עיון בכל המשרות

Director of IT & Information Security

נמצא אצל Checkmarx

מוזכר במשרה זו

תיאור

Who are we? Checkmarx is the AI-powered application security leader helping the world’s most security-conscious enterprises secure the software that powers modern life. For more than two decades, our unified platform and services have helped organizations protect human- and AI-generated code from the first line through runtime, reducing risk across applications, cloud, and the software supply chain without slowing innovation.​ ​ We’re trusted by 1,600+ customers in 70+ countries, including some of the largest enterprises and governments in the world. Guided by research-led innovation and a developer-first mindset, we help every developer, security team, and enterprise build software that is risk-free by design. What are we looking for? Checkmarx is seeking a Strategic Director, IT & Information Security to own and scale our global corporate IT function and enterprise security program. This is a Director level leadership role, carrying full accountability for a significant IT and security budget, a global team, and the systems, projects, and controls that keep the company running securely at scale. You will own the delivery of IT services and infrastructure projects company-wide, while directing the design, implementation, and continuous improvement of our corporate security program — including security systems, threat modeling, and offensive security testing. You will partner closely with the Directors of GRC and DevSecOps, and report directly into the CIO/CISO, to ensure IT, security, compliance, and product security efforts are aligned, resourced, and mutually reinforcing. Given the scope and budget accountability of this role, it is positioned and compensated at the upper end of our Director/senior-leadership band How will you make an impact? ·Own the global IT & Security strategy, P&L, budgets, roadmap, and operating model, balancing reliable day-to-day operations with modernization, automation, and digital transformation. ·Lead the global IT organization and core technology services, including infrastructure, networks, systems, service desk, end-user computing, IAM, and collaboration platforms; establish SLAs/KPIs and drive service quality, efficiency, and employee experience. ·Lead major technology programs and transformations, including infrastructure modernization, migrations, workplace technology, M&A integrations, and other cross-functional initiatives, ensuring delivery on scope, time, and budget. ·Build and scale a high-performing global IT organization while managing strategic vendors, contracts, commercial negotiations, and technology costs. ·Lead corporate security operations and strategy across endpoint, network, email, identity, SIEM/SOC, vulnerability management, cloud environments, security architecture, and security awareness. · Own security risk and testing programs, including threat modeling, penetration testing, red-team engagements, vulnerability remediation, and security monitoring. ·Lead security incident response and crisis management, including detection, containment, root-cause analysis, post-incident reviews, business continuity, and disaster recovery. ·Partner with GRC and DevSecOps leadership to align IT and security operations with enterprise risk, compliance, and application security requirements, including SOC 2, ISO 27001, and GDPR. ·Provide executive and Board/Audit Committee visibility into IT and security posture, risks, budgets, and strategic priorities, and lead IT & Security due diligence for M&A, partnerships, and major vendors. What is needed to succeed? ​ • 10+ years of progressive experience across IT operations/infrastructure and information security, including 4+ years leading teams at a Director level or above, ideally with ownership of budgets in the multiple millions of dollars. • Demonstrated experience owning and managing a significant IT/security budget end-to-end — planning, forecasting, vendor negotiation, and board/executive-level reporting on spend and ROI. • Proven track record leading large-scale, global enterprise IT programs end-to-end, from scoping through delivery and adoption, including programs with multi-million-dollar budgets. • Deep, hands-on knowledge of corporate security systems (EDR/XDR, SIEM, IAM/SSO, network security, DLP, email security) and modern security operations practices. • Demonstrated experience running or directing threat modeling programs (e.g., STRIDE, PASTA, or equivalent frameworks) and penetration testing / red-team engagements at enterprise scale. • Strong understanding of security frameworks and regulatory requirements relevant to a global SaaS/software company (SOC 2, ISO 27001, NIST, GDPR, or similar), and the ability to translate them into operational practice alongside a GRC function. • Executive-level communication and stakeholder management skills • Relevant certifications are a plus: CISSP, CISM, OSCP, GPEN, or equivalent. Checkmarx offers a great work environment, professional development, challenging careers, competitive compensation, great work-life balance, as well as great benefits and perks throughout the year. Checkmarx is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, or other characteristics protected by law. ​

קבלו את המשרות האלה במייל

משרות חדשות במרחוק / היברידי (ישראל) — קבלו את החדשות כל בוקר.

בלי חשבון, בלי סיסמה. מייל אחד בבוקר, רק כשיש משהו חדש. הסרה בלחיצה אחת.

עיון בכל המשרות