Company Overview
[$COMPANY_OVERVIEW]
Role Overview
We are looking for a highly experienced Director of Security to lead our security initiatives at [$COMPANY_NAME]. In this strategic role, you will be responsible for defining and implementing security policies, standards, and procedures to safeguard our information assets and technology infrastructure. You will work closely with cross-functional teams to ensure compliance with regulatory requirements and to foster a culture of security awareness throughout the organization.
Responsibilities
- Develop and execute a comprehensive security strategy aligned with business objectives and risk management frameworks.
- Lead the security team in identifying, assessing, and mitigating security risks associated with technology and operational processes.
- Oversee the implementation of security controls, including network security, application security, and endpoint protection, ensuring a robust defense posture.
- Conduct regular security assessments, audits, and penetration testing to evaluate the effectiveness of security measures and identify vulnerabilities.
- Collaborate with IT and engineering teams to integrate security best practices into the software development lifecycle (SDLC) and IT operations.
- Advise senior management on security-related risks and recommend appropriate measures to optimize security investments.
- Foster a culture of security awareness through training and communication initiatives across the organization.
- Stay current with emerging security threats and industry trends to continuously enhance security policies and practices.
Required and Preferred Qualifications
Required:
- 10+ years of experience in cybersecurity or information security roles, with 5+ years in a leadership position.
- Proven expertise in security frameworks (e.g., NIST, ISO 27001) and regulatory compliance (e.g., GDPR, HIPAA).
- Deep knowledge of security technologies, including firewalls, intrusion detection/prevention systems, SIEM, and identity/access management.
- Experience in incident response and crisis management, with a track record of leading investigations and remediations.
- Strong analytical and problem-solving skills, with the ability to communicate complex security concepts to non-technical stakeholders.
Preferred:
- Relevant certifications such as CISSP, CISM, or CISA.
- Experience with cloud security (AWS, Azure, GCP) and securing DevOps environments.
- Strong project management skills and experience with agile methodologies.
Technical Skills and Relevant Technologies
- Expertise in cybersecurity tools and technologies including vulnerability management, threat intelligence, and endpoint detection and response (EDR).
- Familiarity with programming/scripting languages (e.g., Python, PowerShell) to automate security processes.
- Understanding of network architecture and protocols, as well as secure coding practices.
Soft Skills and Cultural Fit
- Strong leadership and team management skills, with a focus on building and developing high-performing security teams.
- Excellent communication and interpersonal skills, capable of working with diverse teams and stakeholders.
- Proactive approach to problem-solving and the ability to thrive in a fast-paced, dynamic environment.
- Commitment to promoting a culture of trust, integrity, and collaboration.
Benefits and Perks
Annual salary range: [$SALARY_RANGE]
At [$COMPANY_NAME], we offer a comprehensive benefits package that includes:
- Health, dental, and vision insurance
- Retirement savings plan with employer matching
- Generous paid time off policy
- Professional development opportunities and training
- Flexible work arrangements to support work-life balance
Equal Opportunity Statement
[$COMPANY_NAME] is committed to fostering a diverse and inclusive workplace. We are proud to be an Equal Opportunity Employer and will consider all qualified applicants without regard to race, color, religion, sex, national origin, disability, veteran status, or any other protected characteristic.
Location
This role is hybrid, requiring candidates to work from the office at least 3 days a week in [$COMPANY_LOCATION].
