This is a remote position.
Key Responsibilities
Cybersecurity Leadership
-
Own the organization's overall security posture, including threat detection, incident response, vulnerability management, and endpoint/identity protection.
-
Direct security monitoring and incident investigation (e.g., EDR/SIEM alert triage, threat hunting, and formal incident reporting) and lead response to active threats.
-
Define and maintain security architecture standards across cloud (Azure, GCP), including network segmentation, firewall/NGFW policy, and Zero Trust Network Access (ZTNA).
-
Establish and enforce security policies covering access control, data protection, endpoint management, and acceptable use.
Team Leadership
-
Build, lead, and develop the information security team, including hiring, coaching, performance management, and succession planning.
-
Set clear priorities, objectives, and accountability structures for security architects, analysts, IAM/GRC leads, and other direct reports.
-
Foster a collaborative, high-performing team culture and support ongoing professional development and certification.
-
Manage team workload and resources to ensure adequate coverage for monitoring, incident response, and project delivery.
Security Strategy, Design & Implementation
-
Define and own the organization’s security architecture and strategy.
-
Lead the design and implementation of security controls for networks, endpoints, applications, and cloud workloads, including secure-by-design reviews for new projects and technologies.
-
Set technical standards for security tooling selection, deployment, and integration, ensuring coverage across the full technology stack.
-
Evaluate emerging threats and technologies, adjusting the security roadmap to address new attack surfaces (cloud, AI, remote work, etc.).
Security Incident Management
-
Own the security incident response program end-to-end: detection, triage, containment, eradication, recovery, and post-incident review.
-
Establish and maintain the incident response plan, playbooks, and escalation procedures, and lead the response to major security incidents and breaches.
-
Coordinate with legal, communications, and executive leadership on breach notification obligations and external disclosure requirements.
-
Drive continuous improvement of detection and response capabilities based on lessons learned, tabletop exercises, and threat intelligence.
Security Policies & Governance
-
Develop, maintain, and enforce organization information security policies, standards, and procedures (access control, acceptable use, data classification, incident response, vendor security, etc.).
-
Ensure policies remain aligned with applicable regulatory and contractual requirements and are reviewed on a regular cadence.
-
Establish governance structures (security steering committee, policy exception processes) to ensure accountable, auditable decision-making.
-
Represent security in client, partner, and regulatory due-diligence engagements, including security questionnaires and audits.
-
Act as the primary liaison with internal and external auditors, coordinating audit scope, evidence collection, and remediation of findings across security and compliance audits.
Risk Management
-
Own the organization security risk management program, including risk identification, assessment, treatment, and reporting.
-
Maintain the organization's risk register and ensure risk treatment plans have clear ownership, timelines, and executive visibility.
-
Report on the organization's security risk posture to executive leadership and the board on a regular basis, using clear, business-relevant metrics.
Security Budget & Resource Management
-
Own and manage the organization security budget, including forecasting, prioritization, and return-on-investment analysis for security initiatives.
-
Build the business case for security investments, balancing risk reduction against cost and operational impact.
Skills Required
- Lead information security program and set security strategy and architecture
- Direct incident response, SIEM/SOC operations, threat hunting, and EDR investigations
- Design and enforce security controls across cloud environments (Azure, GCP)
- Define and maintain network security including NGFW, segmentation, and ZTNA
- Own identity and access management, data protection, and endpoint protection programs
- Manage security risk program, risk register, and executive/board reporting
- Build and lead security team, including hiring, coaching, and succession planning
- Own security budget, ROI analysis, and business case for security investments
- Manage audits, vendor security assessments, and regulatory due diligence







