Director- Information Security
CommvaultAbout the role
About Commvault
Commvault (NASDAQ: CVLT) is the gold standard in cyber resilience. The company empowers customers to uncover, take action, and rapidly recover from cyberattacks – keeping data safe and businesses resilient. The company’s unique AI-powered platform combines best-in-class data protection, exceptional data security, advanced data intelligence, and lightning-fast recovery across any workload or cloud at the lowest TCO. For over 25 years, more than 100,000 organizations and a vast partner ecosystem have relied on Commvault to reduce risks, improve governance, and do more with data.
JOB DESCRIPTION:
The Director of Information Security reports directly to the CISO and will be responsible for executing Commvault’s Security strategy for information security. We are looking for a leader that has demonstrated successful experience building and evolving information security organizations to scale alongside the organizations that they supported. The individual should be well versed in leading global teams, Identity Access Management, Cloud Security and the latest trends in tools, processes, governance, and compliance. The InfoSec Leader will review current data security procedures, identify new areas of risk, and develop appropriate mitigating controls that are aligned with business objectives. The InfoSec Leader will work with leaders of the IT, Legal, Finance and Product teams to foster a cross collaborative security culture. The InfoSec Leader will be an advocate for security and privacy best practices and drive appropriate communications and training within or outside the organization. In addition, the InfoSec Leader will assist with regulatory matters related to information security in partnership with Legal, Compliance and the applicable business groups.
Position Responsibilities
- Develops, implements, and executes a holistic information security program to ensure appropriate levels of confidentiality, integrity, availability, safety, privacy, and recovery of information by Commvault.
- Builds operational plans to create consistent and scalable processes that supports vision for security program.
- Works across businesses and functions groups to understand needs and recommends physical and technical information security best practices; Regularly lead vulnerability and security assessments across the firm and implement recommendations based on findings.
- Support as needed, responses to security incidents, remediation, as well as proposing solutions to anticipate, prevent, or mitigate future incidents.
- Stays abreast of all emerging information security threats and vulnerabilities and advises the teams accordingly.
- Develops and implements strategies and trainings to increase security awareness of employees.
- Well versed in global compliance requirements. Keep Commvault compliant against its certifications and other regional requirements
- Work with business stakeholders to build, maintain, test and operate Business Continuity plans.
- Manages a team of Security Engineering, Identity & Access Management and Threat & Vulnerability Management.
Position Requirements
- Qualifications
- 10+ years of experience in information security with 5+ years leading Information Security teams
- 5+ years of hands-on Engineering & Vulnerability Management experience.
- Executive level presence and communication skills as this role requires working closely with leaders from various lines of business.
- Proven track record of designing, implementing, and leading information security programs.
- A strong operational & technical background for on premise and cloud-based security models.
- Prior experience with information security testing, auditing, and threat detection.
- Industry related certifications (e.g., CISSP, CISM, CRISC, OSCP) preferred.
- Technical Skills
- Experience with various security tools, frameworks, and standards.
- Experience with Cloud Service Providers and Security Architectures
- Experienced with Security testing methodologies.
- Windows Server/ Desktop – Domain Services
- Intrusion Detection System, Intrusion Prevention Systems
- Antivirus and Endpoint Detection and Response tools
- Experienced with Agile, Scrum & Kanban methodologies a plus
- Leadership Skills
- Collaborative, cross-functional leader who builds consensus when working with business and technology stakeholders and across business groups.
- Highly developed critical thinking and analytical skills with the ability to absorb a large amount of information, summarizing key issues, trends, implications, and risks.
- Strategic thinker, passionate about identifying oppor
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s