Director of Information Security and Operations

🕒 il y a 1 mois

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

👻 Score fantôme 22%

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of jrni

jrni

51 - 200 employés

Fondée en 2008

☁️ SaaS

🤝 B2B

🏢 Entreprise

💰 €6 000 000 Series C - JRNI en 2019-08

SaaS • B2B • Enterprise

jrni est un fournisseur de logiciels basés sur le cloud pour la programmation de rendez-vous et l'engagement client. La plateforme aide les entreprises à gérer les réservations, rendez-vous, files d'attente virtuelles et expériences client en magasin ou à distance sur plusieurs canaux, permettant aux détaillants et fournisseurs de services de proposer la réservation en ligne, l'ordonnancement et l'orchestration du parcours client. jrni cible d'autres entreprises avec un produit SaaS axé sur l'amélioration des opérations et de l'expérience client.

Description

• Set the direction for jrni's Information Security program against ISO 27001 and SOC 2 • Own and improve operational controls satisfying ISO 27001, SOC 2, GDPR, and other frameworks • Own JRNI's AI security policy and governance standards (aligned with NIST AI RMF and ISO 42001) • Lead AI Operations — using AI to improve efficiency while governing AI systems for privacy and security risk • Partner with Legal and external auditors on audits, evidence collection, and certification renewals • Build and support a culture of security awareness, data protection, and compliance, including training • Manage and optimize production cloud infrastructure for scalability, reliability, and compliance • Partner with Engineering / SRE on CI/CD, release management, and production stability • Oversee monitoring, alerting, and observability to resolve issues proactively • Implement and test disaster recovery and business continuity plans • Lead vulnerability management, patching, and hardening across the estate • Own security and operational incident response plans; run tabletop exercises • Serve as incident commander for Sev-1/Sev-2 events, coordinating with customers, Legal, and execs • Lead blameless post-incident reviews and track remediation to closure • Maintain a risk register and lead periodic enterprise risk assessments • Own third-party / vendor risk management — vendor reviews, DPAs, sub-processor oversight • Oversee IAM across corporate (SSO, MFA, SCIM) and production (least-privilege, JIT access, break-glass), with access reviews and joiner/mover/leaver processes • Manage JRNI's cyber insurance relationship and renewals • Improve processes for productivity, scalability, and audit readiness • Use automation to streamline workflows and strengthen compliance reporting • Develop and manage the operational budget across people, technology, and vendors • Work with Customer Success to ensure service delivery and operational excellence • Build, mentor, and retain effective, engaged InfoSec and TechOps teams • Define clear career paths, performance objectives, and development plans • Foster a blameless, learning-oriented culture • Collaborate across Sales, Customer Success, Product, and Engineering • Own responses to customer security questionnaires (SIG, CAIQ), RFPs, and audit requests; maintain a customer-facing trust center • Act as security executive sponsor in enterprise sales cycles • Partner with Legal and Product on data residency, classification, retention/deletion, and DSAR fulfillment • Establish KPIs (uptime, MTTD/MTTR, audit closure, remediation SLAs, CSAT) and report to execs and the Board

🎯 Exigences

• Significant experience in Information Security and/or IT Operations, including leading multiple teams • Leading SOC 2 Type II and ISO 27001 audits end-to-end • Operating production SaaS infrastructure at scale on AWS and GCP; strong cloud/network/app security and DevSecOps • Hands-on with SIEM, EDR, vulnerability scanners, and CSPM platforms • Leading incident response in production SaaS • Strong, clear executive communication — comfortable with the Board, customers, and auditors • Bachelor's in CS, Engineering, or related field — or equivalent professional experience • CISSP, CISM, CISA, AWS Security Specialty, or ISO 27001 Lead Auditor/Implementer are nice to have • HIPAA, PCI-DSS, or FedRAMP experience are nice to have • AI/ML governance (NIST AI RMF, ISO 42001) and securing AI-enabled products are nice to have • Defining and operating customer-facing trust programs are nice to have

🏖️ Avantages

• Professional development opportunities • Flexible work arrangements

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Curative

501 - 1000

🏥 Santé

🛡️ Assurance

Principal Security Engineer leading security engineering function for Curative's infrastructure, applications, and AI systems with a strong emphasis on building secure designs.

🇺🇸 États-Unis – Télétravail

💵 $175 000 - $200 000 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Gainwell Technologies

10 000+ employés

💼 Conseil

📦 Logistique

⚕️ Assurance santé

Information Security Officer responsible for security compliance and client delivery in healthcare. Collaborating with leadership to identify security issues and manage risks.

🇺🇸 États-Unis – Télétravail

💵 $90 900 - $129 900 / an

💰 Grant en 2023-06

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Highmark Health

10 000+ employés

🛡️ Assurance

💼 Conseil

📦 Logistique

Manager Information Security & Risk Management at Highmark Health ensuring alignment with security needs and managing personnel activities. Overseeing technology products and contributing to strategic planning efforts.

🇺🇸 États-Unis – Télétravail

💵 $129 100 - $214 500 / an

💰 €5 000 000 Grant en 2021-05

⏰ Temps Plein

🟠 Senior

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security

🕒 il y a 1 mois

EZCORP

5001 - 10000

🛒 Commerce de détail

👥 B2C

Director of Cyber Security at EZCORP responsible for enterprise security vision and measures. Leading strategies to safeguard sensitive information and manage security operations.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Cyber Security

🕒 il y a 1 mois

Banner Bank

1001 - 5000

🏦 Banque

💸 Finance

💳 Fintech

Principal AI & Cloud Security Engineer shaping secure AI adoption and Azure cloud strategies at Banner Bank. Overseeing enterprise security in innovative AI solutions to ensure compliance and resilience.

🇺🇸 États-Unis – Télétravail

💵 $135 000 - $178 000 / an

⏰ Temps Plein

🔴 Expert

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Azure

Cloud

Cyber Security

SDLC

Vault