Apply Edge Start your job search

Director of Information Security

Ascendo Resources · Miami, FL

Apply & track with Apply Edge
Title: Director of Information SecurityLocation: Miami, FL (Doral area) / 100% onsiteDirect HireSalary: $170k - 190k/year + BenefitsJob DescriptionThe Director of Information Security leads the organization's information security program, ensuring the confidentiality, integrity, and availability of company data, systems, and networks. This role is responsible for setting the strategic direction of the security program, including Security Operations (SOC), Governance, Risk and Compliance (GRC), Data Governance, DevSecOps, and network security architecture and policy.The Director develops and enforces security policies, oversees risk management and incident response, manages relationships with auditors, regulators, and third-party providers, and partners with the network engineering function and executive leadership to align security initiatives with business objectives.ResponsibilitiesDefine, implement, and maintain the organization's information security strategy, policies, standards, and procedures, ensuring alignment with business objectives and regulatory requirements.Lead and develop the Information Security team, including supervisors, engineers, and analysts. Set goals, conduct performance reviews, mentor staff, and support professional development.Oversee the Security Operations Center (SOC), including monitoring, threat detection, incident response, and coordination with internal teams and external Managed Security Service Providers (MSSPs).Direct the Governance, Risk, and Compliance (GRC) program, including risk assessments, control testing, policy management, exception handling, and remediation tracking.Lead the Data Governance program, including data classification, data loss prevention, data retention, and privacy controls aligned with applicable regulations.Oversee DevSecOps practices, ensuring security is integrated into the software development lifecycle, infrastructure-as-code pipelines, and cloud deployments.Define and govern network security architecture, standards, and policy — including firewall, IDS/IPS, VPN, network segmentation, and zero trust requirements — partnering with the network engineering function that designs and operates the underlying infrastructure.Manage the information security budget, including operational expenditures, capital expenditure planning, and vendor and licensing agreements.Lead enterprise incident response activities, serving as the executive point of contact during significant security events, and coordinate communication with leadership, legal, and external parties as required.Establish and maintain key security metrics and dashboards, reporting regularly to the VP of Information Technology and other executive stakeholders on the state of the security program, key risks, and remediation progress.Manage internal and external audits and regulatory examinations, including evidence collection, response coordination, and remediation of findings.Evaluate, select, and manage relationships with security technology vendors, MSSPs, consultants, and other third parties.Stay current on emerging threats, technologies, regulations, and industry best practices, and recommend strategic adjustments to the security program accordingly.Partner with IT, Network Engineering, Legal, HR, Internal Audit, and business leaders to embed security and compliance considerations into enterprise initiatives, projects, and operations.Oversee security awareness and training programs to promote a strong security culture across the organization.Required QualificationsBachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field, with a minimum of ten (10) years of progressive experience in information security.Minimum of five (5) years of experience managing technical teams.Demonstrated experience leading enterprise security functions including Security Operations (SOC), Governance, Risk and Compliance (GRC), Data Governance, and DevSecOps.Strong knowledge of security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, PCI-DSS, SOX, and applicable data privacy regulations.Comprehensive understanding of network security architecture and security technologies, including next generation firewalls, intrusion detection and prevention systems, VPNs, network segmentation, zero trust architecture, SIEM, EDR/XDR, and identity and access management.Experience developing and managing departmental budgets, capital expenditure planning, vendor and contract management, and total cost of ownership analysis.Proven ability to lead incident response activities, including investigation, containment, eradication, recovery, and post-incident reporting to executive leadership.Experience supporting internal and external audits, regulatory examinations, and customer security assessments.Ability to translate complex technical risks into clear business language for executives, board members, and non-technical stakeholders.Strong written and verbal communication skills, with the ability to communicate effectively in English at all levels of the organization and at an advanced proficiency level.Ability to define problems, collect data, establish facts, and draw valid conclusions.Ability to work under pressure and in stressful scenarios, including during active security incidents.Ability to establish and maintain effective working relationships with executives, customers, vendors, auditors, and fellow employees.Ability to multitask and prioritize efficiently across a variety of strategic and operational issues.Ability to work a flexible schedule, extended hours, holidays, and/or weekends as needed, including on-call availability for security incidents.Preferred/PLUSMaster's degree in Cybersecurity, Information Systems, Business Administration, or a related field.Industry certifications such as CISSP, CISM, CISA, CRISC, CCSP, or equivalent.Experience in regulated industries (financial services, healthcare, energy, or similar) with exposure to compliance frameworks such as SOX, HIPAA, GLBA, or NERC-CIP.Experience presenting to executive leadership, audit committees, or boards of directors.Ability to verbally communicate in Spanish at an intermediate level.