Director of Information and Data Security

20 hours ago


Santa Clara, California, United States Eltropy Full time

Role Purpose
The Director of Information and Data Security will establish and lead Eltropy's IT and
Cybersecurity function, responsible for developing foundational systems, processes, and
governance across infrastructure, data protection, and compliance. This leader will drive
security maturity across the organization, balancing hands-on execution with long-term
strategic planning, and partnering with external GRC consultants to build a scalable security
and compliance framework aligned with industry standards (e.g., SOC 2, ISO

Key Responsibilities
IT and Infrastructure Security

  • Oversee endpoint management, asset inventory, and identity and access management
    (IAM).
  • Establish standards for device hardening, patch management, and secure configuration.
  • Define and manage the budget for all security and IT tools, services, and human capital,
    ensuring cost-effectiveness and alignment with the overall security roadmap.
  • Implement centralized visibility and control across systems and SaaS applications.

Cybersecurity and Data Protection

  • Lead threat detection, vulnerability management, and incident response operations.
  • Implement and maintain a Cloud Security Posture Management (CSPM) solution to
    monitor cloud infrastructure (AWS/Azure) for misconfigurations and compliance issues.
  • Deploy and tune SIEM/XDR solutions to enhance visibility and threat detection across
    environments.
  • Conduct regular penetration testing, track remediation, and drive security awareness
    programs.
  • Define and enforce data protection policies covering classification, encryption, and
    retention.

Governance, Risk, and Compliance (in partnership with GRC Consultant)

  • Partner with external GRC consultants to design and operationalize Eltropy's information
    security and compliance framework.
  • Translate consultant-driven recommendations into actionable internal controls, policies,
    and monitoring mechanisms.
  • Manage the Third-Party Risk Management (TPRM) program, including vendor due
    diligence, security questionnaires, and ongoing risk monitoring.
  • Maintain a centralized risk register and oversee remediation tracking.
  • Own operational compliance for frameworks such as SOC 2, ISO 27001, and GDPR.

Security Architecture and Product Collaboration

  • Work closely with Engineering and Product teams to embed security-by-design principles
    in SaaS architecture and cloud deployments.
  • Implement automated security testing (SAST/DAST) within the CI/CD pipeline to shift
    security left and reduce vulnerabilities early in the development lifecycle.
  • Review architecture and third-party integrations to ensure alignment with data security
    and privacy standards.

Incident Management and Business Continuity

  • Establish and operationalize the company's Incident Response Plan (IRP) and Business
    Continuity/Disaster Recovery (BCP/DR) framework.
  • Conduct tabletop exercises and post-incident reviews to enhance preparedness and
    learning.

Security Awareness and Culture

  • Develop and implement a company-wide security awareness program.
  • Partner with HR and Operations to ensure onboarding/offboarding includes security
    compliance and periodic training.
  • Foster a security-first culture emphasizing accountability and vigilance across teams.

Leadership and Department Setup

  • Build and lead a high-performing IT and Security team, including IT administrators and
    cybersecurity engineers.
  • Define structure, roles, and hiring priorities aligned with the company's growth stage.
  • Create a phased roadmap for security maturity, including technology adoption and process optimization.

Key Performance Indicators (KPIs)

  • Security Tool Coverage: Achieve at least X% deployment and agent coverage across all
    corporate and cloud assets within the first 6 months.
  • Vulnerability Remediation: Maintain average time-to-remediate critical and high
    vulnerabilities below X days.
  • Compliance Milestones: Achieve SOC 2 / ISO 27001 readiness within agreed timelines.
  • Asset Visibility: 100% endpoint and asset inventory completeness.
  • Incident Management: Reduction in mean time to detect (MTTD) and mean time to
    respond (MTTR) for incidents.
  • Team Ramp; Process Setup: Completion of key hires and operational processes within the first
    year.

Requirements

  • Independent, self-starter with strong ownership and execution bias.
  • Ability to prioritize and execute in a resource-constrained, fast-paced SaaS environment.
  • Strategic thinker with operational depth; able to balance long-term maturity goals with
    immediate risk mitigation.
  • Excellent communication skills with the ability to influence and align cross-functional
    stakeholders.
  • Proven experience setting up IT or cybersecurity programs in a SaaS or technology
    environment.
  • Strong understanding of endpoint protection, cloud infrastructure security (AWS/Azure),
    IAM, and network security.
  • Experience with SIEM and/or XDR deployment and tuning for threat detection and
    monitoring.
  • Familiarity with CSPM, SAST/DAST, and vulnerability management tools.
  • Knowledge of GRC frameworks (SOC 2, ISO and translating them into practical,
    auditable controls.

Reporting to: VP of Operations
Level: Senior Leadership

Direct Reports:
- IT Team
- Cybersecurity Engineer(s)



  • Santa Clara, California, United States WhiteDog Cyber Full time $23 - $29

    WhiteDog is seeking an Information Security Analyst to join our Security Operations Center team. The Analyst will help coordinate and report on cyber incidents impacting SOC-as-a-Service customers. This position involves critical duties and responsibilities that must continue to be performed during crisis situations and contingency operations, which may...


  • Santa Clara, California, United States Marvell Technology Full time $168,920 - $253,000

    About Marvell Marvell's semiconductor solutions are the essential building blocks of the data infrastructure that connects our world. Across enterprise, cloud and AI, and carrier architectures, our innovative technology is enabling new possibilities. At Marvell, you can affect the arc of individual lives, lift the trajectory of entire industries, and fuel...


  • Santa Clara, California, United States Palo Alto Networks Full time

    Company DescriptionOur MissionAt Palo Alto Networks everything starts and ends with our mission:Being the cybersecurity partner of choice, protecting our digital way of life.Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and...


  • Santa Clara, California, United States Infoblox Full time $234,365 - $365,310 per year

    DescriptionAt Infoblox, every breakthrough begins with a bold "what if." What if your ideas could ignite global innovation? What if your curiosity could redefine the future?  We invite you to step into the next exciting chapter of your career journey. Bring your creativity, drive, your daring spirit, and feel what it's like to thrive on a team big enough...


  • Santa Clara, California, United States NTT DATA Full time

    Make an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.Your day at NTT DATAThe Data Center...


  • Santa Clara, California, United States Palo Alto Networks Full time

    Our MissionAt Palo Alto Networks everything starts and ends with our mission:Being the cybersecurity partner of choice, protecting our digital way of life.Our vision is a world where each day is safer and more secure than the one before. We are a company built on the foundation of challenging and disrupting the way things are done, and we're looking for...


  • Santa Clara, California, United States Lensa Full time

    Lensa is a career site that helps job seekers find great jobs in the US. We are not a staffing firm or agency. Lensa does not hire directly for these jobs, but promotes jobs on LinkedIn on behalf of its direct clients, recruitment ad agencies, and marketing partners. Lensa partners with DirectEmployers to promote this job for NVIDIA. Clicking "Apply Now" or...


  • Santa Clara, California, United States Microsoft Full time

    Microsoft Silicon, Cloud Hardware, and Infrastructure Engineering (SCHIE) is the team behind Microsoft's expanding Cloud Infrastructure and responsible for powering Microsoft's "Intelligent Cloud" mission. SCHIE delivers the core infrastructure and foundational technologies for Microsoft's over 200 online businesses including Bing, MSN, Office 365, Xbox...


  • Santa Clara, California, United States NTT DATA Full time

    Make an impact with NTT DATAJoin a company that is pushing the boundaries of what is possible. We are renowned for our technical excellence and leading innovations, and for making a difference to our clients and society. Our workplace embraces diversity and inclusion – it's a place where you can grow, belong and thrive.Your day at NTT DATAThe Global...


  • Santa Clara, California, United States Vantage Data Centers Full time

    About Vantage Data CentersVantage Data Centers powers, cools, protects and connects the technology of the world's well-known hyperscalers, cloud providers and large enterprises. Developing and operating across North America, EMEA and Asia Pacific, Vantage has evolved data center design in innovative ways to deliver dramatic gains in reliability, efficiency...