Director, Corporate Security

Nintex Nintex · Enterprise · Bellevue, WA · IT

The Director, Security and Compliance will be responsible for the strategic leadership of the security and compliance program at Nintex. This role will establish, maintain, enhance, and grow comprehensive security strategies, policies, and procedures to ensure the integrity, confidentiality, and availability of intellectual property and assets are protected. The Director will be responsible for proactively identifying, assessing, and reporting on security risks that meet regulatory requirements and support the risk posture of Nintex. This includes information security, risk management, compliance, security education, product security, and leadership of security engineers and compliance analysts.

What you'd actually do

  1. Establish near and long-term internal security and compliance goals, define security strategies, metrics, reporting mechanisms and program services; and create a roadmap for continual security and compliance growth.
  2. Lead the design, implementation, and protection of security controls, processes, and technologies to protect the organization's intellectual property and assets.
  3. Actively engage in a threat management and intelligence program in collaboration with an outsourced Security Operations Center (SOC).
  4. Provide regular and consistent reporting on the current status of the information security program to senior business leaders.
  5. Manage security incidents and breaches, including incident response, investigation, and remediation efforts.

Skills

Required

  • Bachelor's degree in computer science or similar field such as Engineering, Information Security, or Information Systems.
  • Current and relevant Industry Certifications such as CISSP, CCSP, or CISA.
  • 10+ years of direct experience in an Information Security role.
  • 5+ years of experience leading teams in a Security organization.
  • Deep familiarity with enterprise security technologies, such as: firewalls, EDR, SIEM, MDR, MFA, CASB, vulnerability management, encryption technologies, etc.
  • In-depth knowledge of information security principles, practices, technologies, standards, risk management methodologies and frameworks.
  • Exceptional problem-solving and analytical skills with the ability to distill complex and nuanced issues into structured frameworks and processes.
  • Strong, executive level oral and written communication skills with ability to understand technology sufficiently to clearly communicate the complexity in simple terms for key stakeholders, both in one-on-one and public settings.
  • Strong ability to translate strategic-level goals into actionable objectives.

What the JD emphasized

  • security strategies
  • security risks
  • security controls
  • security posture
  • security engineers
  • security policies
  • security awareness
  • product security
  • threat modeling
  • cloud security posture
  • cyberattacks