Director of Information Security
Director, Information Security (Compliance, Data Security, Privacy & Risk)
About the role
We're hiring a Director of Information Security to lead our governance, data protection, privacy, and risk functions. This is a senior leadership role responsible for the programs that demonstrate we handle data responsibly — to customers, regulators, and the board. You'll own our compliance certifications, data security strategy, privacy program, and enterprise risk management, and you'll build and lead the team that runs them.
You'll operate as both a strategic leader and a program builder: setting direction, hiring and growing a team, and partnering across engineering, legal, product, and the executive team to make security and privacy a durable business advantage rather than a checkbox.
What you'll do
Own and mature our compliance program end to end, including frameworks such as SOC 2, ISO 27001, and others relevant to our customers and markets, and lead audits to successful outcomes.
Set data security strategy: data classification, access governance, encryption standards, DLP, and controls that protect sensitive and customer data across its lifecycle.
Build and run the privacy program, ensuring compliance with regulations such as GDPR and CCPA/CPRA, and partner with legal on data processing, DPAs, and privacy-by-design.
Establish and operate an enterprise risk management program: risk identification, assessment, treatment, and reporting to leadership and the board.
Own the third-party/vendor risk and customer trust functions, including security questionnaires, customer assurance, and the trust center.
Develop, maintain, and enforce security policies, standards, and control frameworks, and drive continuous controls monitoring.
Hire, lead, and grow a high-performing team spanning GRC, privacy, and risk.
Serve as a trusted advisor to executives and report regularly on security, privacy, and risk posture.
What we're looking for
Extensive experience in information security, GRC, privacy, or risk, including several years leading and building teams (typically 10+ years total, with meaningful management experience).
Proven track record owning compliance certifications (SOC 2, ISO 27001, or equivalent) and leading audits to completion.
Deep knowledge of data protection and privacy regulations (GDPR, CCPA/CPRA) and how to operationalize them.
Strong grounding in risk management frameworks and enterprise risk programs.
Excellent executive communication — able to translate risk into business terms for leadership and the board.
Experience partnering across engineering, legal, product, and sales in a fast-moving environment.
Nice to have
Relevant certifications (CISSP, CIPP, CISM, CRISC, or similar).
Experience scaling a compliance/privacy program through significant company growth.
Familiarity with continuous compliance tooling and controls automation.
Background supporting enterprise sales and customer security reviews.
What success looks like
Within your first year, you'll have a clear-eyed view of our risk landscape, a maturing set of compliance and privacy programs, a team positioned to scale, and executive confidence in our security and privacy posture.
Salary: $240k
Values