Source Job

US

  • Lead and mature the information security program, building on ISO 27001 and SOC 2 foundations.
  • Develop and operationalize security policies, risk management, and incident response.
  • Partner with Engineering and Product to integrate security into software development.

ISO 27001 SOC 2 Cloud Security AWS GCP

20 jobs similar to Director of Information Security

Jobs ranked by similarity.

$200,000–$245,000/yr
US

  • Own the overall security posture, including policy, standards, and risk framework.
  • Manage ISO 27001, SOC 2, FedRAMP, and CMMC compliance programs.
  • Lead incident response, vulnerability management, and customer security assurance.

RapidFort is a cybersecurity company that helps organizations secure and optimize their software supply chain and containerized environments. As a fast-growing startup, we foster a culture of ownership and direct communication, where every team member contributes to our mission of securing cloud-native applications for regulated industries.

$120,000–$220,000/yr
Global Unlimited PTO 22w maternity 16w paternity

  • Own and build Flodesk's security program end to end, including policies, controls, and governance.
  • Lead SOC 2, ISO 27001, and CCPA readiness while partnering with engineering on secure development.
  • Manage IT operations, vendor vetting, and security tooling to scale the program.

Flodesk is a fast-growing email marketing company that helps creators and small businesses design emails and monetize their email lists. It is a remote-first company with a globally distributed team and offices in San Francisco, Menlo Park, and Da Nang.

Global

  • Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
  • Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
  • Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.

Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.

US

  • Lead the design and execution of cybersecurity architecture and engineering to ensure compliance with internal and external policies.
  • Partner with business leaders to identify risks, develop solutions, and embed security into enterprise strategy.
  • Oversee deployment, integration, and optimization of security tools while driving cloud-native security improvements.

U.S. Financial Technology builds and operates the world's largest mortgage securitization platform, supporting the Uniform Mortgage-Backed Security of Fannie Mae and Freddie Mac. It handles 70% of mortgage-backed securities and fosters a collaborative, remote-first culture.

Global Unlimited PTO

  • Lead and grow a small security team while owning Canary's security and compliance program end-to-end.
  • Serve as the primary security voice to customers, partners, and auditors, translating security posture for varied audiences.
  • Set technical direction for security tooling and stay hands-on in architecture and threat-model reviews.

Canary Technologies is a leading agentic AI platform for hotel and guest management, powering digital infrastructure for over 20,000 hotels in 125+ countries. With nearly $200M raised, they are a top-funded hotel tech company, recognized for growth and workplace excellence.

Germany 6w PTO

  • Lead ISO 27001 and SOC 2 audit cycles end-to-end, owning compliance and audit.
  • Own customer trust by responding to security questionnaires and representing InfoSec to enterprise clients.
  • Drive risk management, vendor security, and incident response while building AI-assisted workflows.

We are the first AI-native Employee Experience Platform, helping organizations unlock inspirational communication. Our diverse team of 550+ employees supports over 1,500 customers, and we are a unicorn company valued at over $1 billion.

$135,000–$145,000/yr
Global

  • Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
  • Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
  • Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.

Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.

$100,000–$130,000/yr
Global

  • Take ownership of information security governance, including policies, risk registers, and control documentation.
  • Manage day-to-day security program operations, mentor analysts, and coordinate cross-functional initiatives.
  • Lead incident response, compliance support, and serve as primary counterpart to the vCISO.

Aries is a financial technology company building modern infrastructure and products for active investors and traders. As a growing organization, they are investing in a practical, accountable security program deeply integrated into how the company operates.

$115,000–$150,000/yr

  • Manage day-to-day security operational availability and supportability of a 24x7x365 infrastructure.
  • Make recommendations on enhancements to security hardware, software, and tools, and perform risk analysis.
  • Configure, implement, monitor, and support security software/systems including firewalls, VPNs, IDS/IPS, DLP, etc.

eMoney Advisor is a wealth management system that offers transparency, security, mobile access, and superior organization. We serve more than 109,000 financial professionals and support over 6 million end clients, fostering a culture that values diversity and inclusion.

US

  • Develop and execute enterprise cybersecurity strategy and multi-year security roadmap.
  • Lead cybersecurity risk management, security operations, and incident response programs.
  • Ensure compliance with HIPAA, HITRUST, NIST, and other regulatory frameworks.

Mom's Meals provides home-delivered meal solutions for individuals with health needs. The company values its team members and offers a generous benefits package.

$80,208–$83,372/yr
Poland

  • Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
  • Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
  • Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.

Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.

$116,019–$145,024/yr
US 4w PTO 4w maternity 4w paternity

  • Design, deploy, and manage cloud security solutions to protect AWS and Azure environments.
  • Perform security assessments, vulnerability remediation, and lead key security programs.
  • Automate security processes and integrate DevSec practices into the software development lifecycle.

Navitus is a pharmacy benefit manager (PBM) alternative that aims to make medications more affordable by removing cost from the drug supply chain. The company fosters a diverse, creative, and growth-oriented culture.

Europe

  • Architect and oversee advanced security monitoring and threat detection frameworks across diverse systems and log sources.
  • Lead the integration of security into the software development lifecycle, including Security-as-Code and automated SAST, DAST, and SCA capabilities within CI/CD pipelines.
  • Own the end-to-end vulnerability management strategy across infrastructure and applications, prioritizing remediation according to business risk.

The partner company operates a large-scale digital platform and a globally distributed technology ecosystem connected to gaming and esports communities. They maintain a flexible, distributed, and inclusive work environment focused on equal opportunity and technical ownership.

Global

  • Improve perimeter and network-layer defenses (WAF, DDoS mitigation, anti-bot) and secure product APIs against abuse.
  • Manage vulnerability identification, prioritization, remediation, and coordinate external pentests.
  • Lead incident response, run the Security Champions program, and manage the Bug Bounty program.

Social Discovery Group (SDG) solves problems of loneliness, isolation, and disconnection by providing social entertainment platforms that connect people across cultures. The company is an international team of digital nomads working remotely worldwide and has been named a Great Place to Work (USA & Japan, 2024–2025).

Canada

  • Mentor and advise security leaders on building and scaling an Information Security program.
  • Provide strategic guidance on product security, cloud security, incident response, and compliance.
  • Collaborate with engineering, product, and business teams to strengthen security culture and processes.

$115,336–$159,286/yr
US

  • Lead coordination and implementation of a comprehensive information security program, including policies, processes, and technical controls.
  • Assess security threats, evaluate emerging technologies, and develop countermeasures to protect sensitive systems and data.
  • Collaborate across teams to translate risks into practical strategies and ensure compliance with security regulations and privacy laws.

This organization protects critical technology and information systems across internal IT, e-commerce, web, and cloud environments in the healthcare sector. It fosters a mission-driven, inclusive culture with employee resource groups and career development programs.

Europe 4w PTO

  • Lead and develop the Information Security GRC strategy, roadmap, operating model, and governance cadence.
  • Coordinate SOC 2, DORA/CySEC-related assurance, internal and external audits, and regulatory requests.
  • Build, develop, and manage the GRC team and improve GRC efficiency through automation and reusable evidence.

JustMarkets is an international FinTech company. It is a growing organization with a focus on information security and compliance.

$205,000–$230,000/yr
US Unlimited PTO

  • Lead security monitoring, incident response, and threat hunting across cloud and AI-enabled environments.
  • Establish operational priorities, metrics, and playbooks based on organizational risk.
  • Drive responsible adoption of AI-assisted detection and response capabilities.

Backblaze is a cloud storage and backup provider that helps customers protect their data across over 175 countries. The company fosters a culture centered on fairness, goodness, and work-life balance, with a strong commitment to diversity and inclusion.

Europe

  • Act as Information Security Officer for FinTech, supporting ISO 27001, SOCv2, and DORA implementation.
  • Coordinate security activities across teams, ensuring alignment with cyber security strategy and governance.
  • Track risks, gaps, and remediation, while preparing updates for security leadership.

Coinspaid Dev is the engineering brand behind the technology and infrastructure built within Coinspaid. With over 120 engineers and 11 years of industry experience, the team builds distributed systems and blockchain infrastructure across more than 20 blockchain networks.

US

  • Lead global information security strategy across manufacturing, product, and application security, ensuring resilience and regulatory readiness.
  • Oversee OT/ICS security, product security for FDA-regulated medical devices, and application security with DevSecOps practices.
  • Build and lead a global team, partner with senior executives, and establish risk management frameworks and metrics.

They are a global industrial and healthcare technology company operating in over 50 countries, manufacturing connected products and medical devices. They are a large, decentralized organization with a collaborative culture and a focus on security and innovation.