Employment Type: Full-Time
Reports To: Chief Operating Officer (COO)
Our client is seeking a hands-on, strategic, and operationally strong Director of Information Security & Data Privacy to lead and mature the organization's cybersecurity, information security, data privacy, governance, risk, and compliance programs.
This leader will be responsible for protecting the organization's information assets, maintaining customer trust, ensuring compliance with regulatory and industry standards, and enabling secure business growth within a fast-paced, high-growth SaaS environment.
The ideal candidate combines deep technical security expertise with proven leadership experience and a pragmatic, hands-on approach. This role requires someone who can set strategy while remaining actively engaged in day-to-day security, privacy, risk, and compliance initiatives.
Reporting to the Chief Operating Officer (COO), this individual will lead the organization's Information Security, Data Privacy, Governance, Risk, and Compliance (GRC) functions while partnering closely with IT Operations, Product, Engineering, Legal, HR, and executive leadership.
- Develop, implement, and continuously improve the organization's Information Security strategy, roadmap, and overall security posture.
- Lead and oversee security operations across:
- Identity and Access Management (IAM)
- Endpoint security
- Vulnerability management
- Threat detection and monitoring
- Incident response
- Security operations and continuous improvement
- Partner closely with Product and Engineering teams to integrate security into cloud infrastructure, applications, and the software development lifecycle.
- Develop, maintain, and enhance security policies, standards, procedures, and technical controls aligned with industry best practices.
- Lead the organization's security awareness and education program.
- Support customer, partner, and enterprise security assessments and due diligence activities.
- Manage vendor security reviews, third-party risk assessments, customer security questionnaires, and remediation activities.
- Remain hands-on and actively involved in security operations, investigations, risk remediation, and technical decision-making when needed.
- Own and continuously evolve the organization's Data Privacy and Governance program .
- Ensure ongoing compliance with applicable regulations, certifications, and frameworks, including:
- ISO 27001
- SOC 2
- GDPR
- CCPA and applicable U.S. state privacy requirements
- Other applicable privacy and security regulations
- Lead internal and external security and compliance audits and maintain ongoing certification programs.
- Partner with IT Operations, Legal, HR, Product, Engineering, and business leaders to operationalize security and privacy requirements.
- Develop, maintain, and govern privacy policies, standards, procedures, controls, and compliance documentation.
- Monitor evolving privacy regulations and security requirements and recommend appropriate organizational and technical changes.
- Help ensure privacy considerations are incorporated into business processes, technology decisions, products, and customer-facing initiatives.
- Lead enterprise cybersecurity and technology risk assessments and ongoing risk management activities.
- Develop and maintain security metrics, KPIs, dashboards, and executive-level reporting.
- Regularly communicate security posture, compliance status, vulnerabilities, and enterprise risks to executive leadership.
- Lead third-party risk management and vendor security governance.
- Evaluate emerging cybersecurity threats, technologies, and AI-related risks.
- Establish scalable governance processes that support secure business growth while balancing operational efficiency.
- Drive remediation efforts and ensure identified security, privacy, audit, and compliance risks are appropriately addressed.
- Serve as the organization's trusted advisor on cybersecurity, information security, data privacy, compliance, and technology risk.
- Build strong partnerships across Product, Engineering, IT Operations, Legal, HR, and other business functions.
- Lead, mentor, and develop a high-performing Information Security and Data Privacy team.
- Build scalable security, governance, privacy, and compliance processes appropriate for a rapidly growing SaaS organization.
- Balance strategic planning with hands-on execution, remaining actively engaged in operational priorities when needed.
- Translate complex cybersecurity and privacy risks into clear business recommendations for executive and non-technical stakeholders.
- Foster a collaborative, pragmatic, and solutions-oriented culture that enables business innovation while appropriately managing risk.
- Hands-on leader who combines strategic vision with strong operational execution.
- Strong communicator capable of influencing executive leadership, technical teams, and non-technical stakeholders.
- Collaborative leader who builds trusted partnerships across the organization.
- Calm, decisive, and effective during security incidents and other high-pressure situations.
- Strong analytical, organizational, and problem-solving skills.
- Pragmatic approach to security and privacy that balances risk management with business objectives.
- Passion for building scalable, secure, and efficient processes that enable business growth.
- Committed to mentoring and developing high-performing teams.
- 10+ years of progressive experience across Information Security, Cybersecurity, Data Privacy, and related disciplines.
- 5+ years of Director-level or comparable senior leadership responsibility.
- Proven experience leading Information Security and Data Privacy programs within a fast-paced SaaS, software, technology, or cloud-native organization .
- Strong hands-on technical expertise across:
- Cloud security, particularly AWS and/or Azure
- Identity and Access Management (IAM)
- Security operations
- Vulnerability management
- Endpoint security
- Security monitoring and incident response
- Demonstrated experience owning or materially leading Data Privacy programs , including GDPR, CCPA, and/or other U.S. state privacy requirements.
- Proven success achieving, maintaining, and continuously improving ISO 27001, SOC 2 , and similar security/compliance programs.
- Deep knowledge of cybersecurity frameworks, enterprise risk management, privacy regulations, and security best practices.
- Experience implementing and managing modern security technologies within cloud-based environments.
- Demonstrated success building, mentoring, and leading high-performing technical teams.
- Strong project management, organizational, communication, and cross-functional leadership skills.
- Ability to operate effectively at both the strategic and tactical levels.
- CISSP, CISM, CRISC, or comparable industry certification.
- Experience supporting hybrid and remote work environments.
- Experience collaborating with Product and Engineering organizations to embed security into cloud-native application development and the SDLC.
- Familiarity with modern SaaS technology ecosystems and cloud security platforms.
- Experience supporting mergers and acquisitions, organizational scaling, or rapid business growth.
- Experience developing security and governance frameworks for emerging technologies, including AI.
- Experience supporting enterprise customers and responding to sophisticated customer security, privacy, and compliance requirements.
- Opportunity to shape and mature the organization's Information Security, Data Privacy, and Governance programs within a growing SaaS environment.
- High-impact leadership role with visibility across executive leadership and the broader organization.
- Opportunity to work closely with Product, Engineering, IT Operations, Legal, HR, and business leadership.
- Collaborative, fast-moving environment focused on innovation, customer trust, and operational excellence.
- Opportunity to build and lead a modern, scalable cybersecurity, privacy, risk, and compliance organization that directly enables business growth.