> Markdown version of [/jobs/ext/2634616-director-of-information-security-hybrid](https://www.wearedevelopers.com/jobs/ext/2634616-director-of-information-security-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Information Security (Hybrid) - **Company:** SAGE Dining Services, Inc. - **Location:** Baltimore, MD, United States - **Experience:** Expert - **Salary:** $170,000.0 - $220,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Software System Penetration Testing, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Disaster Recovery, Intrusion Detection Systems, Information Systems Security Architecture Professional, PCI Data Security Standards, Information Technology Security Auditing, Security Information and Event Management, Software Engineering, Software Security, Firewalls (Computer Science), Information Technology, Cyber Warfare, Devsecops, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=72d11ad702ffd34d ## About the Role * Bachelor's degree in Information Security, Computer Science, or a related field (or relevant experience). * Minimum of 10 years of demonstrable experience as a Chief Information Security Officer or in a similar senior-level cybersecurity role. * Extensive knowledge of information security principles, cybersecurity frameworks (e.g., NIST, ISO 27001), and risk management practices. * Working knowledge of security auditing, vulnerability assessments, and risk mitigation. * Experience with security technologies such as firewalls, intrusion detection systems, SIEMs, and encryption. * Solid knowledge of data privacy regulations and compliance requirements. * Ability to develop and implement complex security strategies. * Strong leadership and communication skills, with the ability to influence decision-making at all levels. * Exceptional analytical and problem-solving skills with a keen eye for identifying potential risks and vulnerabilities. * Ability to manage a team of security professionals and work cross-functionally with IT, legal, and compliance teams. * Expertise in Secure Software Development and DevSecOps practices. * Relevant certifications in cybersecurity, such as Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or Certified Information Systems Auditor (CISA) preferred. * Experience with cloud security and securing cloud infrastructure. * Familiarity with incident management and disaster recovery planning. * Knowledge of ethical hacking and penetration testing techniques. * Background in regulatory compliance and data privacy laws relevant to our industry (e.g., FERPA, PCI DSS, HIPAA, and state student-data and consumer-privacy laws). * Hands-on experience with SIEM tools, firewalls, and intrusion detection systems. * Understanding of artificial intelligence and machine learning applications in security. * Experience securing multi-site, distributed operations and third-party/vendor integrations common in food service and hospitality technology. About SAGE ## Description The Director of Information Security will lead the organization's information security strategy, governance, and risk management program. The Director is responsible for safeguarding our digital ecosystem, protecting sensitive data, ensuring compliance with cybersecurity and privacy regulations, and strengthening our defenses against an ever-evolving threat landscape. This role combines strategic leadership with operational excellence, partnering across Technology, Culinary, Operations, HR, Legal, and our school communities to embed security into every aspect of the organization., * Develop, implement, and maintain a comprehensive security program that includes cyber defense, data protection, and security operations across corporate and field environments. * Conduct risk assessments, identify vulnerabilities, and prioritize remediation efforts to reduce risk. * Lead recurring NIST CSF-based assessments, gap analysis, prioritization, and remediation roadmap development across enterprise, software, and operational environments. * Oversee security incident detection, response, and recovery, ensuring swift mitigation of potential breaches and timely notification to affected parties and school partners. * Manage the security architecture, tools, and technologies deployed across SAGE's IT infrastructure, applications, and vendor integrations. * Coordinate with legal, compliance, and regulatory teams to ensure compliance with data protection laws applicable to our business, such as FERPA, PCI DSS, and applicable state and federal privacy regulations. * Monitor security metrics and report on the company's security posture to executive leadership. * Lead security awareness training programs for employees to promote a culture of cybersecurity across the organization, from the home office to on-site dining teams. * Stay updated on cybersecurity trends, technologies, and best practices to enhance security proactively. * Develop and maintain a policy architecture that translates enterprise security requirements into domain-specific standards, procedures, and evidence expectations. * Own the SSDLC program charter and application security operating model using SAMM or an equivalent framework. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market)