1

Information Security Director Jobs (NOW HIRING)

The Director of Information Security will manage an existing security team, oversee the operating model for security engineering and ops, and partner closely with Product Security, Security ...

The Director of Information Security will manage an existing security team, oversee the operating model for security engineering and ops, and partner closely with Product Security, Security ...

The Director of Information Security will manage an existing security team, oversee the operating model for security engineering and ops, and partner closely with Product Security, Security ...

Director, Information Security

Boston, MA · On-site

$175K - $200K/yr

As the Director, Information Security, you will be the architect of our enterprise security posture during a pivotal stage of our growth. With tens of millions of dollars in revenue and at a growth ...

About the Job The Director of Information Security leads execution of PetSmart's cybersecurity program across security operations, security engineering, compliance support, and related governance ...

As the Director, Information Security, you will be the architect of our enterprise security posture during a pivotal stage of our growth. With tens of millions of dollars in revenue and at a growth ...

They are seeking a Director of Information Security to lead the execution of security engineering and operations capabilities, ensuring compliance with business and regulatory requirements while ...

Directs and oversees the development and maintenance of information security architecture patterns ... Actively participates in aligned Incident Response and Business Continuity Teams. # of Direct ...

About the Job The Director of Information Security leads execution of PetSmart's cybersecurity program across security operations, security engineering, compliance support, and related governance ...

next page

Showing results 1-20

Information Security Director information

See salary details

$89.5K

$139.6K

$202K

How much do information security director jobs pay per year?

As of Jun 13, 2026, the average yearly pay for information security director in the United States is $139,587.00, according to ZipRecruiter salary data. Most workers in this role earn between $125,000.00 and $149,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an Information Security Director, and why are they important?

To thrive as an Information Security Director, you need deep expertise in cybersecurity, risk management, and regulatory compliance, typically backed by a bachelor’s or master’s degree in a related field and several years of leadership experience. Familiarity with security frameworks (such as NIST or ISO 27001), security operations tools (like SIEM and IDS/IPS), and certifications (like CISSP, CISM, or CISA) is highly valuable. Excellent communication, strategic thinking, and leadership skills help in leading teams, influencing company culture, and managing stakeholder expectations. These competencies are crucial for protecting organizational assets, ensuring compliance, and responding effectively to evolving cyber threats.

What is the difference between Information Security Director vs Security Manager?

AspectInformation Security DirectorSecurity Manager
ResponsibilitiesOversees overall security strategy, policies, and compliance at an organizational levelManages day-to-day security operations and team implementation
CertificationsCISSP, CISM, CISA often requiredCISSP, Security+ common
Work EnvironmentExecutive leadership, strategic planningOperational, team management
Industry UsageUsed across industries for senior security leadershipCommon in organizations with dedicated security teams

The main difference is that the Information Security Director focuses on strategic, high-level security planning and policy, while the Security Manager handles daily security operations and team management. Both roles require relevant certifications and are vital in maintaining organizational security, but they differ in scope and focus.

What are some common challenges faced by Information Security Directors when aligning security initiatives with business objectives?

Information Security Directors often face the challenge of balancing robust security measures with the need for business agility and innovation. They must communicate complex technical risks in a way that business leaders can understand, ensuring that security initiatives support the organization's strategic goals without hindering operations. Additionally, they work closely with cross-functional teams to implement security policies that satisfy both regulatory requirements and business needs, often negotiating compromises to achieve the best outcomes for all stakeholders.

What does an Information Security Director do?

An Information Security Director is responsible for overseeing an organization’s information security strategy, policies, and procedures. They lead teams to protect sensitive data from cyber threats, ensure compliance with regulations, and manage responses to security incidents. Their role involves assessing risks, implementing security measures, and collaborating with other departments to promote a culture of security across the organization.

What Does an Information Security Director Do?

As an information security director, your duties are to oversee and manage your organization’s technology security measures, technology integration, and testing to ensure they are working properly. As the director, you have a mix of administrative and analytical responsibilities. You hire and train new analysts and security specialists, meet with other senior management personnel to ensure that each department is complying with protocol, and audit the company routinely to ensure that the company’s network and security systems remain updated and able to prevent major security breaches.

What cities are hiring for Information Security Director jobs? Cities with the most Information Security Director job openings:
What are the most commonly searched types of Information Security jobs? The most popular types of Information Security jobs are:
Who are the top companies hiring for Information Security Director jobs? The top employers for Information Security Director jobs are:
What states have the most Information Security Director jobs? States with the most job openings for Information Security Director jobs include:
Infographic showing various Information Security Director job openings in the United States as of June 2026, with employment types broken down into 69% Full Time, and 31% Part Time. Highlights an 95% Physical, 2% Hybrid, and 3% Remote job distribution, with an average salary of $139,587 per year, or $67.1 per hour.
Information Security Director (ISD)

Information Security Director (ISD)

Redgrave LLP

Chantilly, VA • On-site, Remote

Full-time

Medical, Dental, Vision, Retirement

Posted 4 days ago


Job description


Information Security Director Opportunity


JOB SUMMARY

Redgrave LLP is seeking an Information Security Director to lead, mature, and scale a comprehensive, enterprise-wide information security program. This is an executive ownership role working at the intersection of legal technology, client trust, and emerging AI adoption. The ISD serves as the Firm\'s principal authority on cybersecurity, AI governance, data protection, and enterprise risk management — accountable for ensuring the confidentiality, integrity, and availability of Firm and client data across all systems, platforms, and emerging technologies.

This is a remote position with regular collaboration across time zones.

ESSENTIAL FUNCTIONS

Enterprise Security Governance

  • Define and execute a Firm-wide cybersecurity strategy aligned with NIST CSF, NIST AI RMF 1.0, ISO 27001, and SOC 2 frameworks
  • Own and continuously mature the Firm\'s Information Security Management System (ISMS)
  • Lead ISO 27001 gap analysis and establish a roadmap toward certification
  • Develop, maintain, and enforce security policies, standards, procedures, and governance structures
  • Define and track key risk indicators (KRIs), metrics, and reporting frameworks

AI Governance & Emerging Technology Risk

  • Serve as the Firm\'s executive owner of AI security and governance
  • Design and implement a scalable AI governance framework, including acceptable use standards, risk-tiering criteria, and data handling controls
  • Evaluate AI tools, platforms, plugins, and agentic workflows prior to deployment
  • Monitor evolving AI risk vectors (e.g., prompt injection, data leakage, MCP connector trust boundaries)
  • Maintain and govern the Firm\'s AI System Inventory

Vendor Risk Management

  • Own the Firm\'s vendor risk management program, including intake, risk-tiering, assessment, and continuous monitoring
  • Evaluate SOC 2 reports, DPAs, security questionnaires, and subprocessor disclosures
  • Negotiate and maintain contractual security terms and data protection obligations with vendors
  • Respond to client-driven vendor due diligence requests from regulated industries

Compliance & Audit

  • Own the Firm\'s SOC 2 Type II program, including control maintenance, evidence collection, and auditor engagement
  • Ensure alignment with ABA Formal Opinion 512, client contractual requirements, and applicable regulatory standards
  • Manage cyber insurance processes, including underwriting submissions and renewal strategy

Security Operations

  • Provide executive oversight of security architecture across Microsoft 365 and Azure
  • Oversee Defender for Endpoint, Entra ID, Microsoft Purview, Conditional Access, and Secure Score
  • Own and maintain the Firm\'s incident response program, including tabletop exercises and response coordination

Leadership & Reporting

  • Serve as the Firm\'s primary cybersecurity advisor to executive leadership and the Management Committee
  • Establish regular reporting on security posture, AI risk, vendor risk exposure, and program maturity
  • Direct and mentor the Information Security Analyst and develop organizational security capability

QUALIFICATIONS

Required:

  • 10+ years of progressive experience in information security, including leadership and program ownership roles
  • CISSP (required); CISM or equivalent considered
  • Demonstrated experience leading or scaling a security program; law firm or professional services preferred
  • Strong experience with cloud security, vendor risk, and compliance frameworks
  • Experience with SOC 2 programs and enterprise security tooling in Microsoft environments

Preferred:

  • Experience with AI governance frameworks and emerging technology risk
  • Experience leading ISO 27001 certification or gap analysis
  • Familiarity with legal industry technologies and client expectations
  • Experience in high-growth or rapidly scaling environments

PHYSICAL REQUIREMENTS

  • Occasionally lifts objects up to 20 pounds
  • Must be able to sit or stand for extended periods
  • Occasional travel for project-related work may be required
  • Work is generally performed in a home office (remotely) and in a traditional business setting
Benefits

Redgrave LLP is committed to supporting our employees and ensuring their needs are met beyond the workplace. We offer a flexible portfolio of benefits and services, including medical, dental, and vision coverage, a 401(k) plan, additional benefits to help you prepare for retirement, free access to Employee Assistance Programs, and other programs designed to help you and your family stay healthy, feel secure, and enjoy a positive work/life balance.

Redgrave LLP is an Equal Opportunity Employer.