Head of Security

Security EngineerSecurity EngineerFull TimeRemote

Location

United States

Posted

12 days ago

Salary

Not specified

No structured requirement data.

Job Description

Head of Security


Role purpose


Own the organization’s security posture end-to-end. The Head of Security sets strategy,
standards and day-to-day execution across information security, application security,
infrastructure security and (where applicable) physical security. The role balances risk reduction
with business enablement - making security practical, measurable and scalable.

Key responsibilities

1) Security strategy & governance
● Define and maintain the security strategy, roadmap and operating model aligned to the
business goals.
● Establish security policies, standards and secure-by-default guardrails.
● Define and enforce data protection and encryption standards.
● Create security metrics/KPIs and executive reporting.

2) Risk management
● Run an enterprise risk assessment process.
● Assess and prioritize risks across systems, vendors and business processes.
● Own security exception handling and ensure compensating controls are documented
and monitored.

3) Incident response & resilience
● Own the incident response program: playbooks, on-call procedures, tabletop exercises,
evidence handling, postmortems.
● Lead response to security incidents (containment, eradication, recovery) and coordinate
internal/external stakeholders.
● Improve resilience through backups, disaster recovery testing and security
monitoring/alerting.

4) Security operations
● Implement and oversee controls such as IAM, MFA, least privilege, endpoint security,
patching and secure configuration baselines.
● Operate vulnerability management (scanning, triage, remediation SLAs) and penetration
testing coordination.
● Protection and monitoring of sensitive data: implement and operate controls to prevent
unauthorized access, misuse or exfiltration.
● Maintain logs/SIEM, detection engineering and continuous monitoring where
appropriate.

5) Product & application security
● Embed security into SDLC: secure coding standards, code scanning, dependency
management, secrets handling, CI/CD controls.
● Perform/enable threat modeling and security reviews for new features and architectural
changes.
● Drive remediation of application and infrastructure findings with engineering teams.

6) Vendor & third-party security
● Own third-party risk management: due diligence, security questionnaires,
contract/security addendums, ongoing monitoring.
● Ensure vendors meet security requirements and that data-sharing is controlled and
auditable, including encryption and data handling expectations for sensitive data.

7) Security culture & training
● Build a strong security culture via training, phishing simulations and clear processes.

8) Budget, team & leadership
● Build and manage the security budget (tools, vendors, staffing) and justify investments
based on risk and ROI.
● Hire, develop and manage security staff and/or MSSP relationships.
● Establish clear SLAs and service ownership across security domains.

Required experience & skills
● Strong understanding of cloud security (AWS/Azure/GCP), IAM, network security and
endpoint security.
● Strong understanding of data protection and encryption practices.
● Proven incident response leadership and ability to manage crisis communications.
● Ability to translate technical risk into business impact and make pragmatic
recommendations.
● Experience building security programs, policies and metrics from scratch or scaling
them.
● Strong stakeholder management, vendor negotiation and executive communication



Location

Remote


Department

IT


Employment Type

Full-Time


Minimum Experience

Manager/Supervisor


Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 1-10Since 1999H1B No Sponsor

Information Assurance Engineer managing cybersecurity for DoD mission systems

AzureCyber Security
United States

Senior Manager, Information Security Officer

Paytient

Paytient Health Payment Accounts help people better access and afford care.

Security Engineer12 days ago
Full TimeRemoteTeam 51-200Since 2018H1B No Sponsor

This is a hands-on role for a highly motivated and experienced Information Security Officer. In this quickly developing organization, you will be expected to be a strong team player who can also independently drive key security initiatives as the information security department m...

United States

Manager of Information Technology

OpenSesame

We help companies develop the world's most productive and admired workforces.

Security Engineer12 days ago
Full TimeRemoteTeam 51-200Since 2011H1B No Sponsor

About OpenSesame OpenSesame is the trusted partner for Workforce Reinvention in the age of AI. OpenSesame delivers integrated software, curated and customizable content, and expert services – embedded into existing learning, HR, and work systems – to help organizations expand the...

United States

Regional Director – Data Security

Zscaler

We make it easy to secure your cloud transformation. Get fast, secure, and direct access to apps without appliances.

Security Engineer12 days ago
Full TimeRemoteTeam 5,001-10,000Since 2008H1B Sponsor

Regional Director driving sales for cybersecurity solutions in the USA

United States
$160K - $200K / year