Director of Information Security
Collectors
hybridleadpermanentsecurityengineering-management Full remote Today via WTTJ
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
Information SecuritySecurity OperationsAppSecCloud SecurityGRCSOC 2ISO 27001NIST CSFIncident ResponseAWS
About the role
Role overview
Lead and execute Collectors’ information security program across application security (AppSec), cloud security, security operations (SecOps), and GRC. Act as the operational leader that refines the security roadmap into measurable outcomes while partnering closely with engineering, IT, legal, and privacy stakeholders.
Key missions & responsibilities
- Information Security Program Leadership: Own the security program and drive security roadmap execution across AppSec, CloudSec, SecOps/IR, and GRC.
- Security Operations (SecOps): Lead detection and response, threat intelligence, incident management, and improve SOC maturity to identify, contain, and recover from security events.
- Application Security (AppSec): Embed secure development practices into the SDLC, including code analysis tooling and vulnerability management, in partnership with product and platform engineering teams.
- Cloud Security: Establish and evolve cloud security capabilities.
- GRC / Risk & Compliance:
- Manage governance, risk, and compliance activities.
- Build and maintain a security risk register.
- Define, track, and communicate security KPIs and program metrics.
Requirements
- 10+ years in information security, including 5+ years leading security teams across multiple disciplines.
- 2+ years managing managers or cross-functional security functions.
- Strong hands-on credibility in cloud and application security, including familiarity with:
- AWS, Azure, or GCP
- Modern application architectures
- CI/CD pipelines
- Container-based workloads
- Breadth across AppSec, CloudSec, SecOps/IR, and GRC, with the ability to operate across domains without losing depth.
- Experience leading organizations through SOC 2, ISO 27001, NIST CSF, HITRUST, or similar frameworks; able to manage audit cycles and regulatory requirements.
- Strong background in incident response and building metrics-driven detection and response capabilities; experience overseeing SOC, detection engineering, and IR.
- Ability to translate executive priorities into roadmaps, operationalize security strategy, and clearly surface risk to technical and non-technical audiences.
- Strong people leadership and communication skills; confident briefing of executives and collaboration with engineering and cross-functional partners.
Nice to have / stated preferences
- Metrics- and outcome-driven leadership.
- Willingness to support in-person collaboration: if you live within a 1-hour commute to an office, you’ll be required to be onsite most of the time.
About Collectors
Collectors is a company in the collectibles industry. It’s hiring a senior security leader to run end-to-end information security, from security operations and app/cloud security to governance, risk, and compliance.
Scraped 7/30/2026