- Salary
- $175k – $185k
- Location
- Exton, PA · Exton, Pennsylvania, United States
- Department
- IT Ops
- Seniority
- Director
- Source
- Greenhouse
Description
Director of Information Security & Data Privacy
Your Mission as Director of Information Security & Data Privacy
Energage is seeking a hands-on, strategic, and operationally strong Director of Information Security & Data Privacy to lead and mature the company's cybersecurity, information security, data privacy, governance, risk, and compliance programs. This leader will be responsible for protecting the company's information assets, maintaining customer trust, ensuring compliance with regulatory and industry standards, and enabling secure business growth in a fast-paced, high-growth SaaS environment. This role requires balancing strategic leadership with day-to-day operational execution while partnering closely with Product, Engineering, IT Operations, Legal, HR, and executive leadership. Reporting to the Chief Operating Officer (COO), this role will lead the company's Information Security, Data Privacy, Governance, Risk, and Compliance (GRC) functions while partnering closely with the IT Operations to ensure secure, reliable, and compliant technology operations.
Accountability & Impact:
In this role, you’ll...
Information Security
- Develop, implement, and continuously improve the company's Information Security strategy, roadmap, and security posture.
- Lead security operations, including:
- Identity and Access Management (IAM)
- Endpoint security
- Vulnerability management
- Threat detection and monitoring
- Incident response
- Security operations and continuous improvement
- Partner closely with Product and Engineering teams to integrate security into cloud infrastructure, applications, and the software development lifecycle.
- Develop, maintain, and enhance security policies, standards, procedures, and technical controls aligned with industry best practices.
- Lead the company's security awareness and education program.
- Support customer, partner, and enterprise security assessments and due diligence activities.
- Manage vendor security reviews, third-party risk assessments, customer security questionnaires, and remediation activities.
Data Privacy & Compliance
- Own and continuously evolve the company's Data Privacy and Governance program.
- Ensure compliance with applicable regulations and frameworks, including:
- ISO 27001
- SOC 2
- GDPR
- CCPA
- Other applicable privacy and security regulations
- Partner with IT Operations, Legal, HR, Product, Engineering, and business leaders to operationalize security and privacy requirements.
- Lead internal and external audits and maintain ongoing certification programs.
- Develop, maintain, and govern privacy policies, standards, procedures, and compliance documentation.
- Monitor evolving privacy regulations and recommend appropriate organizational changes.
Governance, Risk & Compliance
- Lead enterprise cybersecurity risk assessments and risk management activities.
- Develop security metrics, KPIs, dashboards, and executive reporting.
- Report security posture, compliance status, and enterprise risks to executive leadership.
- Lead third-party risk management and vendor security governance.
- Evaluate emerging technologies, cybersecurity threats, and AI-related risks.
- Establish governance processes that support secure business growth while balancing operational efficiency.
Strategic Leadership
- Serve as the company's trusted advisor on cybersecurity, privacy, compliance, and technology risk.
- Build strong partnerships across Product, Engineering, IT Operations, Legal, HR, and other business functions.
- Lead, mentor, and develop a high-performing Information Security and Data Privacy team.
- Build scalable security, governance, and compliance processes appropriate for a rapidly growing SaaS organization.
- Balance strategic planning with hands-on execution, remaining actively engaged in operational priorities when needed.
- Foster a collaborative, pragmatic, and solutions-oriented culture that enables business innovation while managing risk.
Leadership Competencies
- Hands-on leader who combines strategic vision with operational execution.
- Strong communicator capable of influencing executive leadership, technical teams, and non-technical stakeholders.
- Collaborative leader who builds trusted partnerships across the organization.
- Calm, decisive, and effective during security incidents and high-pressure situations.
- Strong analytical, organizational, and problem-solving skills.
- Passion for building scalable, secure, and efficient processes that enable business growth.
- Committed to mentoring and developing high-performing teams.
Qualifications
What You Bring to the Role:
- 10+ years of progressive Information Security, Cybersecurity, and Data Privacy leadership experience.
- 5+ years of director-level or senior leadership responsibility.
- Proven experience leading Information Security and Data Privacy programs within a fast-paced, high-growth SaaS or cloud-native organization.
- Strong hands-on technical expertise in:
- Cloud security (AWS and/or Azure)
- Identity and Access Management (IAM)
- Security operations
- Vulnerability management
- Endpoint security
- Security monitoring and incident response
- Demonstrated success building, mentoring, and leading high-performing technical teams.
- Deep knowledge of cybersecurity frameworks, risk management, privacy regulations, and security best practices.
- Proven success achieving, maintaining, and continuously improving ISO 27001, SOC 2, and similar compliance and certification programs.
- Experience implementing and managing modern security technologies in cloud-based environments.
- Strong project management, organizational, communication, and cross-functional leadership skills.
Nice to haves:
- Experience supporting hybrid and remote work environments.
- Experience collaborating with Product and Engineering organizations to embed security into cloud-native application development.
- Familiarity with modern SaaS technology ecosystems and cloud security platforms.
- CISSP, CISM, CRISC, or comparable industry certifications.
- Experience supporting mergers and acquisitions, organizational scaling, or rapid business growth.
- Experience developing governance for emerging technologies, including AI.
Compensation and Benefits:
The base pay range for this role is $175,000 - $185,000. The base pay range is dependent on factors including, but not limited to, experience, skills, qualifications, relevant education, certifications, seniority, and location. The range listed is just one component of the total compensation package for employees. Other rewards vary by position"
In addition to base pay, our total rewards package includes:
- PTO policy includes company holidays, sick time, vacation time, and floating holidays
- Remote
- Company pays a portion of individual health care premium
- Option to participate in a company-sponsored 401(k)
- Training and education
- Professional development; all employees have access to a third party professional coach
- Tuition reimbursement program
- Opportunity to work for a purpose-driven organization using business as a force for good (https://www.bcorporation.net/)
Energage is a hybrid/remote workplace with employees in various US locations. While our employees enjoy the flexibility of daily remote work, they are also given the occasional opportunity for in person interaction. This includes in our office in Exton Pa, or in a coworking space/out in their local area. This role is available for remote work in the following states:
- Arizona
- Delaware
- Florida
- Georgia
- Maryland
- Michigan
- North Carolina
- Nebraska
- New Jersey
- New York STATE (NYC residents excluded)
- Pennsylvania
- South Carolina
- Tennessee
- Texas
- Wisconsin
If you reside outside of the above locations, you will not be considered for this role.
About Energage:
Energage is a purpose-driven company that helps organizations turn employee feedback into useful business intelligence and credible employer recognition through Top Workplaces. Built on 19 years of culture research and the results from 23 million employees surveyed across more than 70,000 organizations, Energage delivers the most accurate competitive benchmark available. With access to a unique combination of patented analytic tools and expert guidance, Energage customers lead the competition with an engaged workforce and an opportunity to gain recognition for their people-first approach to culture. For more information or to nominate your organization, visit energage.com or topworkplaces.com.
Energage is committed to fostering a diverse and inclusive environment. We are proud to be an equal opportunity employer. Energage encourages all qualified candidates to apply, including those of any race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.