Director of Information Security and Operations

🕒 July 27

🇺🇸 United States – Remote

⏰ Full Time

🔴 Lead

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 18%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of jrni

jrni

51 - 200 employees

Founded 2008

☁️ SaaS

🤝 B2B

🏢 Enterprise

💰 $6M Series C - JRNI on 2019-08

SaaS • B2B • Enterprise

jrni is a provider of cloud-based appointment scheduling and customer engagement software. The platform helps businesses manage bookings, appointments, virtual queues and in-store or remote customer experiences across channels, enabling retailers and service providers to offer online booking, scheduling and customer journey orchestration. jrni targets other businesses with a SaaS product focused on improving operations and customer experience.

📋 Description

• Set the direction for jrni's Information Security program against ISO 27001 and SOC 2 • Own and improve operational controls satisfying ISO 27001, SOC 2, GDPR, and other frameworks • Own JRNI's AI security policy and governance standards (aligned with NIST AI RMF and ISO 42001) • Lead AI Operations — using AI to improve efficiency while governing AI systems for privacy and security risk • Partner with Legal and external auditors on audits, evidence collection, and certification renewals • Build and support a culture of security awareness, data protection, and compliance, including training • Manage and optimize production cloud infrastructure for scalability, reliability, and compliance • Partner with Engineering / SRE on CI/CD, release management, and production stability • Oversee monitoring, alerting, and observability to resolve issues proactively • Implement and test disaster recovery and business continuity plans • Lead vulnerability management, patching, and hardening across the estate • Own security and operational incident response plans; run tabletop exercises • Serve as incident commander for Sev-1/Sev-2 events, coordinating with customers, Legal, and execs • Lead blameless post-incident reviews and track remediation to closure • Maintain a risk register and lead periodic enterprise risk assessments • Own third-party / vendor risk management — vendor reviews, DPAs, sub-processor oversight • Oversee IAM across corporate (SSO, MFA, SCIM) and production (least-privilege, JIT access, break-glass), with access reviews and joiner/mover/leaver processes • Manage JRNI's cyber insurance relationship and renewals • Improve processes for productivity, scalability, and audit readiness • Use automation to streamline workflows and strengthen compliance reporting • Develop and manage the operational budget across people, technology, and vendors • Work with Customer Success to ensure service delivery and operational excellence • Build, mentor, and retain effective, engaged InfoSec and TechOps teams • Define clear career paths, performance objectives, and development plans • Foster a blameless, learning-oriented culture • Collaborate across Sales, Customer Success, Product, and Engineering • Own responses to customer security questionnaires (SIG, CAIQ), RFPs, and audit requests; maintain a customer-facing trust center • Act as security executive sponsor in enterprise sales cycles • Partner with Legal and Product on data residency, classification, retention/deletion, and DSAR fulfillment • Establish KPIs (uptime, MTTD/MTTR, audit closure, remediation SLAs, CSAT) and report to execs and the Board

🎯 Requirements

• Significant experience in Information Security and/or IT Operations, including leading multiple teams • Leading SOC 2 Type II and ISO 27001 audits end-to-end • Operating production SaaS infrastructure at scale on AWS and GCP; strong cloud/network/app security and DevSecOps • Hands-on with SIEM, EDR, vulnerability scanners, and CSPM platforms • Leading incident response in production SaaS • Strong, clear executive communication — comfortable with the Board, customers, and auditors • Bachelor's in CS, Engineering, or related field — or equivalent professional experience • CISSP, CISM, CISA, AWS Security Specialty, or ISO 27001 Lead Auditor/Implementer are nice to have • HIPAA, PCI-DSS, or FedRAMP experience are nice to have • AI/ML governance (NIST AI RMF, ISO 42001) and securing AI-enabled products are nice to have • Defining and operating customer-facing trust programs are nice to have

🏖️ Benefits

• Professional development opportunities • Flexible work arrangements

Apply Now

Similar Jobs

🕒 July 27

Curative

501 - 1000

🏥 Healthcare

🛡️ Insurance

Principal Security Engineer leading security engineering function for Curative's infrastructure, applications, and AI systems with a strong emphasis on building secure designs.

🕒 July 25

Gainwell Technologies

10,000+ employees

💼 Consulting

📦 Logistics

⚕️ Healthcare Insurance

Information Security Officer responsible for security compliance and client delivery in healthcare. Collaborating with leadership to identify security issues and manage risks.

🕒 July 24

Pinnacle Treatment Centers, Inc.

1001 - 5000

🏥 Healthcare

🧘 Wellness

🌍 Social Impact

Director of Security & Network at Pinnacle Treatment Centers leading cybersecurity strategy and operations. Overseeing enterprise networking, security initiatives, and team leadership in addiction treatment services.

🕒 July 23

Highmark Health

10,000+ employees

🛡️ Insurance

💼 Consulting

📦 Logistics

Manager Information Security & Risk Management at Highmark Health ensuring alignment with security needs and managing personnel activities. Overseeing technology products and contributing to strategic planning efforts.

🕒 July 22

EZCORP

5001 - 10000

🛒 Retail

👥 B2C

Director of Cyber Security at EZCORP responsible for enterprise security vision and measures. Leading strategies to safeguard sensitive information and manage security operations.