Head of Security

Security EngineerSecurity EngineerFull TimeRemote

Location

United States

Posted

9 days ago

Salary

Not specified

No structured requirement data.

Job Description

Head of Security


Role purpose


Own the organization’s security posture end-to-end. The Head of Security sets strategy,
standards and day-to-day execution across information security, application security,
infrastructure security and (where applicable) physical security. The role balances risk reduction
with business enablement - making security practical, measurable and scalable.

Key responsibilities

1) Security strategy & governance
● Define and maintain the security strategy, roadmap and operating model aligned to the
business goals.
● Establish security policies, standards and secure-by-default guardrails.
● Define and enforce data protection and encryption standards.
● Create security metrics/KPIs and executive reporting.

2) Risk management
● Run an enterprise risk assessment process.
● Assess and prioritize risks across systems, vendors and business processes.
● Own security exception handling and ensure compensating controls are documented
and monitored.

3) Incident response & resilience
● Own the incident response program: playbooks, on-call procedures, tabletop exercises,
evidence handling, postmortems.
● Lead response to security incidents (containment, eradication, recovery) and coordinate
internal/external stakeholders.
● Improve resilience through backups, disaster recovery testing and security
monitoring/alerting.

4) Security operations
● Implement and oversee controls such as IAM, MFA, least privilege, endpoint security,
patching and secure configuration baselines.
● Operate vulnerability management (scanning, triage, remediation SLAs) and penetration
testing coordination.
● Protection and monitoring of sensitive data: implement and operate controls to prevent
unauthorized access, misuse or exfiltration.
● Maintain logs/SIEM, detection engineering and continuous monitoring where
appropriate.

5) Product & application security
● Embed security into SDLC: secure coding standards, code scanning, dependency
management, secrets handling, CI/CD controls.
● Perform/enable threat modeling and security reviews for new features and architectural
changes.
● Drive remediation of application and infrastructure findings with engineering teams.

6) Vendor & third-party security
● Own third-party risk management: due diligence, security questionnaires,
contract/security addendums, ongoing monitoring.
● Ensure vendors meet security requirements and that data-sharing is controlled and
auditable, including encryption and data handling expectations for sensitive data.

7) Security culture & training
● Build a strong security culture via training, phishing simulations and clear processes.

8) Budget, team & leadership
● Build and manage the security budget (tools, vendors, staffing) and justify investments
based on risk and ROI.
● Hire, develop and manage security staff and/or MSSP relationships.
● Establish clear SLAs and service ownership across security domains.

Required experience & skills
● Strong understanding of cloud security (AWS/Azure/GCP), IAM, network security and
endpoint security.
● Strong understanding of data protection and encryption practices.
● Proven incident response leadership and ability to manage crisis communications.
● Ability to translate technical risk into business impact and make pragmatic
recommendations.
● Experience building security programs, policies and metrics from scratch or scaling
them.
● Strong stakeholder management, vendor negotiation and executive communication



Location

Remote


Department

IT


Employment Type

Full-Time


Minimum Experience

Manager/Supervisor


Related Categories

Related Job Pages

More Security Engineer Jobs

Senior Manager, Information Security Officer

Paytient

Paytient Health Payment Accounts help people better access and afford care.

Security Engineer9 days ago
Full TimeRemoteTeam 51-200Since 2018H1B No Sponsor

This is a hands-on role for a highly motivated and experienced Information Security Officer. In this quickly developing organization, you will be expected to be a strong team player who can also independently drive key security initiatives as the information security department m...

United States

Manager of Information Technology

OpenSesame

We help companies develop the world's most productive and admired workforces.

Security Engineer9 days ago
Full TimeRemoteTeam 51-200Since 2011H1B No Sponsor

About OpenSesame OpenSesame is the trusted partner for Workforce Reinvention in the age of AI. OpenSesame delivers integrated software, curated and customizable content, and expert services – embedded into existing learning, HR, and work systems – to help organizations expand the...

United States
Security Engineer9 days ago
Full TimeRemote

What we are looking for: A Service technician who installs, services and repairs commercial laundry equipment including washers, dryers, ironers and other related machinery. Before we continue to dive into the requirements for the role let’s talk about Why you should join Laundry...

United States
Full TimeRemoteTeam 51-200

The Senior Security Officer will serve as the Facility Security Officer (FSO), managing all security aspects for the IDE contract and ensuring compliance with DoD and Service regulations. Key duties include maintaining the SECRET facility clearance, managing personnel clearances via DISS/NBIS, and establishing a COMSEC account.

United States