Director, Information Security & IT
KasewareAbout the role
Location: Denver, Colorado. This is a hybrid role in which employees are expected to work 3 days in-office and 2 days at home.
Do you love building the security and IT foundations that mission-critical software runs on, and do you want to know that your work helps keep communities safer? Kaseware builds case management and investigations software trusted by law enforcement, government, and corporate security teams. The trust those customers place in us – and our continued ability to operate in the most demanding compliance environments – depends on a strong information security and IT foundation. That is where you come in.
We are looking for a Director of Information Security & IT to lead Kaseware’s combined security, compliance, and enterprise IT functions. Reporting to the VP of Product & Technology, you will be the designated Information Security Officer (ISO) for the company and accountable for the controls, audits, and continuous monitoring that keep us authorized to serve our customers. You will lead a small but dynamic team and own the day-to-day health of our enterprise IT environment endpoints, identity, Microsoft 365, and the corporate network, alongside the security and compliance program.
Job Type: Full-time, Exempt
Responsibilities and Duties:
Information Security Officer (ISO) Role:
- Serve as the named Information Security Officer (ISO), with delegated authority for control implementation, evidence collection, and ongoing attestation
- Partner with the executive team on overall security strategy, risk posture, and executive reporting to the leadership team
Compliance & Audit Program:
- Own the compliance program for Kaseware’s active certifications and pursuits, including but not limited to:
- FedRAMP
- SOC 2 Type II
- ISO/IEC 27001
- State and federal CJIS
- StateRAMP and TxRAMP
- Manage 3PAO and external auditor engagements end to end; planning, evidence collection, walkthroughs, findings, and remediation tracking
- Maintain the System Security Plan (SSP), Plan of Action & Milestones (POA&M), and continuous monitoring artifacts
- Author and maintain company security policies, standards, and procedures; perform technical writing as needed
- Review customer contracts, RFP responses, and partner agreements for compliance and security obligations
Enterprise IT:
- Lead enterprise IT operations across endpoint management (Mac and Windows, MDM, patching, lifecycle), identity and access management (Entra ID, SSO, SCIM, joiner/mover/leaver), Microsoft 365, and the corporate network
- Own employee onboarding and offboarding, IT support, and SaaS administration for the corporate environment
- Drive secure-by-default IT engineering – configuration baselines, vulnerability management, asset and license management, and access governance – in alignment with FedRAMP, CJIS, and ISO 27001 control requirements
Risk & Incident Response:
- Own the security incident response program – playbooks, tabletop exercises, communications, and post-incident review – for both security events and compliance violations
- Coordinate cross-functional response during security incidents, breaches, and compliance escalations; document outcomes and report to leadership and regulatory bodies as required
- Use lessons learned from incidents to evolve policies, controls, and tooling; integrate findings into continuous monitoring and the POA&M
- Partner with Engineering on application security findings (penetration tests, SAST/DAST, container scans) where corporate or compliance reporting is required; AppSec ownership remains with Engineering
Team Leadership:
- Lead, mentor, and develop a four-person team
- Recruit and onboard new team members as the program grows; conduct performance reviews and career development planning
- Lead company-wide security awareness, new-hire training, and role-specific training programs
- Present compliance posture, audit results, and risk findings to executive leadership and, where appropriate, customers and regulators
- Support the Sales team on customer-facing security and compliance requirements in RFPs, security questionnaires, and customer audits
Required Education:
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering, or a related field, or equivalent professional experience.
Required Skills & Experience:
- 10+ years of progressive experience in information security, IT, or compliance roles, with at least 4+ years in a leadership role managing people
- Demonstrated experience as a named ISO, securi
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s