Director of Security
ArbiterAbout the role
The Director of Security is responsible for protecting Arbiter’s systems, data, and users by leading a small security team while remaining highly hands-on with day-to-day security operations. This role combines leadership with technical expertise, including investigating potential threats, conducting penetration testing, managing security tools, and ensuring compliance with applicable security and privacy regulations. Candidate must reside in the United States.
Key Responsibilities
Hands-On Security Operations
· Actively monitor, investigate, and respond to potential security issues.
· Conduct penetration testing and vulnerability assessments on Arbiter’s systems.
· Manage, configure, and optimize security tools (e.g., SIEM, endpoint protection, firewalls).
Team Leadership
· Lead, mentor, and support a team of two Security Analysts.
· Establish clear processes for incident response, investigations, and reporting.
· Foster a culture of continuous learning and improvement within the team.
Policy & Compliance
· Maintain and update security policies and procedures in alignment with the Secure Control Framework.
· Ensure compliance with CCPA, GDPR, FERPA, and state-level privacy regulations.
· Manage evidence collection and reporting for compliance audits.
Risk Management & Incident Response
· Identify, assess, and mitigate security risks across infrastructure, applications, and data.
· Lead incident response efforts, including root cause analysis and remediation.
· Partner with IT, DevOps, and Engineering to strengthen defenses against evolving threats.
Awareness & Training
· Deliver security awareness training to employees, covering phishing, password hygiene, social engineering, and compliance requirements.
· Promote a proactive security mindset across the company.
Collaboration
· Work closely with IT, HR, Engineering, and other departments to embed security into daily operations.
· Provide security input during new technology initiatives, vendor assessments, and system changes.
Requirements- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- 7+ years of hands-on experience in information security, with at least 2 years in a leadership or team lead role.
- Strong technical skills in penetration testing, incident response, and security tool management.
- Knowledge of industry security frameworks and regulations (CCPA, GDPR, FERPA, SOC 2, etc.).
- Excellent problem-solving skills and the ability to balance technical detail with business impact.
- Relevant certifications preferred (CISSP, OSCP, CISM, CEH, etc.).
- Must be able to work in the United States without VISA sponsorship.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s