Director, Information Security (Remote, US)
OpenlyAbout the role
Why Openly
Openly is rebuilding insurance from the ground up. We are re-envisioning and enhancing every aspect of the customer experience. Doing this requires a rapidly growing team of exceptional, curious, empathetic people with a wide range of skill sets, spanning technology, data science, product, marketing, sales, service, claims handling, finance, etc.
The Openly Difference
We created Openly because we saw an evident gap in the market for premium insurance made simple. Consumers deserve more complete coverage at competitive prices.
- The Price Difference: Using cutting-edge data and technology, we provide you with customizable, competitive prices to protect your most valuable assets.
- The Policy Difference: Coverages are truly customizable to meet your individual protection needs, for both standard coverages and optional add-ons.
- The Experience Difference: From tailored claims handling to highly responsive customer service, we are focused on making the home insurance purchasing process a better overall experience.
Welcome to your next adventure.
At Openly, our people are just as important as our product. For us, collaboration, communication, and work-life balance are more than nice-to-haves— they’re the must-haves that make us who we are. We believe a great company is the result of a shared set of values, so we look for these qualities in every candidate we hire.
- Integrity
- Empathy
- Teamwork
- Curiosity
- Urgency
We've designed our hiring process with you, the candidate, in mind. At every step, you have the chance to present your strengths and learn more about what makes Openly a great place to work.
We're committed to Diversity, Equity, & Inclusion
We embrace individuality and believe diverse teams are winning teams. Our commitment to inclusion across race, gender, age, religion, identity, and experience drives us forward every day.
Job Details
As the Director of Information Security at Openly, you will be responsible for maintaining and maturing the company's security program. This involves collaborating with cross-functional teams to identify and mitigate risks, establishing security policies and procedures, and ensuring compliance throughout the organization. You will apply a risk-informed approach to security and compliance, enabling the business to operate safely and securely.
Key Responsibilities
- Develop and execute a comprehensive information security roadmap in collaboration with technology leadership and compliance leadership.
- Provide oversight for security governance and risk management, including risk assessments, vulnerability management, and incident response planning.
- Promote a culture of security awareness throughout the organization by conducting training sessions and awareness campaigns.
- Provide regular updates and reports to senior management and stakeholders on the state of information security within the organization.
- Lead SOC II Type II audit including audit coordination, controls, and evidence collection.
- Evaluate and manage security risks associated with third-party vendors and service providers.
- Establish and maintain information security policies, standards, and procedures in compliance with relevant industry regulations (e.g., GDPR, PCI DSS, state Insurance Data Security laws) and best practices.
Qualifications
- Education: BS degree in Computer Science, IT, related technical discipline or equivalent years of experience.
- Experience
- 8+ years of experience in information security roles with a balance of management, compliance, and technical expertise.
- Proven management abilities
- Experience guiding and growing teams of teams, balancing security, compliance and engineering needs with the needs of the business.
- Demonstrated ability to leverage resources and teams to deliver multiple projects from start to finish in reasonable overlapping time frames
- Experience developing a strategy or roadmap for your teams
- Proven experience leading SOC II audits and evidence collection
- Familiarity and willingness to work with Agile methodologies
- Excellent written and verbal communication
- CISSP, CISM, or other cybersecurity certifications preferred, but not required
- Working knowledge of one or more public cloud technologies (AWS, Azure, Google Cloud) and information security in a hybrid
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s
Similar roles
Director, Middle Market Business Development - Commercial Lines (Middle Market Insurance Production Underwriting Director)
Nationwide
$255,000/yr
Director, Digital Marketing
Warner Music Group
$120,000/yr
Account Director, Sports
NBCUniversal
$170,000/yr