Full job description
The Director / Senior Director of Security at TripleLift leads the security strategy and program across the programmatic advertising platform, cloud infrastructure, and enterprise environment. This role involves partnering with Engineering, Product, Legal, and executive leadership to build and mature a scalable security program. Responsibilities include defining security strategy, leading a security engineering team, managing enterprise security architecture on AWS, driving compliance and governance programs (SOC 2, PCI, NIST CSF, ISO 27001, HITRUST), overseeing security monitoring and incident response, embedding security into SDLC and DevSecOps workflows, leading vulnerability management, and communicating security posture to leadership. Requirements include a bachelor's degree or equivalent experience, 8+ years in information security with 3+ years in leadership, deep AWS cloud security expertise, experience with compliance frameworks, security operations, DevSecOps, and strong communication skills. Benefits include medical, dental, vision plans, flexible PTO, and 401k with employer match. Salary range is $165,000 to $220,000 USD.
What you'll do
- Define and execute security strategy, roadmap, and program priorities aligned with company objectives and regulatory requirements
- Lead, grow, and mentor security engineering team across cloud/infrastructure security, GRC, and security operations
- Own enterprise security architecture across AWS cloud, CI/CD pipelines, and corporate infrastructure ensuring security best practices
- Drive compliance and governance programs maintaining certifications including SOC 2, PCI, NIST CSF, ISO 27001, HITRUST
- Oversee security monitoring, threat detection, incident response capabilities including SIEM and EDR tooling
- Partner with Engineering and DevOps to embed security into SDLC and promote secure coding standards
- Lead vulnerability management and risk assessment programs including audits, penetration testing, remediation tracking
- Serve as subject matter expert for security vendor evaluations, customer due diligence, and contract reviews
- Communicate security posture, risks, and progress to executive leadership and board
- Cultivate company-wide security awareness through training, policy development, and education programs
Requirements
- Bachelor's degree in Computer Science, Information Security, or related technical field, or equivalent experience
- Relevant security certifications preferred: CISSP, CISM, CISA, or equivalent
- 8+ years progressive information security experience
- At least 3 years leadership or management experience overseeing security engineers or analysts
- Deep expertise in AWS cloud security including IAM, VPC architecture, logging/monitoring, cloud-native security tooling
- Experience building or maturing security programs and compliance frameworks (SOC 2, PCI DSS, NIST CSF, ISO 27001)
- Strong background in security operations: SIEM/EDR management, incident response, threat hunting, vulnerability management
- Experience embedding security into DevSecOps workflows including IaC (Terraform, CloudFormation), CI/CD security controls, secure coding remediation
- Ability to influence cross-functional stakeholders and communicate security risk to non-technical audiences
- Experience in fast-paced, cloud-native environments; adtech, martech, or SaaS industry experience a plus
- Excellent written and verbal communication skills
Tech stack
AWSIAMVPCCI/CDTerraformCloudFormationSIEMEDRDevSecOps
Benefits
Medical, Dental & Vision PlansFlexible PTO401k with employer match