Apply Edge Start your job search

Director of Information Security

Optilogic · United States

Apply & track with Apply Edge

Who we are:Optilogic offers cloud-native supply chain network design solutions that enable businesses to evaluate trade-offs across financial performance, service levels, and systemic risk to design resilient supply chains even in the most dynamic, challenging environments. Its Cosmic Frog supply chain design solution tackles enterprise data at scale, runs models faster than ever, automatically converts legacy models, and requires no IT footprint. Cosmic Frog is the only supply chain design platform to combine optimization, simulation, and risk engines, and includes a risk rating on every scenario. Solutions include network design, intelligent greenfield analysis and site selection, M&A analysis, near-shoring/reshoring, CapEx planning, cost-to-serve, product flow, and many more.What we’re looking for:We are seeking an experienced and strategic Director of Information Security to join our dynamic and growing Optilogic team! In this role, you will be responsible for developing and leading our information security strategy across our cloud-native B2B SaaS environment. You will play a critical role in protecting Optilogic’s products, systems, data, and customers while enabling the company to scale securely.Reporting to the appropriate executive leadership, you will partner closely with Engineering, Product, IT, Legal, Compliance, and other cross-functional teams to establish and continuously improve Optilogic’s security program. This role will have a strong focus on security strategy, risk management, compliance, cloud security, application security, and building a security-first culture across the organization.If you are passionate about building modern security programs, solving complex problems, working in a fast-paced SaaS environment, and helping organizations securely leverage innovative technology – while looking to have some fun along the way – then we want to hear from you!What you’ll doInformation Security Strategy & Leadership:Develop and execute a comprehensive information security strategy aligned with Optilogic’s business objectives, technology environment, and growth.Establish security priorities, policies, standards, and programs that protect Optilogic’s products, infrastructure, data, and customers.Serve as a security subject matter expert and trusted advisor to executive leadership and cross-functional teams.Build and foster a security-first culture across the organization through education, awareness, and collaboration.Cloud & Infrastructure Security:Lead security strategy across Optilogic’s cloud-native infrastructure and SaaS environment.Partner with Engineering and Infrastructure teams to implement secure architecture, identity and access management, encryption, network security, secrets management, logging, monitoring, and vulnerability management.Establish and continuously improve security controls across cloud environments, applications, endpoints, and corporate systems.Evaluate emerging technologies and security solutions to improve Optilogic’s overall security posture.Application & Product Security:Partner closely with Engineering and Product teams to integrate security throughout the software development lifecycle (SDLC).Establish secure software development practices, including threat modeling, code security, dependency management, vulnerability remediation, and security testing.Drive application security reviews and risk assessments for new products, features, integrations, and technologies.Help ensure security is embedded into the development and deployment of Cosmic Frog and other Optilogic products.Risk Management & Compliance:Own and continuously improve Optilogic’s information security risk management program.Lead security compliance initiatives, including SOC 2 and other applicable security and privacy frameworks and customer requirements.Maintain and improve security policies, procedures, controls, and supporting documentation.Partner with Legal, Compliance, IT, and other teams to respond to customer security questionnaires, audits, assessments, and due diligence requests.Identify, assess, and prioritize security risks and develop mitigation strategies aligned with business objectives.Security Operations & Incident Response:Establish and maintain an effective security monitoring, detection, and incident response program.Lead the development and testing of incident response, business continuity, and disaster recovery processes related to information security.Coordinate the investigation, containment, remediation, and communication of security incidents.Establish appropriate metrics and reporting to monitor security program effectiveness and organizational risk.Third-Party & Data Security:Develop and oversee third-party security risk management and vendor assessment processes.Establish appropriate security requirements for vendors, partners, and technology providers.Partner with internal teams to ensure appropriate protection of customer, employee, and company data.Help establish and maintain data classification, retention, access, and protection standards.Security Awareness & Culture:Develop and maintain security awareness and training programs for employees.Promote security best practices across the organization and help employees understand their role in protecting Optilogic and its customers.Establish clear security expectations and processes that balance strong security with the needs of a fast-moving technology organization.Skills and Requirements: 2+ years of leadership experience directly managing security engineering, security operations, or GRC teams.4+ years of progressive information security experience spanning both technical security engineering functions and GRC.Demonstrated experience managing SOC 2, ISO 27001, or similar certification and audit processes from initiation through completion.Experience with international industry security standards (NIST, ISO, SOC 2) and data privacy regulations (GDPR, CCPA, and other regional standards).Education:Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field. Advanced degree or relevant security certifications are a plus.