drjobs Sr. Director, Cybersecurity

Sr. Director, Cybersecurity

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Singapore - Singapore

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

We are Bugcrowd. Since 2012 weve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers with our patented data and AI-powered Security Knowledge Platform. Our network of hackers brings diverse expertise to uncover hidden weaknesses adapting swiftly to evolving threats even against zero-day exploits. With unmatched scalability and adaptability our data and AI-driven CrowdMatch technology in our platform finds the perfect talent for your unique fight. We aim to create a new era of modern crowdsourced security that outpaces threat actors. Unleash the ingenuity of the hacker community with Bugcrowd visit . Based in San Francisco and New Hampshire Bugcrowd is supported by General Catalyst Rally Ventures Costanoa Ventures and others.

We specifically seek a hands-on technical security leader. You bring experience building security monitoring reference architectures deploying tools integrating platforms assessing modern cloud-native applications and infrastructure - and leading teams executing that mission successfully. You lead with an open mind a can-do attitude seek truth and alignment over winning arguments and see incident response as an opportunity to learn grow and improve partnership across our global teams.

Program Leadership

  • Define the Cyber Security Strategy for Bugcrowd and identify areas of improvements to the threat landscape internal risk tolerance objectives and/or compliance objectives.
  • Ensure the technical aspects of vendor acquisitions and tools are safe for Bugcrowds use in unison with the IT and compliance teams.
  • Assess corporate technology systems determine strategy for changes enhancement and improvements; recommend and implement the same from the perspective of cyber security.
  • Carry out and fulfill the cyber security strategy of bugcrowd proactively improving the security posture with time.
  • Work with GRC to assist in designing develop implement and coordinate areas of policies and procedures for compliance with SOC-2 NIST 800-53v4 ISO27001ISO27018 and FedRAMP.
  • Represent Bugcrowd in the internal and external audits for SOC-2 ISO27001 and ISO27018.

AppSec and Product Security Leadership

  • Manage Bugcrowds bug bounty program ensuring that clients have a standard to aspire to when running their own bounty programs.
  • Analyze new features prior to development or launch to ensure the security measures in place are sufficient for the project. (security architecture and security testing)
  • Manage the access controls for Bugcrowds production codebase (GitHub).
  • Approve and analyze authorisation requests to production data (AWS GitHub Tableau etc.).
  • Perform regular audits of Bugcrowds cloud infrastructure alongside helping with architecture of any cloud solutions from the security perspective.
  • Manage and audit all vulnerability scans (internal and external) for all of Bugcrowds systems (Qualys and Nessus).
  • Proactively test and identify issues within Pull Requests and production to find issues (code review & penetration testing).
  • Automate security tasks to proactively identify and fix security issues within Bugcrowd. (Python golang JS Ruby)
  • Perform configuration management upon all Bugcrowd systems (IT and cloud).
  • Perform code audits on new features patches etc.

Security Operations Detection and Incident Response

  • Perform IR for all parts of the business (on-call 24x7) and perform root cause analysis upon the incidents to properly mitigate them in the future. Aid with forming an Incident Response Plan (IRP) based on these incidents.
  • Perform threat intelligence to proactively find issues relating to Bugcrowds security posture.
  • Plan implementation of security controls in unison with the required teams (infra eng secops IT compliance Researcher Success (RS) etc.).
  • Monitor the security controls for all of Bugcrowds systems and build a team to do the same. (SIEM usage)
  • Perform malware analysis on any potential malware should the forensic requirements arise during IR.
  • Coordinating red team engagements against Bugcrowd and implementing security controls to mitigate any issues found.
  • Develop security awareness materials for all roles within the Bugcrowd organisation.
  • Aid the Legal team with GDPR related issues from researchers and programs.

Management and Team Leadership

  • Perform table top exercises within the Bugcrowd organization to ensure the organization is prepared for future threats.
  • Aid with business continuity testing since the internal cybersecurity team plays a major role within the process.
  • Present findings and observations to the ISMS committee.
  • Portray and represent the technical controls and engineering areas within the ISMS committee (requirement of ISO27001).

Supervisory Responsibility

  • Lead and manage a team of internal cybersecurity professionals.
  • Train and grow the security team with objectives that are defined measured and monitored.
  • Support Security Leadership with delegated responsibilities as requested.
  • Take a proactive collaborative and respected leadership role in the Company to galvanize support of a robust efficient and secure technology organization.
  • Manage a team of hungry and fast growing security professionals with both strong attack and defense skills.

Knowledge Skills and Abilities

  • Proven work experience leading Cyber Security (penetration testing red teaming GRC IR secure development and security architecture) in a startup and growing with the organization.
  • Excellent knowledge of technical security controls including cloud web application infrastructure IT and compliance.
  • Experience in data governance data architecture data flow and system architecture to optimize the same.
  • Hands-on experience with penetration testing red teaming and security patch bypass testing.
  • Ability to work independently and must have strong organizational and communication skills.
  • Systems / Software (detailed knowledge of the following stack): Mac OS Python JavaScript Ruby Golang Java Kotlin Postgres GSuite Cisco Umbrella Netskope Crowdstrike GitHub AWS Heroku Cloudflare DataDog JAMF etc.
  • Familiarity with Jira is a plus.
  • Experience related to and assistance with ISO27001 ISO27018 NIST 800-53v4 and SOC2 audits is compulsory.
  • Degree in Computer Science cyber security MIS or equivalent experience desirable but not required.
  • Experience in cyber security with demonstrations of responsibility and technical excellence.
  • Must be eager to work hard to learn many new skills solve problems and integrate tightly with the rest of the team.
  • Willingness to support a global organization with limited staff via off hours activity while maintaining a healthy work-life balance.

Working Conditions and Physical Requirements

  • The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
  • Sitting and / or standing - Must be able to remain in a stationary position 50% of the time
  • Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
  • Environment - remote work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified keeping with our commitment Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations. Accordingly if reasonable accommodation is required to fully participate in the job application or interview process to perform the essential functions of the position and/or to receive all other benefits and privileges of employment please contact HR at.

Culture

At Bugcrowd we are solving security threats and vulnerabilities that are relevant to everyone therefore we believe solving these problems takes all kinds of backgrounds. We value the perspectives and experiences people from underrepresented backgrounds bring.

Disclaimer

This position has access to highly confidential sensitive information relating to the technologies of Bugcrowd. It is essential that the applicant possess the requisite integrity to maintain the information in the strictest confidence.

The company is authorized to obtain background checks for employment purposes under state and federal law. Background checks will be conducted for positions that involve access to confidential or proprietary information (including trade secrets).

Background checks may include Social Security verification prior employment verification personal and professional references educational verification and criminal history. Applicants with conviction histories will not be excluded from consideration to the extent required by law.


Equal Employment Opportunity:

Bugcrowd is EOE Disability/Age Employer.

Individuals seeking employment at Bugcrowd are considered without regards to race color religion national origin age sex marital status ancestry physical or mental disability veteran status gender identity or sexual orientation.


Apply at: Experience:

Exec

Employment Type

Full Time

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.