Director of Security – GRC

Job not on LinkedIn

🕒 May 1

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Censys

Censys

51 - 200 employees

Founded 2017

🔒 Cybersecurity

🏢 Enterprise

Cybersecurity • Enterprise • Data

Censys is a leading Internet Intelligence Platform that specializes in Threat Hunting and Attack Surface Management. It provides security teams with a comprehensive, accurate, and up-to-date map of the internet to defend against attacks and hunt for threats. Censys offers solutions for Cloud Asset Discovery, Exposure and Risk Management, and External Attack Surface Management. Its proprietary Internet Map delivers detailed insights and extensive internet scanning capabilities, allowing organizations to continuously monitor internal and external attack surfaces. Founded by the creators of ZMap at the University of Michigan, Censys is deeply rooted in the security open source community and boasts a large internet intelligence community. Censys empowers organizations, including those in financial services, government, and healthcare, to act swiftly against evolving threats and protect their internet-facing assets effectively.

📋 Description

• Own, build, and scale the team and systems for Censys’ corporate security infrastructure • Own company security needs from endpoint provisioning to deploying tools that improve our overall security posture while keeping things simple for all employees • Manage the Security team; delegate day-to-day workloads and ensure coverage of critical functions during PTO to maintain a high SLA • Own the complete endpoint lifecycle including provisioning, application deployment, security controls, and asset retirement • Work closely with internal teams to enforce compliance across endpoints and help users understand how security policies impact their daily work • Manage and secure cloud environments and coordinate security configuration of software and tools • Develop and deliver Security Awareness Training to internal users • Collect and create documentation for security processes and build out a knowledge base for the team • Design, implement, and manage the company’s Data Loss Prevention (DLP) program, including policies, tooling, and enforcement across endpoints, cloud, and email • Own and operate the insider threat program, including behavioral monitoring, investigation workflows, and coordination with Legal, HR, and senior leadership as required • Partner with engineering and infrastructure teams to ensure security telemetry and logging coverage meets both operational and compliance requirements • Lead the development and implementation of Censys’ compliance strategy to achieve and maintain compliance with ISO 27001, SOC 2 Type 2, UK NCSC Cyber Essentials+, and CMMC, in partnership with the Security and Operations teams • Develop, review, and update organizational policies and procedures to align with compliance and governance requirements • Oversee timely responses to security questionnaires and other sales requests relating to organizational and product security and privacy • Validate and respond to inbound legal process as required by federal law • Assist in the procurement process to review proposed purchases for security and privacy concerns • Manage control and process libraries • Conduct ongoing risk assessments • Other duties as assigned

🎯 Requirements

• 10+ years of progressive experience in cybersecurity, with at least 3 years in a senior leadership or Director-level role • Demonstrated experience owning and operating enterprise security programs including DLP, insider threat, and detection and response • Deep familiarity with compliance frameworks including ISO 27001, SOC 2 Type 2, CMMC, NIST, and GDPR • Experience building and managing security telemetry, SIEM, and detection engineering programs • Strong understanding of cloud security (AWS, GCP, or Azure), endpoint security, and identity and access management • Proven ability to lead, mentor, and grow a high-performing security team • Excellent written and verbal communication skills, with the ability to convey complex security concepts to executive leadership, legal, and non-technical stakeholders • Experience managing security incident response, including coordination across Legal, HR, and executive leadership • Background in security program development within a high-growth or scale-up environment.

🏖️ Benefits

• 401k match • health • vision • dental • and more!

Apply Now

Similar Jobs

🕒 May 1

Sony Interactive Entertainment

10,000+ employees

🎮 Gaming

🔧 Hardware

📡 Telecommunications

Staff Cloud Security Engineer focusing on cloud and AI security architecture for PlayStation. Leading security initiatives across multi-cloud environments and AI systems.

AWS

Azure

Cloud

Docker

Google Cloud Platform

Kubernetes

🕒 May 1

Greenhouse Software

501 - 1000

☁️ SaaS

👥 HR Tech

🏢 Enterprise

Head of Security managing complex financial security across NEAR Intents and NEAR One at Defuse Labs. Ensuring comprehensive security in crypto-native environments against diverse threats.

Terraform

🕒 May 1

Calix

1001 - 5000

📡 Telecommunications

☁️ SaaS

🏢 Enterprise

Staff Cloud Security Engineer leading secure infrastructure development for Calix’s AI-powered platform. Collaborating with cross-functional teams to strengthen cloud security and mentoring junior engineers.

Cloud

Distributed Systems

Google Cloud Platform

Microservices

Terraform

🕒 May 1

Hitachi

10,000+ employees

🤖 Artificial Intelligence

⚡ Energy

🚗 Transport

Master Security Architect at Hitachi Vantara ensuring compliance with US Government security standards. Collaborating with engineering teams to deliver hardened security solutions while adhering to best practices.

AWS

Azure

Cyber Security

Google Cloud Platform

Linux

SQL

VMware

🕒 April 30

Cherry

201 - 500

💳 Fintech

🤝 B2B

Product Security Engineer embedding in engineering team at a FinTech, securing products from development to deployment. Monitoring threats and educating engineers on security principles.

AWS

Cloud

SDLC