Director of IT, Information Security & Data Privacy

๐Ÿข Energage ยท all Energage jobs
๐Ÿ“ United States
๐Ÿ’ฐ USD 175,000 - 185,000 / annual
๐Ÿ“… Posted 2026-08-14 ยท via Himalayas
๐Ÿท Infosec,Data-Privacy,Cybersecurity-Leadership,GRC,IT-leadership,Director-Of-IT-and-Security,Director-of-Information-Security,Director-Of-Data-Security,Information-Security-Director,Director-Of-Information-Technology,Senior-Director-IT-Infrastructure-And-Security,Information-Technology-Director,Senior-Data-Security-Director,Director-Of-Business-Information-Security,IT-Security-Director
Apply on original site โ†—

Director of Information Security & Data Privacy

Your Mission as Director of Information Security & Data Privacy

Energage is seeking a hands-on, strategic, and operationally strong Director of Information Security & Data Privacy to lead and mature the company's cybersecurity, information security, data privacy, governance, risk, and compliance programs. This leader will be responsible for protecting the company's information assets, maintaining customer trust, ensuring compliance with regulatory and industry standards, and enabling secure business growth in a fast-paced, high-growth SaaS environment. This role requires balancing strategic leadership with day-to-day operational execution while partnering closely with Product, Engineering, IT Operations, Legal, HR, and executive leadership. Reporting to the Chief Operating Officer (COO), this role will lead the company's Information Security, Data Privacy, Governance, Risk, and Compliance (GRC) functions while partnering closely with the IT Operations to ensure secure, reliable, and compliant technology operations.

Accountability & Impact: In this role, youโ€™ll...
Information Security

- Develop, implement, and continuously improve the company's Information Security strategy, roadmap, and security posture.

- Lead security operations, including:

- Identity and Access Management (IAM)

- Endpoint security

- Vulnerability management

- Threat detection and monitoring

- Incident response

- Security operations and continuous improvement

- Partner closely with Product and Engineering teams to integrate security into cloud infrastructure, applications, and the software development lifecycle.

- Develop, maintain, and enhance security policies, standards, procedures, and technical controls aligned with industry best practices.

- Lead the company's security awareness and education program.

- Support customer, partner, and enterprise security assessments and due diligence activities.

- Manage vendor security reviews, third-party risk assessments, customer security questionnaires, and remediation activities.

Data Privacy & Compliance

- Own and continuously evolve the company's Data Privacy and Governance program.

- Ensure compliance with applicable regulations and frameworks, including:

- ISO 27001

- SOC 2

- GDPR

- CCPA

- Other applicable privacy and security regulations

- Partner with IT Operations, Legal, HR, Product, Engineering, and business leaders to operationalize security and privacy requirements.

- Lead internal and external audits and maintain ongoing certification programs.

- Develop, maintain, and govern privacy policies, standards, procedures, and compliance documentation.

- Monitor evolving privacy regulations and recommend appropriate organizational changes.

Governance, Risk & Compliance

- Lead enterprise cybersecurity risk assessments and risk management activities.

- Develop security metrics, KPIs, dashboards, and executive reporting.

- Report security posture, compliance status, and enterprise risks to executive leadership.

- Lead third-party risk management and vendor security governance.

- Evaluate emerging technologies, cybersecurity threats, and AI-related risks.

- Establish governance processes that support secure business growth while balancing operational efficiency.

Strategic Leadership

- Serve as the company's trusted advisor on cybersecurity, privacy, compliance, and technology risk.

- Build strong partnerships across Product, Engineering, IT Operations, Legal, HR, and other business functions.

- Lead, mentor, and develop a high-performing Information Security and Data Privacy team.

- Build scalable security, governance, and compliance processes appropriate for a rapidly growing SaaS organization.

- Balance strategic planning with hands-on execution, remaining actively engaged in operational priorities when needed.

- Foster a collaborative, pragmatic, and solutions-oriented culture that enables business innovation whi

โ† All remote jobs