Full job description
PubMatic seeks a Director of Information Security to lead and evolve the global security program across enterprise infrastructure, cloud platforms, products, corporate systems, and AI technologies. Responsibilities include defining and executing enterprise security strategy, leading security engineering, operations, governance, and incident response teams, building AI-enabled security automation, establishing executive security metrics, managing security investments and vendor relationships, leading security architecture across cloud and enterprise platforms, driving security automation and continuous improvement, partnering with engineering for secure software development lifecycle, developing AI security strategy and governance, securing AI platforms and applications, leveraging AI for threat detection and incident response, guiding secure adoption of Generative AI, maintaining security governance with compliance and privacy teams, partnering with business leaders to balance security and productivity, and leading security awareness initiatives. Requirements include a bachelor's degree or higher in a relevant field, preferred certifications (CISSP, CISM, CCSP), over 10 years of cybersecurity experience with at least 5 years in leadership, expertise in cloud security, IAM, Zero Trust, DevSecOps, Kubernetes, network security, experience in security transformation and automation, knowledge of AI security risks and technologies, strong executive communication skills, and ability to balance risk with business velocity. The role is full-time, hybrid, located in Redwood City, California. Benefits include paid leave, healthcare, commuter benefits, wellness programs, unlimited DTO, and in-office catered lunches. Salary range is $210,000 to $250,000 USD.
What you'll do
- Define and execute PubMatic's enterprise information security strategy and multi-year roadmap
- Lead Security Engineering, Security Operations, Governance, and Incident Response
- Build a highly automated, AI-enabled security organization focused on excellence and operational efficiency
- Establish executive security metrics, KPIs, and reporting for senior leadership and the Board
- Manage a team of security engineers, security investments, vendor relationships, and strategic security initiatives
- Lead security architecture across cloud infrastructure, enterprise platforms, products, identity, networks, Kubernetes, endpoints, and data protection
- Drive security automation, threat detection, vulnerability management, incident response, and continuous improvement
- Partner with engineering teams to embed security by design throughout the software development lifecycle
- Build reusable security platforms, self-service capabilities, APIs, and automation that enable developers while reducing operational overhead
- Develop and execute the company's AI security strategy and governance framework with a security focus
- Secure enterprise AI platforms, AI infrastructure, and AI-enabled applications
- Leverage AI-powered technologies to improve threat detection, incident response, security operations, and overall operational efficiency
- Guide the organization on secure adoption of Generative AI while addressing emerging risks such as prompt injection, data leakage, model abuse, and AI-specific attack vectors
- Maintain enterprise security governance in partnership with compliance and privacy teams, and third-party security programs
- Partner with business leaders to balance security, regulatory requirements, employee productivity, and business agility
- Lead security awareness initiatives that promote secure development and responsible AI adoption across the organization
Requirements
- Bachelor’s degree or higher in Computer Science, Cybersecurity, Engineering, or related field
- CISSP, CISM, CCSP, or equivalent certifications preferred
- 10+ years of progressive cybersecurity experience with at least 5 years leading enterprise security organizations
- Strong expertise in cloud security, Security Engineering, Security Operations, IAM, Zero Trust, DevSecOps, Kubernetes, network security, and modern enterprise security architectures
- Experience leading enterprise-wide security transformation and implementing automation to improve security operations
- Working knowledge of AI-powered security technologies for automation, threat detection, incident triage, and operational efficiency
- Strong understanding of AI security risks, including LLM security, prompt injection, AI governance, and secure enterprise AI adoption
- Proven ability to design security programs that balance risk reduction with employee productivity, developer experience, and business velocity
- Demonstrated success leading large-scale security initiatives with thoughtful rollout strategies, change management, and user adoption planning
- Exceptional executive presence with outstanding written, verbal, and presentation skills
- Ability to translate complex technical and security topics into concise, business-focused, decision-ready recommendations tailored to different audiences
- High attention to detail and a strong sense of executive communication quality and presentation excellence
Tech stack
cloud securitySecurity EngineeringSecurity OperationsIAMZero TrustDevSecOpsKubernetesnetwork securityAI-powered security toolingautomationthreat detectionincident triagedata protectionenterprise security architectures
Benefits
paid leave programspaid holidayshealthcare, dental and vision insurancedisability and life insurancecommuter benefitsphysical and financial wellness programsunlimited DTO in the USreimbursement for mobilefully stocked pantriesin-office catered lunches 5 days per week