Director of Information Security and Technical Operations in New York at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director of Information Security and Technical Operations based in the United States.
This senior leadership role will own the organization’s information security strategy and core technology operations within a highly regulated financial environment. You will shape enterprise-wide security programs, infrastructure, network operations, identity management, and shared technology services. The role combines strategic leadership with hands-on oversight of security, technology risk, compliance, and operational resilience. You will work closely with Product, Engineering, and Data teams to embed security by design across cloud-based platforms and APIs. You will also lead audit readiness, third-party risk management, incident response, and regulatory compliance. This is a high-impact opportunity to strengthen security maturity, operational reliability, and technology governance while supporting continued business growth.
- Develop, own, and continuously improve the enterprise-wide Information Security Program, including security strategy, policies, standards, roadmap, and alignment with business and regulatory requirements.
- Lead day-to-day security operations across cloud and on-premises environments, including network segmentation, firewalls, VPNs, vendor connectivity, threat detection, incident response, vulnerability management, and security monitoring.
- Oversee core technology operations, including IT infrastructure, network administration, endpoint management, identity and access management, and productivity and technology service platforms.
- Own security and technology controls supporting SOC 2 audits, including evidence collection, control operation, remediation planning, and collaboration with external auditors and customer due diligence teams.
- Establish and maintain a risk management framework aligned with NIST and oversee compliance with the FTC Safeguards Rule and NYDFS 23 NYCRR Part 500.
- Serve as the designated Qualified Individual for the FTC Safeguards Rule, coordinating risk assessments, incident response, risk treatment plans, regulatory obligations, and regular reporting to executive leadership and the board.
- Partner with Product, Engineering, and Data teams to integrate security by design, conduct security architecture reviews, and strengthen application and API security.
- Lead third-party and vendor security risk management, including due diligence, contractual security requirements, ongoing monitoring, and exception management.
- Define and monitor security and operational KPIs and KRIs, including incident MTTR, patching SLAs, control coverage, uptime, and availability, and present program updates to senior leadership and the board.
- Manage the information security and technology operations budget, resource planning, tooling strategy, and security training programs designed to support scalable growth.
- Promote a culture of security, operational excellence, accountability, and continuous improvement across the organization.
Requirements:
- Bachelor’s degree in Computer Science, Engineering, Business, or a related field; a master’s degree is preferred.
- At least 8 years of progressive experience across information security and IT operations, including at least 4 years in a senior leadership position such as Director, Senior Director, Head of Security, CISO, or equivalent.
- Experience leading security and technology functions in cloud-centric, SaaS, fintech, or similarly technology-driven environments.
- Strong knowledge of SOC 2 compliance and audit leadership, as well as FTC and NYDFS information security requirements or comparable financial-sector regulations.
- Solid understanding of NIST security frameworks, including NIST CSF and NIST 800-53, with experience translating frameworks into practical security controls and governance programs.
- Demonstrated experience implementing and mapping security controls across hybrid and cloud environments.
- Strong understanding of modern cloud architectures such as AWS, Azure, or GCP, along with DevSecOps, identity and access management, endpoint security, and SIEM/security monitoring technologies.
- Experience with risk management, security architecture, incident response, vulnerability management, third-party risk, and regulatory reporting.
- Relevant certifications such as CISSP, CISM, CISA, CCSP, or equivalent are preferred.
- Familiarity with additional frameworks and regulations such as ISO 27001, PCI DSS, and GLBA is an advantage.
- Strong leadership, communication, collaboration, organizational, and analytical skills, with the ability to manage competing priorities and perform effectively under deadlines and changing business needs.
Benefits:
- Annual salary of $170,000–$200,000.
- Remote work environment for eligible employees residing in approved U.S. states.
- Medical, dental, and vision coverage available from day one.
- Flexible spending options, including HSA and FSA accounts.
- 401(k) plan with company match, with enrollment available from day one.
- Paid time off, sick time, and volunteer time off.
- Paid parental leave options.
- Employer-paid life and disability insurance.
- Wellbeing on Demand program.
- Flexible work environment with a casual dress code.
- Opportunities to contribute to a growing technology and security organization in a regulated financial environment.