Director of Information Security

PCC Technology Inc.
Heathrow, FL, United States
about 1 month ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Amazon Web Services Software System Penetration Testing Microsoft Azure Software as a Service Cloud Computing Cloud Computing Security Cloud Engineering Static Program Analysis Code Review Cyber Security Continuous Integration
+15 more
Identity and Access Management Information Security Management Open Web Application Security Systems Development Life Cycle Zero Trust Network Access Web Application Security Security Information and Event Management Software Engineering Software Vulnerability Management EndPointSecurity Policy as Code Software Security CIS Benchmarks Devsecops Security Orchestration, Automation & Response

Job description

The Director of Information Security is responsible for leading Civix’s enterprise information security program across corporate systems, cloud infrastructure, SaaS products, and customer-facing security initiatives. This leader partners closely with Engineering, Product Management, Cloud Operations, Compliance, Customer Success, and Executive Leadership to ensure security is embedded throughout the software development lifecycle while maintaining a strong internal security posture.

This role owns the strategic direction, governance, and operational execution of the company’s security program, including compliance initiatives, security operations, product security, security awareness, and incident response. The Director will lead a team of security professionals while serving as the primary security advisor for customers, auditors, vendors, and executive leadership. This is a hands-on leadership role in a scaling organization; the Director is expected to both lead and directly contribute where needed.

This position reports directly to the CTO. Requirements:

Security Strategy & Leadership

  • Develop and execute the company’s enterprise information security strategy.
  • Establish security policies, standards, procedures, and governance practices.
  • Partner with executive leadership to assess and mitigate enterprise risk.
  • Build and mentor a high-performing Information Security team.
  • Establish security metrics and regularly report program health to executive leadership.
  • Foster a culture where security is viewed as a business enabler rather than a gatekeeper.
  • Define security requirements that are binding across Engineer, Product, and IT.
  • Own security budget, tooling selection, and staffing roadmap.

Product & Application Security

  • Lead product security initiatives across Civix’s SaaS portfolio.
  • Partner with Engineering leadership to integrate security throughout the SDLC.
  • Drive secure software development practices and developer enablement.
  • Oversee vulnerability management, code scanning, penetration testing, and remediation prioritization.
  • Guide threat modeling and architecture reviews for new products and major initiatives.
  • Establish application security standards across multiple development organizations.
  • Balance product velocity with risk-based security decision-making.
  • Drive automation-first security, CI/CD integration, policy-as-code, and continuous compliance

Governance, Risk & Compliance

  • Own enterprise compliance initiatives including:
  • SOC 2
  • FedRAMP readiness and supporting programs
  • CJIS-related security controls
  • Customer security assessments
  • Internal security audits
  • Manage security policies and control frameworks.
  • Coordinate external auditors and compliance partners.
  • Track remediation efforts and ensure timely closure of findings.
  • Partner with Legal and Compliance on customer contractual security requirements.
  • Maintain formal enterprise risk management framework alignment with NIST 800-53

Security Operations

  • Oversee enterprise vulnerability management.
  • Lead incident response planning and execution.
  • Coordinate security monitoring and investigation activities.
  • Direct third-party security testing and remediation efforts.
  • Oversee identity and access management security practices.
  • Ensure continuous improvement of operational security controls.
  • Building guardrails and automation vs manual gatekeeping.

Customer & Election Security

  • Support high-profile customer implementations and critical election events where security readiness is essential.
  • Act as executive face of for customers, including high-trust government and elections clients.
  • Assist Sales and Customer Success with security questionnaires and customer due diligence.
  • Partner with Product and Engineering to ensure customer-facing security commitments are achieved.
  • Ability to translate complex security concepts into customer confidence.

Vendor & Third-Party Security

  • Serve as primary security contact for security vendors, auditors, and strategic partners.
  • Oversee third-party security assessments.
  • Evaluate security technologies and recommend investments.
  • Manage relationships with penetration testing firms and compliance partners.

Security Awareness & Organizational Enablement

  • Lead company-wide security awareness and training initiatives.
  • Build secure development education programs.
  • Promote security-first thinking throughout the organization.
  • Provide coaching and guidance to engineering leaders on security prioritization and best practices.

Leadership Responsibilities

  • Lead and mentor Information Security Analysts and Engineers.
  • Establish goals, career development plans, and performance expectations.
  • Build scalable security processes that support organizational growth.
  • Collaborate across Engineering, Product, Cloud Operations, Customer Success, and Corporate IT.
  • Influence without authority across multiple organizations., * Maintain and mature Civix’s enterprise security posture.
  • Successfully lead SOC 2 and FedRAMP-related initiatives.
  • Reduce organizational risk through proactive security leadership.
  • Improve security maturity across products and engineering teams.
  • Build strong partnerships with customers and internal stakeholders.
  • Establish a security organization that enables product delivery while maintaining high standards of governance and compliance.
  • Mentor and develop a highly effective security team.
  • Serve as a trusted advisor to executive leadership on all matters related to cybersecurity, compliance, and enterprise risk.

Requirements

Do you have experience in Web Application Security Testing?, Required

  • 10+ years of progressive Information Security experience.
  • 5+ years leading Information Security teams.
  • Experience securing cloud-native SaaS platforms (AWS preferred).
  • Strong understanding of modern application security practices.
  • Experience leading enterprise compliance programs including SOC 2.
  • Experience supporting or preparing organizations for FedRAMP or comparable government security frameworks.
  • Experience managing vulnerability management and remediation programs.
  • Knowledge of secure software development practices.
  • Experience responding to customer security assessments and audits.
  • Strong executive communication skills.
  • Demonstrated ability to balance security, business objectives, and customer needs.

Preferred

  • Experience in GovTech, LegalTech, Elections, or regulated SaaS industries.
  • Experience with CJIS, NIST 800-53, CIS Controls, OWASP, and Zero Trust principles.
  • Familiarity with DevSecOps practices and cloud security tooling.
  • Experience supporting enterprise customers during critical production events.
  • Professional certifications such as CISSP, CISM, CCSP, GIAC, or equivalent.

Technical Experience

Experience with many of the following is preferred:

  • AWS Security Services
  • Microsoft Azure security
  • IAM / SSO / MFA
  • Vulnerability Management Platforms
  • SIEM/SOAR solutions
  • Endpoint Detection & Response
  • Static and Dynamic Code Analysis
  • Container Security
  • Infrastructure as Code security
  • Security automation
  • Incident Response tooling
  • FedRAMP and NIST control implementation

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:32 min

Decoupling business logic with policy as code

Anderson Dadario +1 · LIVE

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:31 min

Enforcing compliance with guardrails and policy as code

Martin Reynolds Martin Reynolds · World Congress 2025

Videos

See all

Related articles

See all