Jobgether
Accountabilities: Own and mature preventative security capabilities across cloud, SaaS, endpoint, identity, network, and data environments. Translate security objectives into technical requirements, controls, tooling strategies, implementation plans, and measurable outcomes. Evaluate, select, configure, and deploy security technologies covering areas such as DLP, insider threat, endpoint security, IAM, vulnerability management, access controls, and security monitoring. Continuously assess security posture, identify vulnerabilities and control gaps, prioritize risks, and drive remediation through completion. Partner with IT, Engineering, DevOps, and Product teams to integrate security controls into infrastructure, technologies, and business initiatives. Develop security metrics and reporting that provide clear visibility into control effectiveness, risk, and overall security posture. Work with Security Operations to ensure preventative controls provide appropriate visibility and protection for threat investigation and response. Develop, maintain, and test incident response playbooks, business continuity processes, and disaster recovery plans. Support security compliance initiatives and collaborate directly with auditors by providing evidence, explaining controls, and addressing findings. Translate requirements from SOC 2, ISO 27001, ISO 42001, GDPR, CCPA/CPRA, EU AI Act, and related frameworks into practical technical controls. Provide technical direction and mentorship to security engineers, analysts, IT partners, and external contractors. Act as a security advisor to technical and non-technical stakeholders, translating threats and vulnerabilities into actionable recommendations. Take ownership of ambiguous security challenges from initial strategy and technology evaluation through implementation, measurement, and continuous improvement. Requirements 7+ years of progressive information security experience, including substantial hands-on implementation of enterprise security controls. 2+ years of technical leadership, team lead, or people management experience. Deep knowledge of cloud, SaaS, endpoint, identity, network, and data security, including traditional and agentic AI environments and workloads. Hands-on experience implementing security tooling and controls rather than primarily defining policy or overseeing third-party implementation. Experience with security domains such as DLP, IAM, endpoint security, vulnerability management, insider threat, access management, and security monitoring. Strong understanding of modern cloud infrastructure, security architecture, and risk management. Experience working in modern Mac, Linux, cloud, SaaS, and open-source-heavy environments. Experience automating security controls and workflows using scripting such as Python and infrastructure-as-code security approaches including Terraform, policy as code, and CI/CD guardrails. Working knowledge of NIST, CIS, ISO 27001, SOC 2, and Zero Trust security frameworks. Experience participating in security audits, working directly with auditors, gathering technical evidence, and remediating findings. Strong knowledge of securing third-party APIs and OAuth integrations, including scoping, token lifecycle management, and revocation across SaaS and data platforms. Ability to communicate complex technical risks and vulnerabilities clearly to Engineering, Product, IT, and non-technical stakeholders. Strong analytical, problem-solving, and independent decision-making skills. Experience working within U.S.-based technology environments and familiarity with enterprise security expectations. Comfortable operating autonomously in a fast-moving environment where priorities and requirements evolve continuously. Benefits Competitive compensation with the potential for commissions or bonus programs, where applicable. Equity opportunities for eligible regular employees. Comprehensive employee benefits. Remote work environment. Opportunity to work on modern cloud, SaaS, cybersecurity, and AI-related technologies. Significant ownership and autonomy in shaping preventative security capabilities. Technical leadership and mentoring opportunities. Collaboration with Engineering, Product, IT, DevOps, Security Operations, and executive stakeholders. Professional growth through exposure to security frameworks, regulatory requirements, audits, and emerging technology environments. How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1