Omnissa is an AI‑driven digital work platform designed to support flexible, secure, work‑from‑anywhere experiences. The platform integrates Unified Endpoint Management, Virtual Apps and Desktops, Digital Employee Experience, and Security & Compliance into a seamless autonomous workspace that adapts to how people work. Omnissa is rapidly growing and is committed to delivering meaningful impact to its customers.
Role Summary
Director, Security Architecture, Vulnerability Management and Response reports to the Chief Information Security Officer. This leadership role sets and drives strategy for Security Architecture, Vulnerability Management, and Vulnerability Response (PSIRT), protects Omnissa’s infrastructure, applications and services across on‑premises and cloud environments, and oversees the full risk lifecycle from identification through remediation.
Key ResponsibilitiesStrategy & Leadership
- Set multi‑year strategy and roadmap aligned to Omnissa’s risk appetite and business objectives.
- Lead, mentor, and grow a globally distributed senior security engineering and architecture team.
- Serve as senior escalation point for design conflicts, remediation prioritization, and security incidents surfaced through PSIRT.
- Represent the function to executive leadership, translating technical risk into business terms.
Security Architecture
- Partner with business units to establish security standards, perform architecture and design reviews, and embed security into every stage of design and implementation.
- Drive security framework development, hardening standards, and policy adherence across the enterprise.
- Conduct risk assessments for new infrastructure, products and services, ensuring controls are defined before deployment.
- Define and maintain enterprise identity security strategy and standards across workforce, non‑human identities, AI agents and API access.
- Align security architecture with relevant frameworks (SOC2, ISO27001, NISTCSF/800‑53, PCI, HIPAA, FedRAMP).
- Partner with legal, privacy and data owners to enforce classification, residency, retention and disposal standards, including for AI/GenAI training data.
Exposure / Vulnerability Management
- Own end‑to‑end exposure management program, tooling, scanners, processes and SLAs.
- Continuously monitor, prioritize and report on vulnerabilities, providing remediation guidance to product and system owners.
- Govern the program in alignment with Omnissa’s Vulnerability Management Policy and Standards.
- Ensure equal SLAs and remediation accountability across infrastructure, cloud and product/application codebases.
Vulnerability Response (PSIRT)
- Own enterprise PSIRT strategy, partnering with the team on intake, triage and coordinated response.
- Define and enforce SLAs for triage time, severity scoring and remediation timelines.
- Own the responsible disclosure program and any bug bounty/researcher relationships.
- Serve as central coordination point during high/critical vulnerability events, aligning legal, communications, customer success and engineering roles.
- Close feedback loop from PSIRT findings into product security, threat modeling and secure coding programs.
AI Governance & Emerging Technology Security
- Establish and mature security approach to AI and GenAI adoption, including guardrails, managed enterprise settings and acceptable‑use enforcement.
- Assess and govern AI‑related risk as new capabilities are introduced.
- Develop enterprise standards for secure AI usage and partner with threat management on monitoring and detection.
- Apply AI risk frameworks (NIST AI RMF, OWASP LLMTop10, ISO/IEC42001) to guide model and pipeline risk assessments.
Partnership, Tooling & Vendor Management
- Prioritize security in early development lifecycle to embed security, unblock teams and reduce friction.
- Lead security tool selection, proofs of concept and vendor negotiations.
- Manage vendor relationships to ensure measurable risk reduction across the stack.
Required Qualifications
- 10+ years in information security, including 5+ years leading technical security teams in a global SaaS environment.
- Experience building and operating enterprise identity security strategy, including IAM/PAM, authentication standards and identity threat detection.
- Deep hands‑on background in cloud and network security, endpoint/workload protection, exposure/vulnerability management and product security/SDLC.
- Knowledge of data governance, GDPR, CCPA, CMMC and major compliance frameworks; understanding of AI risk frameworks is a plus.
- Track record of partnering with engineering teams to drive security outcomes through influence and collaboration.
- Experience with risk lifecycle: assessment, requirements gathering, control design, tool selection, vendor negotiation and remediation oversight.
- Strong communication skills with ability to influence executives and engineers alike.
- Hands‑on experience integrating security into SDLC and CI/CD pipelines and in threat modeling at the architecture stage.
- Experience operating with globally distributed teams and supporting 24x7 service models.
Preferred Qualifications
- Background at a B2B SaaS/cloud company.
- Experience securing AI/GenAI technologies and establishing governance for their enterprise use.
- Familiarity with modern security tooling such as CrowdStrike, Wiz, Tenable, Seemplicity, Recorded Future, Cribl and Palo Alto / Panorama.
- Relevant certifications (e.g., CISSP, CCSP or equivalent).
Benefits
- Competitive salary range: USD 178,000 – 296,700 per year.
- Participates in a corporate bonus program.
- Employee ownership.
- Health insurance.
- 401(k) with matching contributions.
- Disability insurance.
- Paid time off.
- Growth opportunities.
Equal Employment Opportunity
Omnissa is an Equal Employment Opportunity company and prohibits discrimination and harassment of any kind. All employment decisions at Omnissa are based on business needs, job requirements and individual qualifications, without regard to race, color, religion, ancestry, ethnicity, national origin, sex, age, disability, sexual orientation, gender identity, marital status, veteran status or any other status protected by applicable laws. Omnissa welcomes applicants of all ages and provides reasonable accommodations for applicants and employees with protected disabilities.