> Markdown version of [/jobs/ext/3414922-head-of-information-security](https://www.wearedevelopers.com/jobs/ext/3414922-head-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Information Security - **Company:** Accumulus Technologies, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $200,000.0 - $260,000.0 - **Contract:** Permanent contract - **Skills:** Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, DevOps, Disaster Recovery, Identity and Access Management, IT Management, Secure Coding, Software Vulnerability Management, Software Security - **Published:** September 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=932905cbfa4f01e2 ## About the Role * Substantial progressive experience in information security, including leadership of a corporate or product security function and ownership of security strategy and program delivery. * Demonstrated ability to manage and develop internal security teams and hold external contractors or service providers accountable for results. * Required familiarity with Vanta and with ISO 27001, SOC 2, and HITRUST; practical experience overseeing GRC programs, audits, evidence readiness, and remediation. * Strong understanding of cloud and SaaS security, secure development, identity and access management, encryption, vulnerability management, monitoring, and incident response. * Experience assessing cyber risk, evaluating control effectiveness, governing security exceptions, and translating technical findings into business decisions. * Proven ability to lead customer security reviews and questionnaires and communicate security posture credibly to executives, auditors, regulators, and technical stakeholders. * Experience coordinating response, recovery, resilience testing, and follow-through on corrective actions. * Ability to prioritize competing demands, influence cross-functional teams, and make pragmatic, risk-based security decisions that support product delivery and commercial objectives while protecting the company's security and assurance commitments. * Experience in SaaS, life sciences, or other regulated environments preferred; CISSP, CISM, or a comparable security certification is a plus. ## Description Accumulus Technologies is seeking a Head of Information Security to lead the company's information security function across corporate operations and the Accumulus Platform. Reporting directly to the Chief Operating Officer, with direct access to executive leadership and the Board on material security matters, this leader will set security strategy, oversee governance, risk, and compliance, and represent Accumulus' security posture to customers, regulators, and other external stakeholders. You will lead the CyberDefense, Product Security, and GRC teams. Working with Engineering, Product, DevOps, IT, Legal, and Commercial, you will translate business priorities and security risks into a practical roadmap, establish clear control ownership, and hold teams accountable for delivery. This is a strategic and hands-on leadership opportunity for a security leader who combines technical judgment, operational discipline, and clear communication to protect the business, sustain assurance commitments, and build customer trust. Responsibilities * Own the corporate and product information security strategy, program, and annual objectives; define a prioritized roadmap and align security resources and investment needs with the COO. * Own the evolution of Accumulus' technical security capabilities across cloud infrastructure, product security, identity, vulnerability management, detection and response, and security architecture, prioritizing investment according to material business and cyber risk. * Lead and develop the CyberDefense and Product Security teams; set priorities, performance expectations, and accountability for internal staff and external providers. * Oversee the GRC program and delivery of audit coordination, evidence collection, policies, assessments, remediation tracking, and Vanta administration; retain accountability for program outcomes. * Maintain audit readiness and oversee required audits, certifications, and attestations, prioritizing current commitments and the effective operation of supporting controls. * Review material cyber risks, challenge risk ratings and treatment plans, approve security exceptions within delegated authority, and escalate business risk acceptance to executive leadership. * Partner with Engineering, Product, DevOps, and IT leadership to embed security in architecture, development, and operations; hold control owners accountable for effective safeguards and timely remediation. * Provide senior security direction during material incidents, authorize escalations, oversee lessons learned, and ensure incident response, disaster recovery, and business continuity capabilities are tested with accountable teams. * Resolve cross-functional security decisions affecting delivery, customer commitments, or business risk; escalate unresolved tradeoffs and investment needs to the COO and executive leadership. * Report security posture, material risks, incidents, remediation performance, emerging threats, and investment priorities to executive leadership and the Board, as appropriate. * Serve as Accumulus' senior security representative with customers, prospects, regulators, auditors, partners, and insurers; clearly explain the company's architecture, controls, certifications, risk posture, and regulatory environment. * Lead Accumulus' customer security assurance program, including strategic customer and prospect discussions, due diligence, RFPs, and security assessments; establish a scalable response process and ensure timely, accurate responses. ## Related Videos - [Shifting Stress to Progress— Understanding DevOps to do DevOps Better](https://www.wearedevelopers.com/videos/268-shifting-stress-to-progress-understanding-devops-to-do-devops-better) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Engineering/Manager Pendulum: Generating compound interest on your career](https://www.wearedevelopers.com/videos/100348-engineering-manager-pendulum-generating-compound-interest-on-your-career) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)