Director, Information Security & Technology
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
About the job
Responsibilities
- Own and evolve the multi-year Information Security and Technology strategy, including priorities, investments, tooling, resourcing, and risk.
- Direct Product and Application Security in partnership with Engineering and Product across architecture, development, and the software development lifecycle.
- Lead and develop managers, senior engineers, and technology professionals.
- Provide strategic leadership across cloud security, vulnerability management, security operations, and incident response.
- Own detection, on-call, escalation, and coordination with the parent-company security function.
- Lead governance, risk, and compliance, including NIST CSF 2.0 assessments, external assessments, risk management, and executive reporting.
- Make risk-based decisions balancing security, product velocity, and business needs.
- Set direction for AI security and governance, including secure AI-tool adoption, AI-enabled product security, and responsible AI usage.
- Oversee internal Technology operations, including identity and access, endpoints, employee technology, and remote-workforce support.
- Serve as the Business Information Security Officer and primary partner to the parent-company CISO and enterprise security organization.
- Lead the cross-functional security steering committee and represent Security and Technology in executive forums.
- Educate and influence the organization on security principles, threats, and practices.
Requirements
- 10+ years of progressive Information Security experience.
- Meaningful people-management experience leading managers, senior technical leaders, or multidisciplinary security teams.
- Broad Information Security leadership experience, with depth in Product and Application Security and experience partnering with software Engineering teams.
- Experience building, scaling, or significantly evolving an Information Security program and translating organizational risk into a multi-year roadmap.
- Experience setting organizational direction and making prioritization, investment, tooling, and resourcing decisions.
- Broad knowledge of cloud security, security operations and incident response, vulnerability management, and GRC.
- Strong security judgment and ability to evaluate technical risk in business context.
- Experience building partnerships across Engineering, Product, Legal, executives, and other cross-functional teams.
- Experience developing technical talent, managing performance, and creating accountability.
- Experience leading or closely partnering with internal IT or Technology Operations, including identity and access, endpoint management, and employee technology.
- Excellent communication skills and executive presence.
Nice to Have
- Experience operating within a matrixed, parent-company, or shared-services security model.
- Experience with AWS and cloud-native software environments.
- Experience with NIST CSF 2.0 or NIST AI RMF.
- Experience with AI security or AI governance.
- Experience securing consumer-facing products, particularly products serving minors, and familiarity with privacy and youth-safety considerations.
- Experience leading distributed or remote-first teams.
Compensation and Benefits
- Annual salary: $220,000–$240,000.
- Unlimited vacation policy.
- Paid volunteer opportunities.
- $4,000 technology stipend every two years after starting.
- $500 annual work-from-home stipend.
- Monthly physical, mental, wellness, learning, and lifestyle stipends.
- Medical, dental, vision, prescription, FSA, HRA, HSA, and dependent coverage.
- Traditional and Roth 401(k) plans with immediate company match.
- Basic life insurance.
Skills
Information Security, Application Security, Cloud Security, Security Operations, Incident Response, Vulnerability Management, GRC, Ai Security, AWS, Nist Csf, Nist Ai Rmf, Identity And Access Management, Endpoint Management, Risk Management
Similar jobs
Security Engineering jobsLeads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.
Leads ID.me’s Product Security program and security engineering team, partnering with Product and Engineering to reduce risk through practical, developer-aligned controls. Requires strong technical depth across application and cloud security, outcome-based leadership, and experience building security programs in fast-moving cloud-native environments.
Leads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.
Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.
Leads technical security, compliance (SOC 2, GDPR, ISO 42001), vulnerability management, and infrastructure hardening for a fast-growing fintech. Requires 3-7 years in security engineering with hands-on AWS, vuln tooling, and audit experience.