1

Director It Security Jobs (NOW HIRING)

Required : • Minimum of 10 years of information security and technology risk management experience, with at least 5 years in a leadership capacity at a regulated financial institution or Fintech ...

Being a member of IT Cybersecurity Engineering and Operations at DTCC, your purpose is to provide best in class and versatile security services to the enterprises. As a Director in Cybersecurity ...

Overview The Manager, IT Security, is a key leadership role within the IT Security organization, reporting directly to the Director, Information Security. This position is responsible for leading a ...

Overview The Manager, IT Security, is a key leadership role within the IT Security organization, reporting directly to the Director, Information Security. This position is responsible for leading a ...

next page

Showing results 1-20

Director It Security information

See salary details

$37K

$104.5K

$167K

How much do director it security jobs pay per year?

As of Jul 20, 2026, the average yearly pay for director it security in the United States is $104,452.00, according to ZipRecruiter salary data. Most workers in this role earn between $85,000.00 and $117,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by a Director of IT Security when leading a security team in a large organization?

A Director of IT Security in a large organization often faces the challenge of balancing strategic oversight with day-to-day operational demands. Keeping up with the rapidly evolving threat landscape while ensuring the team has the right tools and training can be demanding. Additionally, coordinating across multiple departments to enforce security policies and fostering a culture of security awareness are critical but complex tasks. Successfully navigating these challenges requires strong leadership, communication skills, and the ability to prioritize and allocate resources effectively.

Can you make $200,000 in cyber security?

A Director of IT Security can potentially earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP, and working in high-demand industries or large organizations. Salary levels depend on factors such as location, company size, and individual expertise. Senior roles often include leadership responsibilities and require strong knowledge of security protocols, risk management, and security tools.

Can you make $500,000 a year in cyber security?

A Director of IT Security can potentially earn $500,000 annually, especially with extensive experience, advanced certifications like CISSP, and leadership roles in large organizations. High salaries are often associated with senior positions overseeing security strategy, risk management, and compliance, and may include bonuses and stock options.

Is 30 too old for cyber security?

As a Director of IT Security, age is not a barrier to entering or advancing in cybersecurity. Many professionals transition into cybersecurity careers later in life, leveraging prior experience, and obtaining certifications like CISSP or CISM can enhance prospects regardless of age.

What does a director of IT security do?

A director of IT security oversees an organization's cybersecurity strategy, manages security teams, and implements policies to protect information systems from threats. They evaluate risks, ensure compliance with security standards, and often work with tools like firewalls, intrusion detection systems, and security frameworks. Strong leadership, technical expertise, and certifications such as CISSP are typically required for this role.

What are the key skills and qualifications needed to thrive as a Director of IT Security, and why are they important?

To thrive as a Director of IT Security, a deep understanding of information security principles, risk management, and a bachelor's or master's degree in cybersecurity or a related field—often coupled with extensive experience—is essential. Familiarity with security frameworks (like NIST, ISO 27001), SIEM tools, and certifications such as CISSP or CISM are typically required. Strong leadership, strategic thinking, and effective communication skills are crucial for leading teams and collaborating across departments. These competencies are vital to developing robust security strategies, mitigating threats, and ensuring regulatory compliance in a rapidly evolving digital landscape.
More about Director It Security jobs
What cities are hiring for Director It Security jobs? Cities with the most Director It Security job openings:
What are the most commonly searched types of It Security jobs? The most popular types of It Security jobs are:
What states have the most Director It Security jobs? States with the most job openings for Director It Security jobs include:
Infographic showing various Director It Security job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 83% Full Time, 14% Part Time, 1% Temporary, and 1% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $104,452 per year, or $50.2 per hour.
Director, Information Technology & Security

Director, Information Technology & Security

Affirm

Remote

Full-time

Re-posted 21 days ago


Job description

Job Summary:
Affirm is reinventing credit to make it more honest and friendly, and they are seeking a Chief Information Security Officer (CISO) to lead their information security and cybersecurity programs. The CISO will design and implement a comprehensive security framework, oversee policies and procedures, and ensure compliance with regulatory expectations while collaborating with various teams to integrate security into the Bank's operations.
Responsibilities:
• Design, implement, and maintain a comprehensive Information Security Program consistent with FDIC guidance (e.g., FIL-66-2019, FIL-13-2021) and the Interagency Guidelines Establishing Information Security Standards.
• Develop and oversee policies, standards, and procedures governing cybersecurity, data protection, and incident response.
• Ensure alignment with the Bank’s overall risk management and governance frameworks.
• Provide regular reporting to executive management and the Board on the Bank’s security posture, emerging risks, and mitigation efforts.
• Establish and manage a threat monitoring and detection capability to identify, assess, and respond to cybersecurity risks.
• Oversee implementation of layered security controls (e.g., network segmentation, encryption, access controls, endpoint protection, vulnerability management).
• Lead the Bank’s Incident Response Program, ensuring timely escalation and coordination with regulators when required.
• Maintain relationships with information-sharing groups (e.g., FS-ISAC) and law enforcement to stay informed of emerging threats.
• Evaluate the information security posture of third-party and affiliate service providers in accordance with the Bank’s Vendor Management Program and FDIC third-party risk guidance.
• Establish due diligence, ongoing monitoring, and contractual requirements for vendors handling sensitive data or performing critical services.
• Coordinate with Operations, Compliance, and Internal Audit to ensure third-party risks are identified, assessed, and mitigated.
• Ensure compliance with applicable privacy and data protection requirements (e.g., GLBA, Regulation P, state privacy laws).
• Implement processes to safeguard customer information and prevent unauthorized access, disclosure, or misuse.
• Partner with business and technology teams to integrate privacy-by-design principles into new products and services.
• Lead development and testing of the Bank’s Business Continuity and Disaster Recovery (BC/DR) plans, ensuring they are integrated with information security objectives.
• Coordinate regular testing and simulations to validate readiness for cyber incidents and system disruptions.
• Support resilience planning for key systems, vendors, and communication protocols.
• Build and document the Bank’s information security program as part of the de novo application process.
• Establish security architecture, monitoring tools, and vendor relationships prior to launch.
• Prepare readiness materials for FDIC and state examinations related to cybersecurity and operational resilience.
• Ensure security risk assessments and third-party reviews are completed and incorporated into pre-opening milestones.
• Serve as the Bank’s senior advocate for cybersecurity and data protection, promoting a culture of security awareness and accountability.
• Provide training and guidance across the organization to enhance information security awareness.
• Collaborate with peers in Risk, Compliance, Operations, and Technology to align security priorities with business strategy.
• Build and lead a capable, mission-driven security team to support the Bank’s evolving needs.
Qualifications:
Required:
• Minimum of 10 years of information security and technology risk management experience, with at least 5 years in a leadership capacity at a regulated financial institution or Fintech.
• Demonstrated experience designing and implementing information security programs compliant with FDIC and FFIEC standards.
• Strong familiarity with third-party risk frameworks and financial services cybersecurity expectations.
• Experience leading incident response, penetration testing, and security operations in cloud-based and hybrid environments.
• Proven ability to communicate complex technical topics to executive leadership, the Board, and regulators.
• Strong leadership, analytical, and problem-solving skills with a risk-based and pragmatic approach to decision-making.
• Expert knowledge of information security principles, frameworks, and regulatory requirements.
• Strategic thinker with strong operational execution and control discipline.
• Effective communicator capable of influencing across technical and business functions.
• Collaborative leader who fosters a culture of accountability, awareness, and continuous improvement.
Company:
Affirm is a financial technology services company that offers installment loans to consumers at the point of sale. Founded in 2012, the company is headquartered in San Francisco, USA, with a team of 1001-5000 employees. The company is currently Late Stage.