A fast‑growing software organization in the self‑funded medical benefits ecosystem is seeking a Director of Information Security to own the security program end to end. This leader will set strategy, build governance, oversee tooling, manage certifications, and represent security directly to clients, auditors, and executive leadership. The role reports to the CTO and manages a Security Analyst responsible for day‑to‑day monitoring and compliance operations.
Location
Atlanta, GA (Hybrid: Tuesday–Thursday in office)
Primary Responsibilities
Security Strategy, Policy, and Governance
- Own the full information security strategy, policies, and control framework.
- Maintain policies aligned to SOC 2 and HITRUST while reflecting real operational practices.
- Select and maintain a control framework such as NIST CSF or ISO 27001.
- Maintain the risk register and drive remediation through completion.
Security Architecture and Tooling
- Own the security tooling roadmap across endpoint, cloud, identity, network monitoring, and collaboration security.
- Oversee tools such as Darktrace, CrowdStrike, and related platforms.
- Evaluate, select, and manage vendor relationships with an eye toward cost, coverage, and operational fit.
- Partner with Engineering on secure‑by‑design practices.
Compliance and Certification Oversight
- Serve as executive owner of SOC 2 Type II and HITRUST programs.
- Lead audit strategy and act as primary contact for auditors and assessors.
- Direct and develop the Security Analyst responsible for evidence collection and control testing.
- Ensure certifications are maintained continuously.
Client and Vendor Security Risk Management
- Own the full process for client security questionnaires and due‑diligence requests.
- Build scalable response processes including knowledge bases, workflow tooling, and SLAs.
- Partner with Sales and Legal on security‑related contract terms.
- Manage third‑party and vendor security risk assessments.
Emerging AI Security and Governance
- Track evolving AI threats and regulatory guidance.
- Own acceptable‑use policy for AI tools internally and within product functionality.
- Build lightweight AI vendor risk assessment processes.
Incident Response and Resilience
- Maintain and evolve the incident response plan.
- Lead response efforts for any security incident, including remediation, communication, and regulatory coordination.
- Conduct tabletop exercises with engineering and leadership.
Team Leadership and Reporting
- Manage and develop the Security Analyst.
- Report regularly to the CTO and periodically to the CEO or board on posture, audit outcomes, and material risks.
Qualifications
Required
- 8+ years in information security, including 2+ years owning a security program.
- Direct experience with SOC 2 Type II and/or HITRUST.
- Hands‑on familiarity with modern security tooling across endpoint, cloud, network, and identity.
- Experience managing high‑volume client/vendor security questionnaires.
- Experience building or maturing security policy from a less‑mature baseline.
- Strong written and verbal communication skills.
Preferred
- Experience in regulated environments such as healthcare, insurance, or financial services.
- Prior involvement in breach response and post‑incident remediation.
- Working knowledge of emerging AI security frameworks (OWASP, NIST).
- Certifications such as CISSP, CISM, or CCSP.
- Experience in small, fast‑moving software organizations.