Skip to content
FetchFetch

Director of Information Security

Leads Fetch’s end-to-end information security program, including application security, vulnerability management, incident response, architecture, GRC, AI risk, and third-party risk. The role requires 7+ years of security experience, incident command capability, and people leadership.

About the job

Responsibilities

  • Own day-to-day execution of Fetch’s information security function.
  • Lead application security and vulnerability management, including Snyk, CI/CD security gates, repository risk classification, remediation SLAs, bug bounty, and continuous penetration-testing disclosure processes.
  • Serve as incident commander for significant security incidents; coordinate containment, communication, post-incident reviews, root-cause analysis, and systemic remediation.
  • Own security architecture reviews for new systems, cloud platforms, and AI agent deployments.
  • Maintain security standards for cloud infrastructure, endpoint protection, network and edge security, identity, and access governance.
  • Own security policies, the risk register, control framework, audit readiness, evidence collection, and internal and external assessments.
  • Partner with AI governance leadership on acceptable-use enforcement and security risk sign-off for AI platforms, agents, and integrations.
  • Own third-party and vendor security risk assessments.
  • Lead security awareness, phishing simulations, and targeted training.
  • Hire, coach, and develop the Security Engineering team; establish priorities, performance management, growth paths, incident rotations, and technical review standards.
  • Report security maturity, open risks, remediation progress, resourcing gaps, and blockers to executive leadership.

Required Qualifications

  • 7+ years of experience in information security, including application security, incident response, and security architecture.
  • Experience running vulnerability management programs at scale using Snyk or comparable tooling.
  • Direct incident command experience coordinating cross-functional responses to significant security events.
  • People management experience, ideally building or scaling a security engineering team.
  • Working knowledge of cloud security, identity and access management, and modern AI/agent architecture risk.
  • Strong written and verbal communication skills, including executive presentation experience.

Preferred Qualifications

  • Bug bounty or responsible disclosure program management experience.
  • Experience building or maturing GRC programs, including SOC 2 or ISO 27001 audit and compliance frameworks.
  • Familiarity with AI agent security, MCP-style tool and agent architectures, and identity delegation patterns.
  • Experience partnering with AI governance or data governance functions.
  • CISSP, CISM, or equivalent certification.

Skills

Application Security, Vulnerability Management, Snyk, Incident Response, Security Architecture, Cloud Security, Identity And Access Management, Ai Governance, GRC, SOC 2, ISO 27001, Bug Bounty, Penetration Testing, Cissp, Cism

LogicGate

LogicGate

Chicago, IL
Director, Cybersecurity
$190k+/yrOn-site8+ YOESecurity Engineering

Leads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.

GameChanger

GameChanger

United States

Director, Information Security & Technology
$220k+/yrRemote10+ YOESecurity Engineering

Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.

Exa

Exa

San Francisco, CA

Head of Security
$250k+/yrOn-site8+ YOESecurity Engineering

Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.

Chronograph

Chronograph

Brooklyn, NY

Head of Information Security & IT
$215k+/yrOn-site8+ YOESecurity Engineering

Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.

Idme

Idme

Mountain View, CA

Director of Product Security
$244k+/yrOn-site8+ YOESecurity Engineering

Leads ID.me’s Product Security program and security engineering team, partnering with Product and Engineering to reduce risk through practical, developer-aligned controls. Requires strong technical depth across application and cloud security, outcome-based leadership, and experience building security programs in fast-moving cloud-native environments.