Apply Edge Start your job search

Director of Information Security

FTS, Inc. · Kennesaw, GA

Apply & track with Apply Edge
Our client, a financial services SaaS company, is looking for a hands-on security leader to build and own their information security program end to end. This is a program-building role for someone who wants full ownership — from policy and control framework through tooling, certifications, incident response, and team leadership — at a company operating under real regulatory and client scrutiny (SOC 2 Type II and HITRUST). You'll report directly to the CTO and periodically brief the CEO and/or board on program status and risk posture.Security Program & GovernanceChoose and maintain an internal control framework (e.g., NIST CSF or ISO 27001) that gives the security program a clean structure, allowing controls to map consistently across SOC 2, HITRUST, and client contract obligationsKeep the risk register current and push identified gaps through to actual resolution, not just documentationSecurity Architecture & ToolingOwn the full security tooling roadmap — endpoint protection, cloud security posture, IAM, network monitoring (including Darktrace, CrowdStrike, and other tools currently managed by the Security Analyst), and email/collaboration securityEvaluate, select, and manage security vendor relationships, weighing coverage against cost and operational lift appropriate for a lean engineering teamWork with Engineering leadership to build secure-by-design principles into the product development lifecycleCompliance & Certification OversightAct as executive owner of the SOC 2 Type II and HITRUST certification programs — setting audit strategy and serving as the primary contact for auditors and assessorsManage and grow the Security Analyst, who handles day-to-day compliance monitoring, evidence collection, and control testingKeep certifications continuously maintained rather than rebuilt from scratch each cycleClient & Vendor Security Risk ManagementOwn the full lifecycle of client and prospect security questionnaires and due-diligence requests, building a scalable response system (knowledge base, workflow tooling, SLAs) instead of answering everything from a blank pageCollaborate with Sales and Legal on security-related contract language, and speak directly to the company's security posture on prospect and client calls when neededOwn third-party/vendor security risk assessments for the company's own suppliers and subprocessorsEmerging AI Security & GovernanceStay current on the evolving AI threat and regulatory landscape — including risks tied to LLMs and AI-assisted development tools — and turn that into practical internal policyOwn the company's acceptable-use policy for AI tools, covering both internal employee use and any AI functionality built into the company's productBuild a lightweight risk assessment process for evaluating third-party AI tools or subprocessors the company adoptsIncident Response & ResilienceOwn and maintain the incident response plan, including running tabletop exercises with engineering and leadershipLead the response to any security incident — technical remediation, internal communication, and coordination of legal/customer/regulatory notification requirements alongside Legal and executive leadershipTeam Leadership & ReportingDirectly manage and develop the Security AnalystProvide regular program updates to the CTO, and periodic security posture, audit outcome, and risk briefings to the CEO and/or boardQualifications8+ years in information security, with 2-3+ years leading a security program end to end (Sr. Manager, Director, Head of Security, or CISO level)Direct experience operating under SOC 2 Type II and/or HITRUST CSF, including working with external auditors through a full certification or renewal cycleHands-on experience across a modern security stack — endpoint, network/cloud monitoring, and IAM — with the ability to evaluate and direct tooling decisions, not just monitor dashboardsExperience managing high-volume client/vendor security questionnaires or due-diligence in a B2B software or SaaS environmentTrack record building or maturing a security program from a less established baseline — this is a build role, not a maintenance roleStrong written and verbal communicator, comfortable representing security to clients, auditors, and executive leadershipPreferred QualificationsExperience in a regulated space adjacent to healthcare, insurance, or financial servicesPrior experience leading or significantly contributing to breach/incident response and post-incident remediationFamiliarity with emerging AI security frameworks (e.g., OWASP LLM guidance, NIST AI risk management) and how to translate them into internal policyCISSP, CISM, or CCSP certificationExperience at a similarly sized company — scaling a security function from one or two people