About The Position

We're looking for a Director of Information Security to lead and mature our security program at a critical inflection point. We've already achieved ISO 27001 and SOC 2 Type 1 certifications — the foundation is in place. Now we need a hands-on leader who can turn that foundation into a durable, well-run program: formalizing policies and procedures, building a high-functioning security team, and protecting our infrastructure, networks, cloud environments, and applications — all without slowing down the engineers and developers who build our products. This is not a "policy for policy's sake" role. You'll be the person who makes security a natural part of how we build software, not an obstacle to it.

Requirements

  • Bachelor's degree in Information Security, Computer Science, Computer Engineering or related field or equivalent work experience
  • 10+ years in information security, with 3+ years in a leadership role owning a security program end-to-end.
  • Direct experience operating within (not just achieving) ISO 27001 and SOC 2 frameworks — you know what "audit-ready" looks like day to day, not just at renewal time.
  • Strong technical depth in cloud security (AWS/GCP), network security, and modern application security (SDLC, AppSec tooling, container/Kubernetes security a plus).
  • Experience building or rebuilding policies and procedures from the ground up in a scaling SaaS environment.
  • A track record of leading security teams that engineers actually like working with — you understand that unenforced policy is theater, and that adoption comes from good tooling and clear communication, not mandates.
  • Experience managing external auditors, penetration testers, and compliance vendors.
  • Excellent communication skills — able to flex between a whiteboard session with engineers and a risk briefing with the board.

Nice To Haves

  • CISSP, CISM, or similar certification.
  • Experience implementing or operating under ISO 27701 (privacy extension to 27001) and the NIST Cybersecurity Framework (CSF).
  • Experience in a company of similar size/stage (post-certification, scaling team).

Responsibilities

  • Own and mature the information security program, ensuring full alignment with ISO 27001 and SOC 2 requirements, including the transition to SOC 2 Type 2.
  • Author, formalize, and maintain the policies, standards, and procedures required to close any remaining gaps and sustain certification readiness (risk management, access control, incident response, vendor/third-party risk, change management, business continuity, etc.).
  • Run the internal control environment: risk assessments, control testing, audit evidence collection, and remediation tracking.
  • Manage relationships with external auditors, pen testers, and compliance partners.
  • Own the security of infrastructure, networks, cloud environments (AWS/GCP), and applications end to end.
  • Set the strategy and roadmap for identity and access management, network and cloud security architecture, endpoint protection, vulnerability management, logging/monitoring, and incident response.
  • Establish and continuously improve secure SDLC practices — threat modeling, secure code review, dependency and supply-chain security, CI/CD pipeline security.
  • Own incident response: build the plan, run tabletop exercises, and lead the response when needed.
  • Lead, coach, and develop security team — establishing clear roles, workflows, and a sense of ownership.
  • Build a team culture rooted in partnership rather than gatekeeping: security as an enabler engineers want to work with, not a blocker they route around.
  • Define how the team engages with Engineering and Product (embedded reviews, self-service tooling, clear SLAs) to minimize friction and rework.
  • Act as the primary security voice to Engineering, Product, IT, Legal, and executive leadership.
  • Translate security risk into business terms for leadership and the board; make pragmatic, risk-based decisions rather than defaulting to "no."
  • Support sales and customer trust efforts (security questionnaires, customer audits, trust center) as a well-run program becomes a competitive advantage.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service