Job Description
For this opening we will consider candidates from the following locations: Woburn,MA,United States | Toronto,ON,Canada
Do you thrive in high-stakes environments, safeguarding critical data and systems while building robust security programs? Are you a passionate leader with a proven track record of mitigating risks and fostering a culture of security awareness? Do you enjoy rolling up your sleeves and collaborating with engineers to design and implement robust security solutions? If so, we invite you to join and lead our security efforts. The Opportunity The CISO / Sr. Director role will be the Head of Information Security, you'll report directly to the CTO and play a central role in fortifying our organization against the ever-evolving threat landscape. You'll ensure the confidentiality, integrity, and availability of our cloud-centric systems while fostering a culture of security awareness across all departments.
What You’ll Do:
Technical Leadership & Security Strategy:
- Design, implement, and maintain a robust, cloud-centric security architecture encompassing firewalls, intrusion detection/prevention systems (IDS/IPS), access controls (e.g., SailPoint), encryption protocols, and cloud-native security solutions.
- Lead the selection, implementation, and ongoing management of security tools and technologies, serving as the organization's primary authority on information security.
- Proactively identify and remediate security vulnerabilities through vulnerability scans, external penetration testing (including active participation), and tabletop exercises, leveraging industry-leading tools like Tenable and Veracode alongside methodologies such as MITRE ATT&CK and STRIDE.
- Implement and optimize security controls to safeguard information assets. Oversee incident response, crisis management, and business continuity planning to ensure operational resilience.
- Deploy and manage a SIEM program for continuous threat detection, analysis, and security posture improvement through KPI monitoring and threat intelligence integration.
Governance, Risk & Compliance (GRC) & Customer Assurance:
- Lead Security Strategy & Culture: Develop and implement a comprehensive security framework (policies, standards, procedures) ensuring regulatory compliance (e.g., SOC 2), industry best practices, and robust customer trust. This includes fostering a culture of risk awareness, ownership, and continuous improvement through engaging security awareness programs and collaboration across departments.
- Manage Security Operations: Oversee the GRC team, lead security operations teams (incident response, vulnerability management), and partner with corporate security to optimize overall strategies. Conduct vendor security reviews. Manage risk management process, risk register, and Security Posture Dashboard. Review exceptions to policies and security gaps and run Security Advisory Board Meetings.
- Build Strong Relationships: Build and maintain strong relationships with key customers, actively engage them, address their security concerns collaboratively, and clearly articulate the organization's security posture.
Strategic Leadership & Team Management:
- Develop and execute IT security strategies aligned with business objectives, incorporating zero-trust principles, crisis management plans, and micro-segmentation for enhanced security.
- Make independent, data-driven decisions to safeguard information assets while ensuring alignment with corporate security strategies.
- Provide strategic guidance on vendor selection, risk assessments, and compliance requirements, ensuring cost-effectiveness and alignment with security needs.
- Lead and mentor a high-performing IT security team focused on cloud security, vulnerability management, incident response, and continuous security improvement.
- Manage staffing needs, recruitment efforts, and professional development programs to build a skilled and motivated security team.
- Collaborate closely with security engineers to innovate and maintain robust security solutions, fostering a culture of continuous improvement.
What you’ll bring:
Experience:
- Minimum 10 years of experience in information security, with at least 7 years in a leadership role (Director, VP, CISO, etc.) within a SaaS environment. Experience leading and growing security teams is a plus.
- Proven track record of building and implementing successful cloud security programs , demonstrably reducing security risks by quantifiable metrics.
- Deep understanding of the evolving threat landscape and a history of translating that knowledge into actionable security strategies that have prevented major security incidents.
- Expertise in cloud security best practices, compliance frameworks (e.g., SOC 2, NIST), and threat modeling methodologies (e.g., MITRE ATT&CK, STRIDE). Experience in successfully achieving and maintaining relevant compliance certifications is a plus.
- Hands-on experience in leading incident response, disaster recovery, and security operations teams. Experience conducting successful incident response exercises and implementing effective disaster recovery plans is a plus.
Technical Skills:
- Strong understanding of cloud security concepts (IaaS, PaaS, SaaS), including containerization (e.g. Kubernetes), and experience in securing cloud workloads.
- Proficiency with security tools like firewalls, intrusion detection/prevention systems, access controls (SailPoint), SIEM platforms (e.g. Datadog), vulnerability scanners (Tenable, Veracode), cloud-native security tools, and experience in leveraging them to proactively identify and mitigate threats.
- Experience with security automation and orchestration tools to streamline security operations. Experience with application-level encryption and implementing DLP Strategy.
- Familiarity with emerging security technologies (e.g., zero-trust architecture) and a willingness to stay ahead of the curve.
Leadership & Communication:
- Proven ability to lead and motivate a high-performing security team, fostering a culture of continuous improvement and knowledge sharing. Experience in mentoring and developing security professionals is a plus.
- Excellent communication, collaboration, and influencing skills to build trust and partnerships across business units, clearly articulating security risks and solutions to technical and non-technical audiences.
- Strong strategic thinking and decision-making abilities to balance security with business needs, effectively allocating resources and prioritizing initiatives.
Education & Certifications:
- Bachelor's degree in Computer Science, IT, or a related field (e.g., Cybersecurity).
- Security certifications are highly desirable (e.g., CISSP, CISM, CISA, AWS Certified Security).
The Location This role can be based in our Boston, MA office (Woburn site) or our Toronto, Ontario office. We offer a hybrid work model that allows for team collaboration in person and flexible work-from-home options.
Who is NOTIFIED?
We believe everyone has a story to tell and we’re passionate about helping people and brands amplify their stories across the globe. We are proud to be the number one provider of enterprise webcasting and investor relations content distribution, as well as a global leader in press release distribution. Our clients have used Notified to monitor over 2 billion social media conversations every year! Our products are built so storytellers can do their best work. But we’re not just a platform—personalized, caring service is how we operate. We add a personal touch to everything we do. We strive to deliver wisdom and insight by helping our clients reach global and targeted audiences, measure outcomes, and fulfill their commitments.
Join the Best in Class!
- “Best Press Release Distribution Company,” MarTech Breakthrough Awards
- “PR Innovation of the Year,” Gold Stevie® Winner, 2023 American Business Awards
- “Marketing/Public Relations Solution,” Gold Stevie® Winner, 2023 American Business Awards
Why work for Notified?
- Global collaboration with team members in 17 countries
- Opportunities to innovate and grow!
- Comprehensive health benefits and wellness programs
- Quarterly recognition awards
- Curated learning libraries offering over 8,000 free courses supporting your business and technical acumen
- Flexibility to work from home on Mondays and Fridays
- Diversity is celebrated and supported inclusive Employee Resource Groups
- Amazing colleagues to learn from and enjoy company social outings and events!
#LI-SB1
#LI-HYBRID
Job Tags
Work from home, Flexible hours, Monday to Friday,