Director of Information Security and Technical Operations (Fintech)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Remote; employees must reside in one of the following states: Alabama, Arkansas, Arizona, Colorado, Florida, Georgia, Illinois, Indiana, Kentucky, Louisiana, Maryland, Michigan, Minnesota, Missouri, Mississippi, North Carolina, New Jersey, Nevada, New York, Ohio, Oklahoma, Oregon, South Carolina, Tennessee, Texas, Utah, Virginia, Washington, or Wisconsin. Conditions: Rothschild, United States.
Salary: USD $170,000–$200,000 per year.
Company
is a consumer finance company that provides flexible financing options through home improvement contractors across the United States.
What you will do
- Develop and continuously improve the enterprise-wide information security program, including strategy, policies, standards, and roadmap.
- Lead security operations across cloud and on-premises environments, including network security, threat detection, incident response, vulnerability management, and monitoring.
- Oversee IT infrastructure, network administration, endpoint management, identity and access management, and shared technology services.
- Own SOC 2 controls, audit evidence, remediation plans, external auditor engagement, and customer security reviews.
- Partner with Product, Engineering, and Data teams on security architecture, security-by-design, application security, and API security.
- Manage third-party security risk, security budgets, operational metrics, training programs, and reporting to senior leadership and the board.
Requirements
- Bachelor’s degree in computer science, engineering, business, or a related field; a master’s degree is preferred.
- At least 4 years of senior security leadership experience and at least 8 years of progressive information security and IT operations experience in a cloud-centric, SaaS, or fintech environment.
- Strong knowledge of SOC 2, NYDFS, FTC information security requirements, NIST CSF, and NIST 800-53.
- Experience implementing controls across hybrid and cloud environments and working with AWS, Azure, or GCP, DevSecOps, identity and access management, endpoint security, and SIEM platforms.
- Relevant certifications such as CISSP, CISM, CISA, or CCSP are preferred.
- Remote employees must reside in one of the listed U.S. states.
Nice to have
- Experience with ISO 27001, PCI DSS, GLBA, or comparable frameworks and regulations.
- Master’s degree or relevant professional certification.
Culture & Benefits
- Day-one medical, dental, vision, HSA, and FSA options.
- 401(k) with company match enrollment on day one.
- Paid sick, volunteer, parental, and other time off options.
- Employer-paid life and disability insurance.
- Flexible work environment with a casual dress code and wellbeing program.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →