About the Role
Fivetran is building data pipelines to power the modern data stack for thousands of companies.
We’re looking for a Director of Information Security leader to drive strategic security improvements, improve team operations. The ideal candidate will lead Fivetran’s vulnerability management, application, and cloud security teams. In this position you will report to the Chief Information Security Officer (CISO) and play a critical role in the security of Fivetran’s products.
The work is very diverse and will vary from high level strategic planning down to hands-on direct contributions defining security processes and collaboration between departments and teams. You’ll also be responsible for ensuring the technical excellence of your team and positive security outcomes for Fivetran’s product offerings.
This is a full-time, remote position based out of the US.
Technologies You’ll Use
AWS, Azure, GCP, Java, BigQuery, SAST, DAST, SCA, Looker, Height
What You’ll Do
- Lead and grow our application and cloud security teams
- Operationalize and scale Fivetran’s vulnerability management, bug bounty, and red team operations
- Drive key improvements to secure our development processes
- Work collaboratively with other departments including Engineering and Product teams
- Identify security risks in current and future systems
- Motivate other departments/teams along their security journey
- Build data driven metrics to represent the maturity state of the security program
- Create alignment with senior leadership to set and communicate the strategy, values, budget, and priorities of the team
- Enhance the performance and career development of members of the team through effective coaching, guidance, and career development
Skills We’re Looking For
- Proven experience in a strategic security leadership role at a SaaS company
- Ability to deeply understand how Fivetran systems work when calculating risk and defining requirements
- The ability to both “lead” and “do”
- Experience in application security, cloud architecture, Java applications, and compliance frameworks
- Ability to communicate complex security concepts to diverse audiences
- Excellent leadership and communication skills with a track record of building strong relationships with teammates, software engineers, SRE, and product managers
Bonus Skills
- Experience with infrastructure security components and configuration for AWS/GCP/Azure
- Proven results encouraging adoption of a security mindset into an organization’s processes, and SDLC habits
- Success in building/supporting security-focused engineering community, culture and security champion programs
#LI-DH1 #LI-REMOTE