Senior Director, Information Security jobs in United States
cer-icon
Apply on Employer Site
company-logo

Aspira · 2 weeks ago

Senior Director, Information Security

Aspira is a market-leading provider of software and services that help public agencies protect natural and cultural resources. The Director of Information Security will be responsible for building and leading Aspira’s global information security program, managing a team, and shaping the security strategy while ensuring compliance and risk management.

CommunitiesGovernmentHospitalityInformation TechnologyInternetInternet of ThingsLeisureTourismTravel
badNo H1Bnote

Responsibilities

Develop and execute Aspira’s enterprise information security strategy, aligned with business goals and regulatory requirements
Develop and execute Aspira’s information security roadmap, aligned with Tech Ops goals and enterprise strategy
Lead the design and enforcement of security standards across AWS, Azure integrations, and on-premises systems within the US and abroad
Provide security risk reporting and metrics to VP Tech Ops and executive leadership
Manage and mentor the security team (Analyst, Sr. Cloud Security Engineer, Sr. Network Security Engineer)
Represent security within Aspira’s Technology Operations leadership team
Establish KPIs and metrics for security maturity, resilience, and incident response performance
Oversee cloud security architecture for AWS-native services (VPCs, Transit Gateway, Direct Connect, GuardDuty, WAF, Network Firewall)
Direct firewall and VPN management across Palo Alto (Panorama), Cisco Meraki, and hybrid environments
Ensure secure hybrid connectivity across AWS, Azure, and global office sites
Champion zero-trust principles across endpoints, applications, and networks
Lead the monitoring and incident response program, integrating AWS CloudWatch, CloudTrail, Security Hub with Rapid7, LogRhythm, and log monitoring pipelines
Define incident response playbooks and coordinate Tier 2/3 escalations
Oversee forensic investigations, root cause analysis, and lessons learned after security events
Partner with IT Ops and DevOps to ensure timely remediation of vulnerabilities
Ensure compliance with NIST, PCI DSS, CIS Benchmarks, SOC2, and insurer-driven security baselines (e.g., MFA enforcement)
Drive risk assessments, security audits, and penetration testing
Own responses to customer/vendor security reviews, insurer security questionnaires, and regulatory audits
Maintain documentation for policies, controls, and audit reporting
Define and measure security KPIs, including Mean Time to Respond (MTTR) for incidents, percentage of assets onboarded into SIEM monitoring, and SLA compliance for vulnerability patching
Lead automation of security operations using Terraform, Ansible, and CloudFormation
Implement CI/CD security integrations to support DevSecOps practices
Track KPIs for detection coverage, incident response times, and vulnerability remediation
Partner with DevOps and engineering to embed DevSecOps practices in the software lifecycle
Optimize SIEM and log ingestion pipelines to achieve full visibility across servers, endpoints, and laptops

Qualification

AWS security servicesSIEM platformsIncident responseSecurity frameworksAutomation/scriptingCloud security architecturePalo Alto firewallsCompliance standardsForensic investigationRisk assessmentLeadershipMentoringCollaboration

Required

8+ years in IT and security, including senior leadership in cloud and network security
Proven expertise in AWS security services, SIEM platforms (Rapid7/LogRhythm), Palo Alto/Meraki firewalls, and hybrid connectivity
Proven experience securing AWS-first environments (VPCs, Security Hub, GuardDuty, WAF, Network Firewall) and hybrid global networks
Strong background in incident response, log analysis, and forensic investigation
Deep understanding of security frameworks and compliance standards (NIST, PCI DSS, SOC2, CIS)
Hands-on automation/scripting experience with Terraform, Ansible, Python, or PowerShell

Preferred

Certifications are strongly preferred: CISSP, CISM, AWS Security Specialty, PCNSE, CCNP Security

Company

Aspira

twittertwittertwitter
company-logo
Aspira's technology helps you manage campground reservations, hunting/fishing licenses, and more.

Funding

Current Stage
Late Stage
Total Funding
unknown
2021-04-23Acquired

Leadership Team

leader-logo
Glenn Wilson
Chief Technology Officer
linkedin
leader-logo
Dan McGrew
CFO
linkedin
Company data provided by crunchbase