Director of Security
Leads security team to build strategy, scale operations, and ensure compliance for AI-powered SaaS serving sensitive research data. Partners with engineering/product on secure development and fosters company-wide security culture. Requires 7+ years leadership in fast-growing SaaS.
About the job
Responsibilities
- Partner with engineering to evolve secure software development using AI coding tools and secure customer-facing products.
- Maintain and advance security and compliance posture; evaluate certifications like SOC 2, ISO 27001.
- Scale security function through automation.
- Lead security operations: auditing, internal documentation, incident response, company-wide security awareness.
- Own security narrative for enterprise customers, including Trust Center, documentation, and reviews.
- Instill security culture across the company and integrate into processes and decision making.
Requirements
- 7+ years in security leadership, including building or scaling a security program at a fast-growing SaaS company.
- Deep experience with SOC 2, ISO 27001, and similar compliance certifications.
- Understanding of appsec, AI product, and AI software development security risks and mitigation.
- Preference for automation over manual scaling.
- Track record partnering with product and engineering teams in governance/oversight model.
- Experience with enterprise security requirements in regulated or research-intensive industries.
- Excellent at organizational change and gaining buy-in across teams.
Skills
SOC 2, ISO 27001, Appsec, Ai Security, Incident Response, Security Automation, Compliance, Secure Software Development, Security Governance, Trust Center
Similar jobs
Security Engineering jobsLeads LogicGate’s internal security organization, compliance posture, risk management, and customer trust program while serving as Deputy CISO. Requires 7–10 years of information security experience, substantial people leadership, SaaS compliance expertise, and strong technical knowledge of modern security architectures.
Leads GameChanger’s Information Security and Technology strategy, teams, roadmap, and risk decisions, with primary focus on product and application security. Requires 10+ years of security experience, broad security-program leadership, and experience managing technical leaders and partnering with Engineering and executives.
Leads Exa’s company-wide security strategy, architecture, engineering, governance, incident response, and team development across AI infrastructure, cloud, products, and corporate systems. Requires executive-level security accountability and deep technical credibility in a rapidly scaling technology company.
Leads Fetch’s end-to-end information security program, including application security, vulnerability management, incident response, architecture, GRC, AI risk, and third-party risk. The role requires 7+ years of security experience, incident command capability, and people leadership.
Leads Chronograph’s information security and IT strategy, combining executive leadership with hands-on oversight of cloud, application, AI, corporate, and compliance security. Requires at least seven years of security experience, broad technical depth, assurance-program leadership, and strong executive communication.