Full Job Description
Job Summary
We are looking for a seasoned Director of Cybersecurity to lead and mature our security program across the full breadth of our business. This is a senior leadership role responsible for protecting our subscription products and customer data, securing our software engineering and DevOps pipelines, and building a governance framework that scales with the company.
You will partner closely with Software Engineering, Product, Legal, and Executive leadership to make security an essential part of our business - not just a compliance checkbox.
Job Responsibilities
Subscription Business & Infrastructure Security
• Own the end-to-end security posture of the company's subscription platform, including customerfacing applications, APIs, and underlying cloud infrastructure.
• Define and enforce security architecture standards for cloud environments (AWS, Azure, GCP), ensuring proper network segmentation, identity and access management (IAM), and data protection controls.
• Lead vulnerability management, penetration testing, and red team exercises to proactively identify and remediate risk across production systems.
• Establish and maintain a Security Operations Center (SOC) capability - whether in-house, managed, or hybrid - to ensure continuous monitoring, threat detection, and incident response readiness.
• Oversee data security controls to protect subscriber PII and payment information in compliance with applicable regulations (PCI-DSS, CCPA, GDPR, etc.).
• Define and rehearse incident response plans, leading the organization through security events from detection through post-mortem.
Software Development & DevSecOps
• Embed security throughout the software development lifecycle (SDLC), partnering with Engineering and Product to shift security left without slowing delivery velocity.
• Own the security of CI/CD build pipelines, including secrets management, pipeline integrity, dependency scanning, and supply chain security controls.
• Drive adoption of SAST, DAST, SCA, and container/image scanning tools across development teams.
• Define and maintain secure coding standards, conducting regular developer security training and threat modeling workshops.
• Establish controls to detect and prevent dependency confusion, code injection, and software supply chain attacks in build and deployment processes.
• Partner with platform and infrastructure engineering teams to ensure IaC (Terraform, Pulumi, etc.) follows security best practices and is reviewed prior to deployment.
Governance, Risk & Compliance • Build and maintain a cybersecurity governance framework.
• Own the company's risk register for cybersecurity, providing clear, quantified risk reporting to executive leadership and the board as appropriate.
• Lead and manage third-party security assessments, customer security questionnaires, and audit responses (SOC 2 Type II, penetration test reports, etc.).
• Develop and enforce security policies, standards, and procedures across the organization.
• Drive vendor and third-party risk management, ensuring security requirements are embedded in procurement and contract processes.
• Maintain awareness of the evolving regulatory landscape and ensure the company's practices remain compliant with applicable laws and industry standards.
• Champion a culture of security awareness through company-wide training programs, phishing simulations, and ongoing communication.
Job Requirements
• 10+ years of progressive experience in cybersecurity, with at least three years in a leadership role managing security programs and teams.
• Deep technical expertise in cloud security (AWS, Azure, or GCP) and securing SaaS or subscription-based products.
• Proven experience implementing DevSecOps practices and securing CI/CD pipelines in modern engineering environments.
• Hands-on knowledge of security tooling: SIEM, EDR, SAST/DAST, vulnerability scanners, secrets management platforms, and cloud security posture management (CSPM) tools.
• Strong background in security governance frameworks (NIST CSF, ISO 27001, SOC 2) and working knowledge of compliance requirements (PCI-DSS, GDPR, CCPA).
• Experience leading incident response efforts, including communication with executives, legal, and external stakeholders.
• Excellent written and verbal communication skills - able to translate complex technical risk into clear, actionable business language.
Preferred Qualifications
• Relevant certifications: CISSP, CISM, CISA, AWS Security Specialty, or equivalent.
• Experience with software supply chain security frameworks (SLSA, SBOM generation, Sigstore, etc.).
• Familiarity with zero trust architecture and its practical application in enterprise environments. • Experience working in a subscription or SaaS business where availability and customer trust are directly tied to revenue. • Background scaling security programs at a growth-stage company.
Essential Job Function