we are looking for a Director of IT Security.
The Director of IT Security leads corporate IT security function and oversees the day-to-day operation and continuous improvement of security controls across the organization.
The role operates within the IT strategy, budget, and governance framework. Leads the day-to-day security function and escalates strategic decisions and material approvals to IT ownership.
The role focuses on protecting identities, endpoints, SaaS and AI environments, corporate systems, suppliers, and information assets, and partners with IT, Operations, R&D, Security, Compliance, Legal, and business stakeholders.
The role manages the IT Security team and builds a scalable function that strengthens security maturity, control coverage, compliance readiness, cyber resilience, and secure business operations.
Responsibilities:
Lead and execute the corporate IT security roadmap and operating plan, and formulate IT Security procedures, standards, and security improvement initiatives, within the strategy and governance framework, in collaboration with the Director of IT.
Manage the IT Security team, starting with a Security Engineer, and support the function's continued growth.
Implement, operate, and improve security controls across identity and access management, endpoint security, DLP, SaaS, AI tools, and corporate systems, including access reviews, endpoint compliance, and secure configuration standards.
Own the corporate vulnerability-management lifecycle, including risk-based prioritization, remediation SLAs, remediation tracking, reporting, and escalation.
Lead the assessment and approval process for internal SaaS and AI tools, approving low- and medium-risk requests and escalating high-risk requests in collaboration with the Director of IT and the appropriate governance forum.
Define and manage IT Security requirements for suppliers, vendors, third parties, and enterprise platforms, and lead security reviews for corporate IT systems, coordinating with R&D Security when product or engineering environments are affected.
Maintain security monitoring, technical enforcement, control documentation, and audit evidence for IT controls.
Lead corporate cyber-resilience activities, including business continuity, disaster recovery, tabletop exercises, and ransomware readiness.
Support incident response for corporate IT Security events and coordinate with R&D Security on incidents affecting both corporate and R&D environments.
Provide IT Security subject-matter expertise for audits, customer security requests, and compliance activities, while overall security and customer-assurance ownership remains with the relevant organizational function.
דרישות:
Undergraduate degree and/or relevant experience in Information Security, Information Technology, Computer Science, or a related field.
At least 8 years of experience in IT Security, Information Security, Security Operations, or a related field.
Experience leading corporate security programs across identity and access management, endpoint security, SaaS, cloud, data protection, and security governance.
Experience managing security controls, access reviews, vulnerability remediation, DLP, security monitoring, incident response, cyber resilience, and audit evidence.
Experience with SaaS and AI security assessments, vendor security, and third-party risk management.
Experience managing or mentoring security professionals and working with cross-functional teams.
Experience working in global high-tech and highly regulated technology organizations.
Familiarity with ISO 27001, SOC 2, NIST CSF, GDPR, HIPAA, or similar standards and frameworks.
Experience with BCP/DR, tabletop exercises, ransomware preparedness, or corporate vulnerability management.
Excellent English verbal and written skills.
Excellent interpersonal, communication, analytical, and risk-assessment skills.
Ability to work independently, prioritize effectively, and present clear recommendations המשרה מיועדת לנשים ולגברים כאחד.