Job Description:
We are seeking a strategic and hands-on Information Security Director to lead the planning, execution, and maintenance of enterprise-wide cybersecurity initiatives. This role will be responsible for establishing a comprehensive certification roadmap to align the organization with leading industry standards (e.g., SOC 2, ISO 27001, HITRUST, NIST, and FedRAMP), while continuously monitoring and improving security posture across systems.The ideal candidate brings expertise in information security governance, risk management, audit compliance, and policy development.
You will work cross-functionally with infrastructure, engineering, legal, and compliance teams to protect organizational assets and meet security certification requirements.
Responsibilities:
- Security Certification Strategy & Execution
- Define and lead the roadmap for achieving key security certifications (SOC 2, ISO 27001, HITRUST, NIST 800-53, FedRAMP, etc.).
- Serve as the primary point of contact for external assessors, auditors, and certification bodies.
- Build, document, and maintain policies and procedures to support compliance with certification frameworks.
- Governance, Risk & Compliance (GRC)
- Develop and manage the enterprise-wide security governance program.
- Oversee risk assessments and third-party security reviews.
- Ensure adherence to relevant laws, regulations, and standards (e.g., HIPAA, GDPR, CCPA).
- Enterprise Security Operations
- Direct the design and implementation of cybersecurity controls, including network security, endpoint protection, identity management, and data loss prevention.
- Coordinate incident response planning and lead incident management efforts.
- Evaluate emerging threats and maintain security awareness across the organization.
- Team Leadership & Cross-Departmental Collaboration
- Build and lead a high-performing security team to execute on compliance and operational security goals.
- Collaborate with engineering, DevOps, and IT to embed security throughout development and infrastructure lifecycles.
- Provide executive-level updates and board presentations on security status and risks.
- Continuous Improvement & Audit Readiness
- Conduct regular internal audits and gap analyses to prepare for formal assessments.
- Manage vendor security assessments and monitor contractual compliance.
- Drive process automation to streamline certification and reporting workflows.
Qualifications
- 10+ years of progressive experience in cybersecurity, information security, or related fields.
- Demonstrated success in leading organizations through one or more formal security certifications (e.g., ISO 27001, SOC 2, HITRUST, etc.).
- Strong knowledge of cybersecurity frameworks (NIST, CIS, ISO, etc.) and regulatory standards (HIPAA, GDPR, FedRAMP).
- Proficiency in security tools and technologies (SIEM, IAM, DLP, vulnerability scanning).
- Strong leadership, communication, and stakeholder management skills.
Preferred Qualifications
- Industry certifications such as CISSP, CISM, CISA, CRISC, or PMP.
- Experience in healthcare, government, or highly regulated industries.
- Familiarity with DevSecOps principles and cloud-native security controls (AWS, Azure, GCP).
- Background in security architecture or engineering.