> Markdown version of [/jobs/ext/597843-sr-director-of-information-security](https://www.wearedevelopers.com/jobs/ext/597843-sr-director-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Director of Information Security - **Company:** CHESS MEDICINE PLLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $200,000.0 - $215,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Spreadsheets, Cloud Computing Security, Cyber Security, Identity and Access Management, Python (Programming Language), Network Security, Log Analysis, Windows PowerShell, Security Information and Event Management, Scripting, Software Security, Firewalls (Computer Science), Legacy Systems, Vulnerability Analysis - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=878bfa9c15a82c23 ## About the Role Do you have experience in Supervising experience?, * Experience: 7+ years of progressive experience in cybersecurity, with at least 2+ years in a team leadership or supervisory role. * Cloud Security: Deep, practical knowledge of securing public cloud environments (AWS, Azure, or GCP). * SecOps & Architecture: Proven hands-on experience with firewalls, network security, penetration testing, endpoint protection, and log analysis. * Framework Fluency: Direct experience implementing and auditing frameworks such as SOC 2, NIST CSF, or ISO 27001. * Code/Scripting (Preferred): Ability to write basic scripts (Python, Bash, PowerShell) to automate security workflows is a major plus. Leadership & Soft Skills * The "Builder" Mentality: You thrive in ambiguity and enjoy building processes and teams from scratch rather than just maintaining legacy systems. * Communication: Ability to translate complex technical risks into clear, actionable business insights for non-technical executives. * Certifications: CISSP, CISM, CEH, or cloud-specific security certifications (e.g., AWS Certified Security) are highly desirable but secondary to proven, practical capability. ## Description We are seeking a dynamic, technical, and visionary Director of Information Security to design, build, and protect our digital ecosystem from the ground up. In this role, you won't just sit in a boardroom managing spreadsheets, you will be the primary architect of our security posture, acting as a player-coach. Initially, you will be deeply hands-on, assessing our current vulnerabilities, hardening our infrastructure, and implementing robust security frameworks. As you establish our baseline defense, you will have the mandate and budget to recruit, hire, and mentor a high-performing security team to scale our operations., Phase 1: Establish & Execute (Hands-On Focus) * Architect & Implement: Evaluate our current infrastructure, cloud (AWS/Azure/GCP) and on prem environments, and applications to design and deploy robust security controls. * Incident Response & Monitoring: Set up and manage SIEM, EDR, and vulnerability scanning tools. Act as the primary incident responder for any security anomalies. * Identity & Access Management: Audit and enforce strict IAM, PAM, and MFA protocols across all corporate and production systems. * Compliance & Governance: Align our security programs with industry standards (e.g., SOC 2, ISO 27001, NIST, HIPAA, or GDPR as applicable) and manage internal/external audits. Phase 2: Scale & Lead (Team Building Focus) * Talent Acquisition: Own the roadmap for security headcount. Source, interview, and hire specialized talent (e.g., SecOps, GRC, AppSec engineers). * Leadership & Mentorship: Define clear KPIs, foster a culture of continuous learning, and provide technical mentorship to your growing team. * Security Culture: Lead company-wide security awareness training and champion a "security-first" mindset across engineering and business operations. * Vendor & Budget Management: Evaluate and manage third-party security vendors, MSSPs, and tool budgets to optimize ROI. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Launching a marketplace on-time: A lesson in taking shortcuts using spreadsheets!](https://www.wearedevelopers.com/videos/477-launching-a-marketplace-on-time-a-lesson-in-taking-shortcuts-using-spreadsheets) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [From Global Capability Centers to AI-Powered Command Centers](https://www.wearedevelopers.com/videos/100096-from-global-capability-centers-to-ai-powered-command-centers) - [MCP doesn’t suck — your agent does](https://www.wearedevelopers.com/videos/100202-mcp-doesn-t-suck-your-agent-does) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)