> Markdown version of [/jobs/ext/3054348-director-of-information-security](https://www.wearedevelopers.com/jobs/ext/3054348-director-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Information Security - **Company:** Information Security Corporation - **Location:** Los Angeles County, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $220,200.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Application Portfolio Management, Cloud Engineering, Cyber Security, Continuous Integration, Programming Tools, Intrusion Detection and Prevention, Python (Programming Language), Machine Learning, Systems Development Life Cycle, Zero Trust Network Access, Secure Coding, Security Information and Event Management, Software Engineering, Software Vulnerability Management, Model-Driven Development, Software Security, Multi-Cloud, Cloudformation, Kubernetes, Terraform, Static Application Security Testing, Programming Languages, Dynamic Application Security Testing - **Published:** September 24, 2026 - **Apply:** https://startup.jobs/director-application-security-zhl-zillow-home-loans-llc-10156845 ## About the Role * 12+ years of progressive security experience, with at least 5 years in leadership roles managing managers and multi-functional security teams; prior experience in a high-growth consumer technology or fintech company is strongly preferred. * Roots in security engineering, software development, or platform engineering-you have built things, not just governed them, and your technical instincts remain sharp enough to engage credibly with principal engineers and architects. * Demonstrated experience owning multiple security domains simultaneously (e.g., SOC/detection, AppSec, architecture) with the organizational maturity to drive excellence across each without personally bottlenecking any of them. * Proven track record in Application Security leadership at scale-specifically, building AppSec programs that integrate natively into SDLC, CI/CD, and developer workflows inside technology-forward organizations. * Deep expertise in multi cloud security (AWS preferred), including IaC security (Terraform/CloudFormation), Kubernetes/container security, and Zero Trust architecture patterns. * Strong detection engineering mindset: experience moving a SOC from alert triage to custom detection pipelines, SOAR automation, and threat-model-driven coverage. * Ability to quantify and communicate security risk in business and financial terms; experience presenting to executive leadership and, ideally, board-level audiences. * Talent magnet: a reputation for hiring and developing elite security engineers, with the technical credibility to attract senior ICs who could work anywhere. * Familiarity with the modern security tooling ecosystem: SIEM, SOAR, DLP,EDR, EPM, CSPM/CWPP ,SaST /DaST. IAC, and container security - with the judgment to rationalize and consolidate rather than accumulate. * Proficiency in at least one scripting or programming language (Python, Go, or similar); sufficient to review automation, detection logic, and security tooling code written by your team. ## Description As Director of Information Security, drive the strategy, execution, and maturity Application Security, and Security Architecture and our India Security Team. This is an M5 leadership role that reports directly to the VP, Information Security , and carries significant accountability for the security posture, talent, and engineering culture of a large, multi-function organization. We are looking for a builder, someone who has led application security organizations inside high-growth technology companies where engineering velocity is a first-class value. You have a background that started in software engineering or security engineering, and you've never fully left it behind. You are the leader who can earn trust with a senior engineers and peers, recruit principal-level security engineers, and then go present business risk. You will manage a team of managers and senior individual contributors across your four domains, partnering deeply with Platform Engineering, Product, Legal, Privacy, and Compliance. You will set multi-year technical roadmaps, own the operational budget and tooling strategy for your org, and serve as a key voice in defining the company's overall security risk posture and investment priorities. Responsibilities Leadership & Organizational Strategy * Lead and develop a multi-manager organization across Application Security, and Security Architecture, setting clear direction, healthy team culture, and high-performance expectations at every level. * Establish and execute a 2-3-year strategic roadmap for your domains that is tightly coupled to Zillow's product and platform engineering priorities, not just industry compliance frameworks. * Own workforce planning, org design, talent acquisition, and the development of a bench of future security leaders-with a specific focus on recruiting and retaining engineers who want to build, not just advise. * Manage budget, tooling portfolio, and vendor relationships across your scope, with a bias toward consolidation, automation ROI, and eliminating tool sprawl. * Represent Application Security at the executive and leadership level; translate complex technical risk into business impact for the VP Application Security * Lead an AppSec organization that partners with product engineering rather than policing it-building "paved road" security capabilities embedded in CI/CD pipelines, frameworks, and developer tooling. * Drive a developer-first security culture: create security enablement programs, secure coding training, and internal tooling that make the secure path the easy path for Zillow's engineers. * Ensure comprehensive coverage of Zillow's application portfolio including secure design review, DAST/SAST integration, dependency management, and API security. * Own product security strategy, ensuring that security is a design-time consideration in new product features, not an audit checkpoint at the end of the SDLC. * Build and maintain a vulnerability management program with clear SLAs, risk-based prioritization, and executive-facing reporting. Security Architecture * Partner with the Security Architecture function to establish and maintain enterprise security patterns, reference architectures, and guardrails for Zillow's cloud-native, AWS-centric infrastructure. * Drive Zero Trust principles and identity-driven access across the environment, working with Platform Engineering to embed security patterns into infrastructure-as-code and platform primitives. * Ensure security architecture is a proactive partner in platform and product design reviews, providing clear, opinionated guidance that accelerates rather than slows engineering delivery. * Maintain a forward-looking architecture posture: evaluate emerging threats and technology shifts (e.g., AI/ML-driven attack surfaces, cloud configuration risk) and evolve controls accordingly. ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)