Jobs and Careers
GA

Senior Director, Information Security Delivery - VM IR SS

Gainwell Technologies
Any city, FL, US, 99999, United StatesRemotefull_timeVerifiedPosted 14 Oct 2025
💰 $205,200/yr($143,600/yr$205,200/yr)

About the role

Be part of a team that unleashes the power of leading-edge technologies to help improve the health and well-being of those most vulnerable in our country and communities. Working at Gainwell carries its rewards. You’ll have an incredible opportunity to grow your career in a company that values work flexibility, learning, and career development. You’ll add to your technical credentials and certifications while enjoying a generous, flexible vacation policy and educational assistance. We also have comprehensive leadership and technical development academies to help build your skills and capabilities.

 

Summary

The Senior Director, Information Security Delivery is a transformative executive leader responsible for building and leading a world-class Vulnerability Management Program, a centralized Incident Response capability, and a high-performing Security Shared Services organization. Reporting directly to the VP, Deputy Chief Business Information Security Officer, this role will drive enterprise-wide risk reduction, operational excellence, and client differentiation through scalable, standardized, and measurable security practices. This leader will be instrumental in elevating the maturity of the organization’s security programs, centralizing embedded resources, and delivering measurable business value through security innovation and execution.

 

Your role in our mission

  • Build, lead, and run a dedicated vulnerability management team, including analysts, engineers, and program managers, with a strong emphasis on cross-functional collaboration across infrastructure, application, cloud, and business teams.
  • Develop and implement a comprehensive vulnerability lifecycle framework, encompassing identification, prioritization, remediation, and reporting, aligned with business risk and regulatory requirements.
  • Drive measurable risk reduction through automation, prioritization based on business impact, and integration with threat intelligence and incident response.
  • Continuously improve program maturity and effectiveness, leveraging metrics, benchmarking, and innovation to position the organization as a leader in vulnerability management.
  • Utilize technology to enhance the vulnerability management program, including the selection and implementation of tools for vulnerability scanning, assessment, and reporting.
  • Establish vulnerability management as a strategic enterprise function, transforming it from a reactive process into a proactive, risk-reducing capability that serves as a competitive differentiator for clients.
  • Design and operationalize a centralized incident response function, capable of rapid detection, containment, and recovery from security incidents across all accounts.
  • Develop and maintain incident response playbooks, escalation protocols, and communication plans tailored to various threat scenarios and business impacts.
  • Lead response efforts for high-severity incidents, coordinating technical and business stakeholders to ensure timely resolution and root cause analysis.
  • Establish post-incident review processes to capture lessons learned, drive continuous improvement, and enhance organizational resilience.
  • Ensure compliance with legal, regulatory, and contractual obligations, including breach notification and forensic investigation requirements.
  • Lead the centralization of embedded security analysts and engineers into a unified Security Shared Services organization, driving standardization, scalability, and efficiency.
  • Implement a shared services operating model, including intake processes, service catalogs, performance metrics, and capacity planning.
  • Foster a culture of excellence and accountability, ensuring shared services staff are empowered, supported, and aligned with enterprise security goals.
  • Drive process optimization and automation, reducing operational overhead and enabling faster, more consistent service delivery.
  • Collaborate with account teams, ISO leaders, and business stakeholders to ensure seamless integration and high client satisfaction.
  • Lead the advancement of security program maturity across vulnerability management, incident response, and shared services using the NIST Cybersecurity Framework and other industry standards.
  • Conduct regular maturity assessments, identifying gaps, benchmarking against peers, and prioritizing initiatives to elevate program effectiveness.
  • Develop and execute multi-year maturity roadmaps, with clear milestones, KPIs, and business alignment.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Gainwell Technologies

View company profile →