Director of InfoSec & Data Privacy

PKR

  • Pennsylvania
  • 8 days ago

    Highlights

    You communicate clearly, build strong cross-functional partnerships, stay composed under pressure, and develop practical security programs that support the business. Lead security operations across identity and access management, endpoint security, vulnerability management, threat detection, monitoring, and incident response.

    Numbers & Facts

    LocationPennsylvania

    Description

    Who Our Client Is
    Our client is a growing SaaS organization focused on innovation, customer trust, and secure business growth. They value collaboration, practical problem-solving, and scalable operations.

    What Our Client Needs
    Our client is seeking a Director of Information Security & Data Privacy to lead and mature its cybersecurity, information security, data privacy, governance, risk, and compliance programs. This hands-on leader will protect information assets, strengthen customer trust, support regulatory compliance, and enable secure growth.

    Who You Are
    You are a strategic and hands-on security leader who can move between executive-level planning and operational execution. You communicate clearly, build strong cross-functional partnerships, stay composed under pressure, and develop practical security programs that support the business.

    What You’ll Do

    • Develop and continuously improve the information security strategy, roadmap, and overall security posture
    • Lead security operations across identity and access management, endpoint security, vulnerability management, threat detection, monitoring, and incident response
    • Partner with Product and Engineering to embed security into cloud infrastructure, applications, and the software development lifecycle
    • Develop and maintain security policies, standards, procedures, and technical controls
    • Lead security awareness and education programs
    • Manage customer security assessments, vendor reviews, third-party risk assessments, security questionnaires, and remediation activities
    • Own and evolve the data privacy and governance program
    • Maintain compliance with ISO 27001, SOC 2, GDPR, CCPA, and other applicable privacy and security requirements
    • Lead internal and external audits and ongoing certification activities
    • Conduct cybersecurity risk assessments and oversee enterprise risk management activities
    • Develop security metrics, KPIs, dashboards, and executive reporting
    • Evaluate emerging technologies, cybersecurity threats, and AI-related risks
    • Advise executive leadership on cybersecurity, privacy, compliance, and technology risk
    • Lead, mentor, and develop the Information Security and Data Privacy team
    • Build scalable security, governance, and compliance processes that support continued growth

    This role includes supervisory responsibility for the Information Security and Data Privacy team. Travel requirements were not specified.

    What You’ll Need

    • 10+ years of progressive experience in Information Security, Cybersecurity, and Data Privacy leadership
    • 5+ years of director-level or senior leadership responsibility
    • Experience leading Information Security and Data Privacy programs in a fast-paced, high-growth SaaS or cloud-native organization
    • Hands-on expertise in cloud security, including AWS and/or Azure
    • Strong experience with identity and access management, security operations, vulnerability management, endpoint security, monitoring, and incident response
    • Demonstrated success building, mentoring, and leading high-performing technical teams
    • Deep knowledge of cybersecurity frameworks, risk management, privacy regulations, and security best practices
    • Experience achieving, maintaining, and improving ISO 27001, SOC 2, or similar compliance and certification programs
    • Experience implementing and managing modern security technologies in cloud-based environments
    • Strong project management, organizational, communication, and cross-functional leadership skills
    • Experience supporting hybrid or remote environments and cloud-native application development preferred
    • Familiarity with modern SaaS technology ecosystems and cloud security platforms preferred
    • CISSP, CISM, CRISC, or comparable industry certification preferred
    • Experience supporting mergers and acquisitions, organizational scaling, rapid growth, or governance for emerging technologies such as AI preferred

    What They Offer
    Great work starts with an environment where people can thrive, grow, and do meaningful work. Their benefits and employee experience are designed to support you both professionally and personally.

    • Compensation range of $175,000 to $185,000, with $20,000 bonus potential.
    • Time to recharge: Paid time off including vacation, sick time, company holidays, and floating holidays
    • Work-from-home flexibility: The flexibility and convenience of remote work
    • Health care support: Company contribution toward the cost of individual health care premiums
    • Plan for your future: Opportunity to participate in a company-sponsored 401(k)
    • Keep learning: Access to training, education, and ongoing professional development
    • Invest in your growth: Access to a third-party professional coach for every employee
    • Continue your education: Tuition reimbursement opportunities to support continued learning
    • Do work that matters: Be part of a purpose-driven organization committed to using business as a force for good as a Certified B Corporation

    The benefits go beyond the basics. You’ll have the flexibility, resources, and development opportunities to build your career while contributing to a purpose-driven organization focused on making the workplace better.

    Equal Opportunity Statement
    Our client believes that diversity fuels innovation, strengthens teams, and drives success. They are committed to fostering a workplace where every individual—regardless of background—feels valued, respected, and empowered to thrive. Discrimination or harassment of any kind is strictly prohibited.

    Our client does not discriminate based on race, color, religion, sex, sexual orientation, gender identity or expression, national origin, ethnicity, age, disability, veteran status, marital status, or any other characteristic protected by applicable laws. Their commitment extends beyond compliance; they actively cultivate an inclusive culture where diverse perspectives are welcomed, and every employee has an equal opportunity to contribute and succeed.

    Similar Jobs

    See more jobs