Director, Information Security
Varsity TutorsAbout the role
Nerdy is looking for a seasoned and highly skilled Director of Information Security to join our team. This role is pivotal in safeguarding our organization's information assets, developing and implementing robust security strategies, and ensuring compliance with regulatory requirements. The ideal candidate will have a strong background in information security, risk management, and team leadership.
About Nerdy:
Nerdy (NYSE: NRDY) is a leading platform for live online learning, with a mission to transform the way people learn through technology. The Company’s purpose-built proprietary platform leverages technology, including AI, to connect learners of all ages to experts, delivering superior value on both sides of the network. Nerdy’s comprehensive learning destination provides learning experiences across 3,000+ subjects and multiple formats—including one-on-one instruction, small group classes, large format group classes, and adaptive self-study. Their proprietary platform leverages AI to personalize the experience for Learners of all ages —from kindergarten to professional—in academic, test prep, enrichment, and certification subjects. Nerdy’s flagship business, Varsity Tutors, is one of the nation’s largest platforms for live online tutoring and classes. Its solutions are available directly to students and consumers, as well as through schools and other institutions. Learn more about Nerdy at https://www.nerdy.com/.
Nerdy’s shareholder letters below explain the product and strategy and are the most effective way to learn about what the company is building.
What You Bring:
- You bring 10+ years of security experience developing and leading company wide security, risk management, and other related programs.
- You bring a Bachelor's degree in computer science, engineering or equivalent required.
- You bring demonstrated success as a security leader in a consumer facing business of substantial scale and complexity.
- You bring an in-depth understanding of all related compliance issues in a consumer business to include Privacy, GDPR, CCPA, SOX, NIST, etc.
- You bring demonstrated understanding of the use of data and analytics in breach detection, monitoring and forensics of the security environment.
- You bring deep expertise in audit and assessment methodologies, procedures, and policies that relate to information networks, systems and applications.
- You bring strong verbal and written communication skills, especially in the areas of presentation and interaction with people at all levels across the organization.
- You bring an ability to inspire investment from the broader population of employees to ensure active participation and championing of key security initiatives.
- You bring a background in software engineering at product development companies, preferably SaaS or PaaS and experience in start-ups as well as larger enterprises.
- You bring experience with modern cloud infrastructure such as AWS and GCP
- You bring experience with automation to scale yourself and the team to identify, audit, and remediate.
- You bring decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one
Nice to Haves:
- CISA- Certified Information Systems Auditor (auditing, monitoring, and assessing IT and business systems).
- CISM - Certified Information Security Manager (affirms ability to assess risks, implement effective governance, and proactively respond to incidents).
- CRISC - Certified in Risk and Information Systems Control - IT risk management
What You Will Do:
- You will define the functional strategies and specific objectives around policies and procedures to support overall company security to assure the safety of physical and digital assets from internal and external threats.
- You will maintain and present documentation as it relates to cloud security operations, processes, standards, architectures, and provide guidance for security remediation to business and engineering partners by demonstrating real, practical risk and value.
- You will define the types of security education and training needed, partnering with HR to ensure compliance.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s