Information Security Director

LineVision•Boston, MA
•Hybrid

About The Position

Step into a pivotal Security Leadership role at a fast-growing grid intelligence company. LineVision’s customers include eight of the ten largest US utilities, which demand the highest levels of security in order to protect sensitive data and the electric grid from attack. You will lead LineVision to achieve a security posture that exceeds industry standards and gives customers the confidence they need to rely on LineVision. Reporting to the VP of Security, IT, and Quality, you will have broad autonomy over security engineering, security operations, controls execution, governance, and compliance. You and a Security Analyst will own our SOC 2 Type II and ISO 27001 programs, risk management, incident response, penetration testing program, and customer security engagements. Partnering with IT, Platform, Hardware, and Customer Success, you will make security a strategic business advantage at LineVision. If you want to build a security program that is seen as a strategic differentiator and wins customer trust, join us at LineVision, Built In Boston Best Places to Work! Applicants must be currently authorized to work in the United States on a full-time basis. This position is not eligible for employment visa sponsorship.

Requirements

  • 6+ years in information security, with at least 2 years in a lead or people-management role.
  • Direct ownership (not only support) of SOC 2 Type II and ISO 27001 audits.
  • Experience conducting risk assessments with NIST CSF or an equivalent framework.
  • Hands-on experience with penetration test management, vulnerability management, and EDR/SIEM tooling (CrowdStrike preferred).
  • Experience with AWS cloud security.
  • Experience responding to enterprise customer security questionnaires and contract requirements.
  • CISSP, or a commitment to earn it within 18 months of start date.

Nice To Haves

  • Experience with OT/ICS or IoT security, including IEC 62443.
  • Familiarity with utility sector requirements (CEII, NERC CIP) or other regulated critical infrastructure.
  • Experience leading incident response for a real event.
  • Experience with Vanta or similar compliance automation.
  • Experience in AI Governance and/or assessing the security of AI tools and features.

Responsibilities

  • Own the annual audit cycle for SOC 2 Type II and ISO 27001 using the Vanta compliance platform, including all controls, internal audits, external audits, and nonconformity tracking to closure.
  • Lead the annual NIST CSF risk assessment, monthly Platform and Hardware risk reviews, and quarterly Governance, Risk & Compliance reviews. Maintain policies and report ISMS efficacy metrics to leadership.
  • Conduct AWS cloud and Sensor penetration tests, ISA/IEC 62443 product security assessments, vendor and product risk assessments.
  • Oversee vulnerability management, CrowdStrike Falcon Complete detection rules, NextGen SIEM data feeds, and the MSSP relationship. Monitor open-source license compliance with FOSSA.
  • Own the incident response program and plan, including the annual 3rd part tabletop, business continuity and disaster recovery exercises, and implementation of lessons learned.
  • Define and guide data management controls, ensuring rigorous application of policies and customer contractual obligations regarding confidential data. Partner with Platform, Hardware and IT to apply controls across all company systems and applications.
  • Lead responses to customer security questionnaires, contract security reviews, and customer-facing security presentations and material.
  • Identify risks and define security standards for enterprise and product AI. Inform the AI governance program with risk assessments and recommendations.
  • Coach and develop the security team. This role requires participation in a compensated rotational on-call schedule. On-call responsibilities are a condition of employment for this position.
  • Establish operational rhythm with the security team, including 1-1s, goal-setting, and sprint planning.
  • Take ownership of the audit calendar, risk register, and security project portfolio.
  • Implement an intake and prioritization process for security work that surfaces trade-offs and schedule risk early.
  • Take over customer security questionnaires and contract reviews, and build a reusable response library.
  • Lead monthly security risk reviews.
  • Deliver SOC 2 Type II and ISO 27001 surveillance audits with no major nonconformances.
  • Complete an annual IEC 62443 security assessment of the product and track remediations.
  • Extend data controls beyond Google Drive to Atlassian, Slack, and email with the IT Lead.
  • Plan and conduct the incident response tabletop, and address findings.
  • Mature CrowdStrike detection rules and SIEM coverage.
  • Propose a 2–3 year security roadmap that fulfills LineVision’s vision for security excellence, including tooling, budget, and resourcing as the company grows.
  • Reduce questionnaire effort per customer through self-service trust materials and a mature answer library.
  • Define security requirements for next-generation sensors and platform features.
  • Establish ISMS efficacy metrics reported quarterly to leadership.
  • Lead quarterly Governance, Risk & Compliance reviews with executive leadership.

Benefits

  • medical, dental, vision and disability insurance
  • commuter benefits
  • a 401(k) with company match
  • trust-based paid time off
  • company bonus plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service