- Company Name
- Squarespace
- Job Title
- Senior Director, Security Operations
- Job Description
-
**Job title**: Senior Director, Security Operations
**Role Summary**
Lead and scale the company’s security operations, overseeing the SOC, incident response, vulnerability management, and security architecture. Develop and execute a comprehensive security strategy, drive continuous improvement through automation and tooling, and build a high‑performing security team. Act as a trusted advisor to leadership and cross‑functional teams, ensuring security is integrated across the organization and that compliance requirements are met.
**Expectations**
- Deliver measurable security KPIs and continuous improvement
- Mentor and grow a capable security team
- Build and maintain strong relationships with internal stakeholders and external vendors
- Ensure alignment of security initiatives with business goals and risk appetite
- Demonstrate subject‑matter expertise across GRC, IR, vulnerability management, product security, and cloud security
**Key Responsibilities**
1. Define, measure, and report on security KPIs/KRIs for the organization.
2. Develop and maintain a 24/7 SOC, overseeing threat detection, monitoring, analysis, and proactive hunting.
3. Lead incident response: create playbooks, conduct investigations, and drive post‑incident reviews.
4. Manage end‑to‑end vulnerability management program, prioritizing remediation across assets.
5. Conduct security architecture reviews and design consultations for new products, features, and infra changes.
6. Identify, evaluate, and implement new security technologies, tools, and automation to enhance detection, prevention, and response.
7. Continuously improve security operations processes through tooling and best‑practice adoption.
8. Stay current on emerging threats and advise leadership on necessary adjustments.
9. Draft and enforce security policies, standards, and guidelines.
10. Build, mentor, and lead a cross‑functional security team.
11. Serve as liaison for Engineering, Product, Legal, Compliance, IT, and other stakeholders.
12. Manage vendor relationships and ensure compliance with regulations (e.g., GDPR, PCI‑DSS, NIST, ISO 27001).
13. Promote security‑by‑design principles throughout the SDLC.
**Required Skills**
- Extensive experience (12+ years) in cybersecurity, with deep knowledge of authentication, authorization, GRC, incident response, vulnerability management, product security, and cloud security.
- Strong Linux and AWS/GCP expertise; familiarity with security automation platforms.
- Proven ability to lead and develop high‑performing security teams.
- Excellent communication and stakeholder management skills across all levels of the organization.
- Knowledge of security frameworks: NIST, CIS, ISO 27001, PCI‑DSS, GDPR, etc.
- Demonstrated ability to drive process improvements, automation, and integration of security into product and operations.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Relevant certifications such as CISSP, CISM, GCIA, or equivalent preferred.