Director of Security

Wysh Financial, LLC.

Northern (KY)

Hybride

USD 190 000 - 220 000

Plein temps

Il y a 39 heures
Soyez parmi les premiers à postuler
Générateur de candidature

N’envoyez pas de CV générique — générez un CV et une lettre de motivation adaptés à ce poste précis.

Passez les filtres ATS

Avantages offerts par ce poste

100% Medical coverage
401k with 4% match
Unlimited PTO

Résumé du poste

Wysh Financial, LLC. is seeking a Director of Security to lead our information security program and ensure regulatory compliance across SOC 2, NIST, and NAIC requirements. The role reports to the CISO and translates security strategy into day-to-day programs, controls, and incident responses.

This is a full-time, remote position based in the U.S. (EST/CST preferred) with a base salary of $190k–$220k. You will oversee security operations, vulnerability management, third-party risk, security

Qualifications

  • 8+ years of information security with at least 3 years in leadership or program management.
  • CISSP or CISM required; CEH/CCSP/CRISC preferred.
  • Experience managing SOC 2 Type II programs and security compliance audits.
  • Hands-on with SIEM platforms (Elastic or equivalent), vulnerability scanners, and EDR/XDR tools.
  • Strong knowledge of NIST CSF, ISO 27001, and cloud security best practices.
  • Experience with insurance cybersecurity requirements—NAIC Model #668 and state regulations preferred.
  • Proven experience leading security incident response.

Responsabilités

  • Lead information security operations: SIEM, threat detection, vulnerability scanning, pentesting, incident response.
  • Own SOC 2 Type II compliance program with auditors and evidence remediation.
  • Manage third-party/vendor risk management program and vendor security posture assessments.
  • Refine security awareness and training for all employees, with modules for operations, engineering, and leadership.
  • Oversee cloud security configurations, identity systems (SSO, PAM), and endpoints with IT teams.
  • Maintain information security policies, standards, and procedures.
  • Coordinate with CISO, CCO, and regulators on cybersecurity market conduct matters (NAIC).
  • Lead incident response planning: tabletop exercises, breach readiness, cyber insurance coordination.
  • Track and report security KPIs to CTO/CISO and executives.
  • Evaluate emerging security tech and advocate investments to improve posture.

Connaissances

Leadership
CISSP/CISM
SOC 2 Type II
SIEM
Vulnerability scans
EDR/XDR
NIST/ISO 27001
Cloud security
NAIC compliance
Incident response

Outils

Elastic SIEM
EDR/XDR tools

Description du poste

At Wysh, we’re not your average insurance company—we’re redefining financial protection for the modern world. Our purpose is to empower every person to live life to the fullest, with the confidence of financial protection. As an entrepreneurial team, we thrive on thinking outside the box, experimenting fearlessly, and delivering innovative solutions that challenge industry norms.

What sets us apart is our people: a dynamic mix of math nerd strategists, user-flow‑obsessed designers, results‑driven developers, and epic storytelling marketers. We love what we do and take work‑life balance and professional development as seriously as our products.

At Wysh, we dream big, safeguard futures, and inspire everyone—our customers and team alike—to aim high. Ready to join a company that’s redefining financial protection and making dreams a reality? Join us on this exciting journey, and let’s make an impact, one Wysh at a time.

The Role

The Director of Security is the operational leader of our information security program, reporting to the CISO. This role will translate our security strategy into day‑to‑day programs, controls, and incident response capability — owning vulnerability management, security operations, compliance certification programs (SOC 2, NIST), third‑party risk, and our security awareness program. As a licensed insurance carrier operating in 49 states, regulatory security compliance is mission‑critical, and this leader ensures our program is robust, documented, and audit‑ready at all times.

This is a full‑time, remote position based in the U.S. (EST or CST time zones preferred). The base salary range for this role is $190K – $220K, with final compensation determined by experience, skill set, and region.

What You’ll Do:

  • Lead the information security operations function: SIEM management, threat detection, vulnerability scanning, penetration testing program, and security incident response.
  • Own and maintain the company's SOC 2 Type II compliance program — coordinating with auditors, managing evidence collection, and remediating findings.
  • Participate in design and own operational management of the third‑party/vendor risk management program — assessing security posture of technology vendors, reinsurers, and distribution partners.
  • Continue to refine existing security awareness and training programs for all employees, with specialized modules for operations, engineering, and leadership teams.
  • Manage the security configuration of cloud environments, identity systems (SSO, PAM), and endpoint security tools in partnership with the IT and Infrastructure teams.
  • Assist with maintenance of the company's information security policies, standards, and procedures.
  • Coordinate with the CISO, Chief Compliance Officer, and state insurance regulators on cybersecurity‑related market conduct matters, including compliance with the NAIC Cybersecurity Model Law.
  • Lead the security incident response plan — including tabletop exercises, breach notification readiness, and cyber insurance coordination.
  • Track and report security KPIs to the CTO/CISO and executive team.
  • Research and evaluate emerging security technologies — recommending investments that improve the company's security posture.

What You’ll Bring:

  • 8+ years of information security experience, with at least 3 years in a security leadership or program management role.
  • CISSP, CISM, or equivalent security certification required; additional certifications (CEH, CCSP, CRISC) preferred.
  • Experience managing SOC 2 Type II programs and security compliance audits.
  • Hands‑on expertise with SIEM platforms (Elastic or equivalent), vulnerability scanners, and EDR/XDR tools.
  • Strong knowledge of NIST Cybersecurity Framework, ISO 27001, and cloud security best practices.
  • Experience with insurance industry cybersecurity requirements — NAIC Model #668, state‑specific regulations preferred.
  • Proven experience leading security incident response.

Diversity and Inclusion

Wysh is a proud equal opportunity employer that is committed to diversity and inclusion in and outside of the workplace. We strongly believe that everyone deserves a seat at the table and we support a culture where our people are empowered to be their authentic selves each and everyday.

We’re building a team that represents a variety of backgrounds, perspectives, and skills to reflect the world that we live in and the customers we serve. You are welcomed to apply for this role free of biases or discrimination regardless of your race, religion, color, sex, gender identity, sexual orientation, age, physical or mental disability, national origin, veteran status or any other basis covered by law.

A Great Team – We focus on hiring people from diverse backgrounds who are easy to get along with and fantastic teammates.

Flexible Work Schedule – Remote work schedule. We’re interested in what you contribute more so than when you do it.

Work Life Balance – Unlimited PTO, Paid Holidays, along with Paid Summer Fridays and Paid parental leave.

Competitive Compensation – The base salary for this role is $190,000 to $220,000 annually. Exact compensation range is determined based on your region, years of experience, and specific skill set using aggregate market data from PayScale.

Health & Wellness – We offer 100% Medical Care Coverage for you and generous contributions for family, Dental and Vision Coverage, Commuter and Parking Reimbursement, 401k with a 4% Match, Health and Wellness Reimbursement, Free talkspace membership, Voluntary Long‑term and Short‑term Disability, Life Insurance and FSA/HSA.

Career Development – We believe in upskilling our teams, providing each employee a $1,000 annual training allowance.

Friendly office environments – Two modern offices; one in Dumbo, Brooklyn and the other in Durham, NC, offering a variety of working spaces for individual or team collaboration with free meals and snacks.

Social events – Monthly culture events, celebrations, team outings and social hours.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self‑identification survey.Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiringprocess or thereafter. Any information that you do provide will be recorded and maintained in aconfidential file.

As set forth in Wysh’s Equal Employment Opportunity policy,we do not discriminate on the basis of any protected group status under any applicable law.

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection.As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measurethe effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categoriesis as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service‑connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Obtenez votre examen gratuit et confidentiel de votre CV.

ou faites glisser et déposez votre fichier ici.

Similar jobs

Postes similaires à comparer

Director of Security (Insurance)
Director of Security (Insurance)

Wysh • États-Unis

À distance
USD 190 000 - 220 000
Unlimited PTO
Paid Holidays
Paid Summer Fridays
+1
VP, Growth
VP, Growth

WithCoverage • New York (NY)

Sur place
USD 250 000 - 300 000
Equity
Comprehensive benefits
Pre-tax accounts
+4
Forward Deployed Engineer, Growth
Forward Deployed Engineer, Growth

With Coverage, Inc. • New York (NY)

Sur place
USD 140 000 - 170 000
Equity
Medical benefits
Time off
+1
Cybersecurity Incident Response & Threat Detection Analyst
Cybersecurity Incident Response & Threat Detection Analyst

Age-Solutions • Columbus (OH)

Sur place
USD 99 000 - 121 000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+6
Account Manager (ENT/Strategic) (Remote) (Austin, Texas)
Account Manager (ENT/Strategic) (Remote) (Austin, Texas)

KnowBe4 • Austin (TX)

À distance
USD 120 000 - 180 000
Bonuses
Adoption assistance
Tuition reimbursement
+2
Account Manager (ENT/Strategic) (Remote) (Austin, Texas)
Account Manager (ENT/Strategic) (Remote) (Austin, Texas)

Egress • États-Unis

À distance
USD 120 000 - 180 000
Monthly bonuses
Employee referral bonuses
Adoption assistance
+3
Cybersecurity Incident Response & Threat Detection Analyst
Cybersecurity Incident Response & Threat Detection Analyst

AGE Solutions • Columbus (OH)

Sur place
USD 110 000 - 140 000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+5
Cybersecurity Threat Hunter
Cybersecurity Threat Hunter

AGE Solutions • Columbus (OH)

Sur place
USD 99 000 - 121 000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+1
Cybersecurity Threat Hunter
Cybersecurity Threat Hunter

Age-Solutions • Columbus (OH)

Sur place
USD 99 000 - 121 000
26 Days Paid Leave
Performance Bonuses
401(k) with Match
+2
Security Engineering and Operations Manager
Security Engineering and Operations Manager

Asset Living • Dallas (TX)

Sur place
USD 140 000 - 170 000