> Markdown version of [/jobs/ext/226048-vp-of-information-security-it](https://www.wearedevelopers.com/jobs/ext/226048-vp-of-information-security-it). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # VP of Information Security & IT - **Company:** Curative Inc. - **Location:** Austin, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $275,000.0 - $310,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Control Objectives for Information and Related Technology (COBIT), Code Review, Cyber Security, Identity and Access Management, IT Management, Information Technology Operations, Networking Hardware, Network Architecture, Software Architecture, Software Tools, Security Information and Event Management, Software Vulnerability Management, Google Cloud, Enterprise Software Applications, Large Language Models, Software Security, Information Technology, Checkmarx, CIS Benchmarks, Static Application Security Testing, Dynamic Application Security Testing - **Published:** May 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1a5bf149f1a78ebf ## About the Role Do you have experience in Vulnerability management?, Do you have a Bachelor's degree?, * Bachelor's degree in a related field or equivalent experience., * 10+ years in information security, with at least 5 years in a leadership role. * Demonstrated experience owning a GRC program and TPRM function. * Hands-on background in Security Operations, vulnerability management, and incident response. * Experience leading an IT function and managing vendor relationships. * Comfortable presenting security topics to executive and non-technical audiences. Technical Skills * Proficiency with SIEM and EDR/XDR platforms; familiarity with code scanning tools (Snyk, Semgrep, Checkmarx, etc.). * Understanding of cloud security (AWS, GCP, Azure), IAM platforms, and network infrastructure. * Knowledge of NIST CSF, ISO 27001, SOC 2, HIPAA, and CIS Controls. * Hands-on experience using AI tools for security monitoring and workflow automation; familiarity with securing LLM deployments, agentic workflows, and AI harness/orchestration security. * Ability to assess risk and develop policy guidance for AI-powered workforce tools. Leadership Competencies * Strategic leader who balances near-term operational demands with longer-term program development. * Strong communicator who translates technical risk into business-relevant terms. * Cross-functional, decisive under pressure, and able to lead teams across multiple functions with competing priorities. ## Description The VP of Information Security & IT is responsible for leading and executing a comprehensive information security and IT strategy, including Governance, Risk & Compliance, Security Operations, and Enterprise IT. As the company's HIPAA Information Security Officer, this leader owns the design, implementation, and continuous improvement of the company's information security program. This leader will partner cross-functionally with every aspect of the business to ensure that security is embedded into every layer of the organization, and that IT systems and infrastructure reliably support the needs of a growing AI-enthusiastic company., Product Security * Deploy and operationalize automated security scanning across engineering products and CI/CD pipelines, identifying and communicating vulnerabilities at the code and architecture level. * Partner with Engineering and Platform teams to integrate SAST, DAST, SCA, and secrets detection tooling into development workflows and secure cloud computing environments. * Maintain vulnerability management processes including prioritization, remediation tracking, and SLA enforcement; leverage AI tooling to improve detection coverage and triage efficiency. Information Security Risk Management * Own the Information Security and IT GRC program, ensuring alignment with HIPAA, COBIT, and other applicable frameworks, including the risk register and control environment. * Own the Third Party Risk Management program, including vendor assessments, contract reviews, and ongoing monitoring with particular attention to the risks introduced by AI-powered vendor tools. * Provide risk-based guidance to stakeholders on new tools, vendors, and architectural decisions, including policy governance for AI workforce tools. Security Operations * Maintain and evolve the threat monitoring program, leveraging AI-assisted detection to ensure continuous visibility and timely identification of suspicious activity. * Lead incident response, coordinating cross-functional teams, managing communications, and driving post-incident reviews. * Continuously improve detection and response capabilities through SIEM tuning, playbook development, and tabletop exercises. Information Technology * Oversee IT operations including helpdesk, system administration, and physical network administration, ensuring reliability and security across the environment. * Set the strategy and roadmap for enterprise applications and infrastructure, including identity and access management; evaluate and govern the use of AI-powered productivity and business tools. Leadership & Communication * Own security and IT vendor relationships, contracts, and budgets, including forecasting and investment recommendations. * Deliver regular updates to executive leadership on program status, key risks, and strategic priorities. * Lead, mentor, and develop a team spanning security and IT, managing priorities, workload, and career growth across both operational and strategic work. ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Cloud Run- the rise of serverless and containerization](https://www.wearedevelopers.com/videos/106-cloud-run-the-rise-of-serverless-and-containerization) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) - [Hiring AI Native Talents](https://www.wearedevelopers.com/videos/100268-hiring-ai-native-talents) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)