The Mathworks

Head of Information Security

The Mathworks$150K — $200K *
Information Technology
15+ years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in computer science, Engineering, or related field.
  • 20 years of professional work experience; 8 years in management.
  • Experience leading risk management and security assessments.
  • Strong understanding of security frameworks like ISO 27001, NIST and privacy regulations (GDPR, CCPA).
  • Technical background in enterprise/cloud security architecture and secure software development.
  • Proven experience leading responses to major security incidents.

Responsibilities

  • Develop and implement cybersecurity vision and strategy aligned with business and regulatory needs.
  • Lead comprehensive cybersecurity programs ensuring the confidentiality, integrity, and resilience of information assets.
  • Evolve and enforce corporate security policies, best practices, and modern architectures like Zero Trust.
  • Manage and maintain modern security architectures involving identity-centric access control and cloud-native defenses.
  • Chair the Security Risk Review Board to evaluate and mitigate security risks effectively.
  • Lead the design and improvement of technical security controls across IT and development environments.
  • Ensure compliance with global security and data privacy regulations (GDPR, CCPA).

Benefits

  • Hybrid work environment with flexibility for in-office days.
  • Opportunities for continued professional development and training.
  • Supportive and inclusive company culture that values innovation.
  • Access to cutting-edge security technologies and practices.
Full Job Description
Job Summary

Responsible for the strategic and technical leadership and direct management of MathWorks' Information Security team, overseeing the company's corporate security. Provides operational direction to ensure protection of data, infrastructure, and physical assets, while maintaining compliance with industry regulations and internal standards.

Partners closely with Product Security team to align strategies, share expertise, and collectively meet MathWorks' overarching security and compliance objectives. Collaborate with senior leadership to define acceptable risk levels and implement practices to meet cybersecurity policies and standards. Must possess deep technical expertise and be hands-on in defining, selecting, and validating security technologies and architectures.

Responsibilities

Strategic Leadership
  • Develop and implement a cybersecurity vision and strategy aligned with business objectives and regulatory requirements.
  • Lead a comprehensive cybersecurity program for confidentiality, integrity, availability, safety, privacy, reliability, and resilience of information assets.
  • Identify and mitigate risks related to non-IT-managed technology ("citizen IT") and ensure clear ownership of any residual risk.
  • Evolve and enforce corporate security policies, best practices, and modern architecture (e.g., Zero Trust, remote work strategies, automated vulnerability management).
  • Manage and maintain modern security architectures (e.g., ZTNA, identity-centric access control, cloud-native defenses, vulnerability, and patch management automation).
  • Provide strategic guidance on security technology investments, architecture reviews, and risk mitigation initiatives.
  • Lead or guide responses to cybersecurity incidents.

Risk Management
  • Chair the Security Risk Review Board, overseeing evaluation, prioritization, and mitigation of security risks.
  • Lead decision-making on acceptance of residual risks and communicate strategies to senior leadership.
  • Facilitate cybersecurity risk assessment and empower business units to make decisions within risk appetite.
  • Manage the organization's incident response and threat hunting capabilities by leading cross-functional teams, implementing playbooks, and continuously improving detection and response effectiveness.

Technical Oversight and Security Engineering
  • Lead the design, implementation, and continuous improvement of technical security controls across IT, cloud, and development environments.
  • Collaborate and develop enterprise-wide standards for identity and access management, network segmentation, endpoint protection, encryption, logging, and monitoring.
  • Collaborate with software engineering and infrastructure teams to embed security principles and controls into architectures, systems, and development processes ("secure by design").
  • Partner with Engineering, IT, and business leaders to embed "shift-left" security into infrastructure, CI/CD pipelines, and operations.

Compliance and Framework Oversight
  • Ensure compliance with global security and data privacy regulations (GDPR, CCPA, ISO 27001).
  • Provide regular reporting on cybersecurity programs and compliance status to senior leadership.
  • Maintain external partnerships with industry peers, agencies, and law enforcement to stay ahead of emerging threats.

Training and Awareness
  • Direct creation of targeted cybersecurity awareness training for all employees, contractors, and system users.
  • Establish metrics to measure training effectiveness, and ensure employees, contractors, and system users.


Minimum Qualifications

  • A bachelor's degree and 20 years of professional work experience (or equivalent experience) is required. 8 years management experience is required.


Additional Qualifications

Required
  • Bachelor's degree in computer science, Engineering, or related field.
  • Experience leading risk management and security assessments.
  • Strong understanding of security frameworks (ISO 27001, NIST) and privacy regulations (GDPR, CCPA).
  • Technical background in enterprise/cloud security architecture, network/system hardening, identity management, secure software development.
  • Proven experience leading the end-to-end response to major security incidents including triage, containment, recovery, stakeholder communication, and post-incident remediation.
  • Ability to work three or more days in the Natick office (MathWorks is a hybrid workplace).

Preferred
  • Master's or equivalent experience preferred.
  • 25 years' experience in information security/cybersecurity, with at least 10 years in management, building, and scaling security teams.
  • Experience with AWS, Azure, or similar cloud environments.
  • Experience in regulated industries (aerospace, automotive, software).

Key Leadership Behaviors
  • Strategic Thinking: Design and implement long-term security initiatives.
  • Technical Leadership: Engage directly with engineers, architects, and IT operations.
  • Risk Management: Assess risks, lead mitigation strategies, and make recommendations on risk acceptance.
  • Collaboration: Lead cross-functional teams and build strong relationships.
  • Change Management: Drive organizational change in security practices and culture.

About The Mathworks

The MathWorks, Inc. is an American software company that specializes in mathematical computing software. The company was founded in 1984 and is headquartered in Natick, Massachusetts. The MathWorks offers a range of products, including MATLAB, Simulink, and Stateflow, which are used in engineering, science, and mathematics. The company serves customers in over 100 countries and has partnerships with major technology companies such as Microsoft and Intel. In 2019, The MathWorks was named one of the best places to work by Glassdoor.
Learn more about The Mathworks
Size
5,000 employees
Industry
Founded
1984

Similar Jobs

More Jobs at The Mathworks

More Information Technology Jobs

Find similar Head of Information Security jobs: