Director of Information Security
Collectors · United States
About The Role
Join Collectors, a leading company in the collectibles industry, as the Director of Information Security. In this role, you will lead the information security program, oversee security operations, drive the application security program, establish cloud security capabilities, and manage governance, risk, and compliance activities. You will collaborate cross-functionally with engineering, IT, legal, and privacy stakeholders to embed security into organizational processes and decision-making. Additionally, you will build and maintain the organization's security risk register and define and track security KPIs and program metrics. This is a high-impact role that requires a strong background in information security and leadership experience.
- Lead the information security program across application security, cloud security, security operations, and GRC, serving as the operational leader responsible for refining and driving the information security roadmap into executed outcomes.
- Own the security operations function, including detection and response, threat intelligence, incident management, and SOC maturity, ensuring the organization can rapidly identify, contain, and recover from security events.
- Drive the application security program, embedding secure development practices, code analysis tooling, and vulnerability management into the SDLC in close partnership with product and platform engineering teams.
- We believe that there is significant value in in-person collaboration. If you live within a 1 hour commuting distance to one of our offices, you will be required to be onsite most of the time
- Metrics-oriented and outcome-driven. You use data to measure program health, prioritize investment, and communicate risk to technical and non-technical audiences alike
- Technically credible in cloud and application security. You have hands-on familiarity with securing cloud environments (AWS, Azure, or GCP), modern application architectures, CI/CD pipelines, and container-based workloads, and you can engage meaningfully with engineering teams on technical trade-offs
- Broad and deep across the security domain. You've built or matured programs spanning AppSec, CloudSec, SecOps/IR, and GRC — and you're comfortable operating across all of them without losing depth in any single area
- Well-versed in governance and compliance frameworks. You've led organizations through SOC 2, ISO 27001, NIST CSF, HITRUST, or similar frameworks and can manage audit cycles and regulatory requirements without letting compliance become the sole definition of security
- Strong in security operations and incident response. You've led or directly overseen SOC teams, detection engineering, and incident response processes, and you understand what it takes to build a mature, metrics-driven detection and response capability
- An experienced security leader with 10+ years in information security, including 5+ years leading security teams across multiple disciplines and at least 2+ years managing managers or cross-functional security functions
- A strategic partner to the CISO. You're skilled at operationalizing security strategy, translating executive-level priorities into roadmaps and team-level execution, and surfacing risk with clarity and context
- A strong people leader and culture builder. You attract and retain top security talent across disciplines, create clear career pathways, and foster an environment where analysts, engineers, and GRC professionals all feel ownership over the mission
- A clear, confident communicator who can brief executives on risk posture, walk engineering teams through threat models, and represent the security organization in cross-functional forums with equal effectiveness
- Collaborative by default. You build productive relationships with engineering, IT, legal, and privacy teams, and you approach security as an enabling function rather than a blocker — while still holding firm on non-negotiable standards
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring