Talent.com
Director of Information and Data Security
Director of Information and Data SecurityEltropy • Santa Clara, California, United States
Director of Information and Data Security

Director of Information and Data Security

Eltropy • Santa Clara, California, United States
job_description.job_card.30_days_ago
serp_jobs.job_preview.job_type
  • serp_jobs.job_card.full_time
job_description.job_card.job_description

Role Purpose

The Director of Information and Data Security will establish and lead Eltropy’s IT and

Cybersecurity function, responsible for developing foundational systems, processes, and

governance across infrastructure, data protection, and compliance. This leader will drive

security maturity across the organization, balancing hands-on execution with long-term

strategic planning, and partnering with external GRC consultants to build a scalable security

and compliance framework aligned with industry standards (e.g., SOC 2, ISO 27001).

Key Responsibilities

IT and Infrastructure Security

  • Oversee endpoint management, asset inventory, and identity and access management

(IAM).

  • Establish standards for device hardening, patch management, and secure configuration.
  • Define and manage the budget for all security and IT tools, services, and human capital,
  • ensuring cost-effectiveness and alignment with the overall security roadmap.

  • Implement centralized visibility and control across systems and SaaS applications.
  • Cybersecurity and Data Protection

  • Lead threat detection, vulnerability management, and incident response operations.
  • Implement and maintain a Cloud Security Posture Management (CSPM) solution to
  • monitor cloud infrastructure (AWS / Azure) for misconfigurations and compliance issues.

  • Deploy and tune SIEM / XDR solutions to enhance visibility and threat detection across
  • environments.

  • Conduct regular penetration testing, track remediation, and drive security awareness
  • programs.

  • Define and enforce data protection policies covering classification, encryption, and
  • retention.

    Governance, Risk, and Compliance (in partnership with GRC Consultant)

  • Partner with external GRC consultants to design and operationalize Eltropy’s information
  • security and compliance framework.

  • Translate consultant-driven recommendations into actionable internal controls, policies,
  • and monitoring mechanisms.

  • Manage the Third-Party Risk Management (TPRM) program, including vendor due
  • diligence, security questionnaires, and ongoing risk monitoring.

  • Maintain a centralized risk register and oversee remediation tracking.
  • Own operational compliance for frameworks such as SOC 2, ISO 27001, and GDPR.
  • Security Architecture and Product Collaboration

  • Work closely with Engineering and Product teams to embed security-by-design principles
  • in SaaS architecture and cloud deployments.

  • Implement automated security testing (SAST / DAST) within the CI / CD pipeline to shift
  • security left and reduce vulnerabilities early in the development lifecycle.

  • Review architecture and third-party integrations to ensure alignment with data security
  • and privacy standards.

    Incident Management and Business Continuity

  • Establish and operationalize the company’s Incident Response Plan (IRP) and Business
  • Continuity / Disaster Recovery (BCP / DR) framework.

  • Conduct tabletop exercises and post-incident reviews to enhance preparedness and
  • learning.

    Security Awareness and Culture

  • Develop and implement a company-wide security awareness program.
  • Partner with HR and Operations to ensure onboarding / offboarding includes security
  • compliance and periodic training.

  • Foster a security-first culture emphasizing accountability and vigilance across teams.
  • Leadership and Department Setup

  • Build and lead a high-performing IT and Security team, including IT administrators and
  • cybersecurity engineers.

  • Define structure, roles, and hiring priorities aligned with the company’s growth stage.
  • Create a phased roadmap for security maturity, including technology adoption and process optimization.
  • Key Performance Indicators (KPIs)

  • Vulnerability Remediation : Maintain average time-to-remediate critical and high
  • vulnerabilities below X days.

  • Compliance Milestones : Achieve SOC 2 / ISO 27001 readiness within agreed timelines.
  • Asset Visibility : 100% endpoint and asset inventory completeness.
  • Incident Management : Reduction in mean time to detect (MTTD) and mean time to
  • respond (MTTR) for incidents.

  • Team Ramp; Process Setup : Completion of key hires and operational processes within the first
  • year.

    Requirements

  • Independent, self-starter with strong ownership and execution bias.
  • Ability to prioritize and execute in a resource-constrained, fast-paced SaaS environment.
  • Strategic thinker with operational depth; able to balance long-term maturity goals with
  • immediate risk mitigation.

  • Excellent communication skills with the ability to influence and align cross-functional
  • stakeholders.

  • Proven experience setting up IT or cybersecurity programs in a SaaS or technology
  • environment.

  • Strong understanding of endpoint protection, cloud infrastructure security (AWS / Azure),
  • IAM, and network security.

  • Experience with SIEM and / or XDR deployment and tuning for threat detection and
  • monitoring.

  • Familiarity with CSPM, SAST / DAST, and vulnerability management tools.
  • Knowledge of GRC frameworks (SOC 2, ISO 27001) and translating them into practical,
  • auditable controls.

    Reporting to : VP of Operations

    Level : Senior Leadership

    Direct Reports :
  • IT Team
  • Cybersecurity Engineer(s)
  • serp_jobs.job_alerts.create_a_job

    Director Information Security • Santa Clara, California, United States

    Job_description.internal_linking.related_jobs
    Sr. Information Security Engineer (27639)

    Sr. Information Security Engineer (27639)

    Supermicro • San Jose, CA, United States
    serp_jobs.job_card.full_time
    Supermicro is a Top Tier provider of advanced server, storage, and networking solutions for Data Center, Cloud Computing, Enterprise IT, Hadoop / Big Data, Hyperscale, HPC and IoT / Embedded customers...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Director, Security

    Director, Security

    RUCKUS Networks • Sunnyvale, CA, United States
    serp_jobs.job_card.full_time
    In our ‘always on’ world, we believe it’s essential to have a genuine connection with the work you do.How You'll Help Us Connect The World. We're transforming from Ruckus 1.Lead the security transfo...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Director of Security & Privacy for AI Banking Platform

    Director of Security & Privacy for AI Banking Platform

    Interface AI • San Jose, CA, United States
    serp_jobs.job_card.full_time
    A pioneering financial technology company in San Francisco is seeking a Director of Security & Privacy Engineering to drive their security and privacy strategy. The ideal candidate will have over 12...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Director, Enterprise Data Management

    Director, Enterprise Data Management

    F5 • San Jose, CA, US
    serp_jobs.job_card.full_time
    Director Of Enterprise Data Management.At F5, we strive to bring a better digital world to life.Our teams empower organizations across the globe to create, secure, and run applications that enhance...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_1_day • serp_jobs.job_card.promoted
    Project (Information Systems) Mgr 3

    Project (Information Systems) Mgr 3

    eTeam Inc • Sunnyvale, California, United States
    serp_jobs.job_card.full_time
    serp_jobs.filters_job_card.quick_apply
    Title : Project Manager (Infrastructure / Security).Mode of interview : Zoom Video and onsite.Active PMP certificate required. Primary Function of this Position : .Manager of IT Infra & Security Proj...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30
    Director of Engineering Governance & Security

    Director of Engineering Governance & Security

    Menlo Ventures • Mountain View, CA, United States
    serp_jobs.job_card.full_time
    A leading data and AI company is seeking a Director of Engineering, Governance Foundation to shape security and privacy in product development. This role involves significant technical leadership, i...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Manager, Information Security - Detection Engineering

    Manager, Information Security - Detection Engineering

    LinkedIn • Sunnyvale, CA, United States
    serp_jobs.job_card.full_time
    LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exci...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Information Systems Security Manager (ISSM) II - Ramstein, Germany

    Information Systems Security Manager (ISSM) II - Ramstein, Germany

    General Dynamics Information Technology • Hayward, CA, United States
    serp_jobs.job_card.full_time
    Clearance Level Must Currently Possess : .Clearance Level Must Be Able to Obtain : .Information Security, Information Security Management, Information System Security. Information Systems Security Manag...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Director, Security Assurance, Kuiper Security

    Director, Security Assurance, Kuiper Security

    Jobright.ai • Sunnyvale, CA, United States
    serp_jobs.job_card.full_time +1
    Director, Security Assurance, Kuiper Security.Director, Security Assurance, Kuiper Security.Director, Security Assurance, Kuiper Security. Be among the first 25 applicants.Director, Security Assuran...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Director, Global SOX Compliance

    Director, Global SOX Compliance

    Supermicro • San Jose, CA, United States
    serp_jobs.job_card.full_time
    Supermicro is a Top Tier provider of advanced server, storage, and networking solutions for Data Center, Cloud Computing, Enterprise IT, Hadoop / Big Data, Hyperscale, HPC and IoT / Embedded customers...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Director of IT — Equity & Global Cloud-First Tech

    Director of IT — Equity & Global Cloud-First Tech

    Carta • Santa Clara, CA, United States
    serp_jobs.job_card.full_time
    A leading technology company in Santa Clara is seeking a Director of Information Technology.This role involves executing a comprehensive IT strategy while leading a customer-centric team focused on...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Director, Security

    Director, Security

    CommScope • Sunnyvale, CA, United States
    serp_jobs.job_card.full_time
    In our ‘always on’ world, we believe it’s essential to have a genuine connection with the work you do.How You'll help us connect the world : . We're transforming from Ruckus 1.Lead the security transf...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Information Security Engineer

    Information Security Engineer

    UNILIN • Palo Alto, CA, United States
    serp_jobs.job_card.full_time
    Within our Unilin Infrastructure team, we are looking for an.Unilin Group’s cybersecurity posture.You will be part of the Unilin Information Security team, part of the global Mohawk cybersecurity o...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Senior Director, Engineering — Cloud AI Security Platform

    Senior Director, Engineering — Cloud AI Security Platform

    Palo Alto Networks • Santa Clara, CA, United States
    serp_jobs.job_card.full_time
    A leading cybersecurity firm is seeking a Senior Director of Engineering to set the long-term technical vision for multiple teams. The ideal candidate will have over 15 years in software development...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_hours • serp_jobs.job_card.promoted • serp_jobs.job_card.new
    Director of Technology Platforms & Applications

    Director of Technology Platforms & Applications

    Cooley LLP • Palo Alto, CA, United States
    serp_jobs.job_card.full_time
    Director of Technology Platforms & Applications.Cooley is seeking a Director of Technology Platforms & Applications to join the. Technology Platforms and Applications.The Director of Technology Plat...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Director of Information Technology

    Director of Information Technology

    Carta • San Jose, CA, United States
    serp_jobs.job_card.full_time
    Carta connects founders, investors, and limited partners through world-class software, purpose-built for everyone in venture capital, private equity and private credit. Trusted by 65,000+ companies ...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted
    Director, Information Technology

    Director, Information Technology

    Calyxo, Inc. • Pleasanton, CA, United States
    serp_jobs.job_card.full_time
    The company was founded in 2016 to address the profound need for improved kidney stone treatment.Kidney stone disease is a common, painful condition that consumes vast amounts of healthcare resourc...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_30 • serp_jobs.job_card.promoted
    Senior Information Security Systems Engineer

    Senior Information Security Systems Engineer

    Leidos Inc • Mountain View, CA, United States
    serp_jobs.job_card.full_time
    Leidos is seeking a qualified Senior Information Systems Security Engineer (ISSE) to serve as the cybersecurity contact responsible for ensuring that assigned federal information systems comply wit...serp_jobs.internal_linking.show_more
    serp_jobs.last_updated.last_updated_variable_days • serp_jobs.job_card.promoted