years of experience, at least five (5) years focused on managing information security in a complex, matrixed environment Extensive experience in regulated industries, especially financial services; banking experience is preferred Proven ability to create and maintain enterprise-level information security programs Motivated individual with strong analytical, problem solving and root cause analysis skills Ability to work on multiple, time-critical projects simultaneously Knowledge of Data Privacy Laws Working knowledge of information security engineering concepts and principles Familiarity with DFS 500 and similar regulations Experience working with external regulators, including NY DFS and FDIC Excellent verbal and written communications, including presentation of complex data in easily, understood ways Ability to confidently interact at multiple levels in the organization and lead cross-departmental team projects Experience presenting to senior levels, including Board of Directors CISSP, CISA or CISM designations preferred Our job titles may span more than one career level. The starting base salary for this role is between $240,000.00 - $260,000.00. The actual base pay is dependent upon many factors, such as: training, transferrable skills, work experience, business needs and market demands. The base pay range is subject to change and may be modified in the future. Amalgamated Bank is an Equal Opportunity and Affirmative Action Employer, Minorities / Females / Individuals with Disability / Veterans. AmeriCorps, Peace Corps and other national service alumni are encouraged to apply. View our Pay Transparency Statement. Submission of a resume or any information regarding your qualifications does not constitute a promise or offer of employment. At Amalgamated Bank, we consider an applicant to be someone who has interviewed at least once, in person, with the hiring manager. Amalgamated Bank does not sponsor applicants for work visas. Hybrid Work Model Effective February 18, 2025, employees in office-based positions will be working a Hybrid work schedule consisting of three days or more, on-site per week, Monday - Thursday, although the specific days may vary by site or organization, with Friday designated as a remote-working day, unless business critical tasks require an on-site presence. This Hybrid work model does not apply to, and daily in-person attendance is required for, the contact center, branch service roles, and general services where the work to be performed is located at a Company site; positions covered by a collective-bargaining agreement (unless the agreement provides for hybrid work); or any other position for which the Company has determined the job requirements cannot be reasonably met working remotely. Please note, this Hybrid work model guidance does not apply to roles that have been designated as “remote”. Search Firm Representatives- Please Read Carefully Amalgamated Bank does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for the position will be deemed the sole property of our company. No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.
    $94k-113k yearly est. 23d ago
  • Senior Information Security Engineer (HYBRID)

    First City Credit Union 3.2company rating

    Remote job

    Job Description The Senior Information Security Engineer will assume, but not be limited to, the following responsibilities: Responsible for designing, managing, and maintaining the credit union's information security systems to ensure member data confidentiality, integrity, and availability Compliance with established security policies, procedures and standards Monitors, manages and analyzes malicious activities daily to ensure the credit union's security infrastructure Assists in the development and maintenance of Information Technology Security Program, including policies, standards, procedures, and security awareness training. Conduct vulnerability scanning and develop prioritized remediation plans Assist internal and external auditors as required The successful candidate will possess the following education, knowledge and skillsets: Undergraduate degree and four (4) years information security related experience; or six (6) plus years of information security related experience Must have one or more of the following industry certifications: ISACA Certified Information Security Manager (CISM) GIAC Information Security Certification Certified Information Systems Security Professional (CISSP) Strong knowledge and experience with IDS/IPS Technologies, Firewall management and maintenance, Anti-Virus / Anti-Malware software, network protocols (BGP, OSPF, etc), SIEM/LEM technology, and etc. Must be a self starter, able to work without constant supervision Strong written and verbal communication skills Strong investigation, remediation, and reporting intuition We provide competitive compensation and benefits package that includes: Health, dental, and vision plans 401(k) plan Life insurance Paid Time Off (PTO) Plan Paid holidays EOE Job Posted by ApplicantPro
    $133k-174k yearly est. 30d ago
  • IT Security Analyst / Manager

    Amerisave Mortgage 4.3company rating

    Remote job

    Description AmeriSave Mortgage has set the standard in online mortgage lending with over $130 billion in funded loan volume. As one of the top-rated, largest privately-owned online mortgage lenders in the nation, our mission is to deliver beneficial, responsible home lending solutions with unwavering integrity, dedication and excellence. Our employees are the driving force behind our success. We believe in the power of a dynamic and talented workforce and creating an environment where your contributions are not just recognized, they're celebrated. Your success is our success, and we are seeking skilled professionals who are ready to bring their A-game, exceed benchmarks and enhance the overall excellence of AmeriSave, while also growing and advancing their careers. At AmeriSave, we're one team with one shared dream - to be the best. Let's redefine excellence together! Role Overview:AmeriSve is seeking an IT Security Analyst/Manager (level dependent on skills and experience). You will be responsible for safeguarding AmeriSave's digital infrastructure by managing IT risk, implementing cybersecurity controls, optimizing secure email gateway configurations, and deploying AI-ready data loss prevention strategies. This role ensures compliance with internal policies and external regulations while supporting secure and efficient business operations. What You'll Do: Cybersecurity Operations Monitor and respond to security incidents across endpoints, networks, and cloud environments. Stay current on emerging threats and recommend proactive defense strategies. IT Risk Management Perform risk assessments for systems, vendors, and AI applications. Document and escalate risk acceptance decisions in alignment with AmeriSave's IT Risk Acceptance Procedure. Collaborate with Compliance and Legal to ensure alignment with GLBA, CCPA/CPRA, and PCI-DSS. Secure Email Gateway (SEG) Administration Manage and tune SEG platforms. Analyze threat reports and enforce email protection policies against phishing, spam, and malware. Coordinate with IT Infrastructure to align SEG and Microsoft Purview DLP configurations. AI-Ready Data Loss Prevention Implement DLP policies that support AI-driven detection and encryption of sensitive data in outbound communications. Evaluate AI systems for data privacy, integrity, and intellectual property leakage risks. Develop incident response playbooks for AI-related security events, including model retraining and anomaly detection. What You'll Need: Bachelor's degree in Information Security or related field. 3+ years of experience in IT security, IT risk management, or third party risk management. Hands-on experience with SEG platforms and DLP tools. Familiarity with AI governance frameworks and anomaly detection tools. Strong understanding of regulatory compliance (GLBA, CCPA/CPRA, PCI-DSS). Preferred Skills: Certifications: CISSP, CISM, GIAC, or equivalent. Experience with AI LLMs for data extraction and security analysis. Knowledge of NIST and SANS Institute cybersecurity frameworks and incident response protocols. **Please note that the compensation information that follows is a good faith estimate for this position only and is provided pursuant to the Colorado Equal Pay for Equal Work Act and Equal Pay Transparency Rules. It is estimated based on what a successful Colorado applicant might be paid. It assumes that the successful candidate will be in Colorado or perform the position from Colorado. Similar positions located outside of Colorado will not necessarily receive the same compensation. ** Compensation: Target annual compensation is $100,000-$160,000 depending on level/experience. Benefits: · 401(k) · Dental insurance · Disability insurance · Employee discounts · Health insurance · Life insurance · Paid time off · 12 paid holidays per year · Paid training · Referral program · Vision insurance Supplemental pay types: · Referral bonuses AmeriSave is an equal opportunity employer. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. California Consumer Privacy Act Disclosure Acknowledgment Employment Applicants, New Hires, and Employees Residing in California AmeriSave Mortgage Corporation's Privacy Policy Statement (“Policy”) can be reviewed here: ******************************** AmeriSave Mortgage Corporation's California Consumer Privacy Act (“CCPA”) Recruitment Disclosure can be reviewed here: ****************************************************** When AmeriSave's Human Resources Department makes future requests for personal information, the same Policy is applicable. By applying, you understand this acknowledgment covers current and future personal information requests. You also acknowledge the business purpose of the personal information collected and that future requests may occur while applying for a position at AmeriSave and/or during employment, if applicable.
    $100k-160k yearly Auto-Apply 48d ago

Learn more about information security director jobs

Browse computer and mathematical jobs