Security Scorecard is looking to hire a Head of Corporate & Product Security. This key role will own the protection of our Corporate IT systems & raise the security bar of Security Scorecards products. The role is an opportunity to implement security programs from the ground up. Youll be guiding Security Scorecard to focus on the systems, services, & processes that protect our most valuable resources, communicate with leadership, legal, & software development teams. This role will report directly to the CTO, with access to the CEO, C-suite, & Board of Directors.
- Develop enterprise-wide security programs
- Train our staff about all aspects of Security
- Proactively monitor threats & take preventive measures
- Identify, report, & control incidents
- Own regulatory compliance such as Soc2, FedRamp, GDPR. FedRamp experience is a must have for this role.
- Integrate security best practices into our SDLC
- Communicate & report risks to Senior Leadership
- Hands on in implementing, installing, & operating security tools
- Working knowledge of MITRE ATT&CK techniques & common attack vectors
- Bias towards action. Why wait until tomorrow if something can be done today?
- Experience communicating & partnering with different levels of product organizations
- Passionate about establishing good testing practices, new tools/technologies, & improving processes
- Can influence through partnerships, instead of edicts
- Experience with on-premise & Cloud technologies
- Experience with FedRamp accreditation & compliance
- Strong strategy & program planning skills
- Passionate & Knowledgeable in security & dedicated to self-development
- Be data-driven & able to quantify impact & changes over time
Our Company Values
S: Solution-focused : we value people who come up with solutions, & not just point out problems.
C : Customer-centric is a crucial value we constantly keep in mind. We ask ourselves in each meeting how is what we are doing making customer lives better?
O : One Scorecard - We value people who have no ego, & want to win as a team.
R: Resilience - This is a hard road, & not an easy road : you need to cultivate the same resilience in the rest of your team.
E : Embody Security DNA- The more you learn about cybersecurity, the more you will be able to influence the company. We value people who are passionate about cybersecurity.
SecurityScorecard's SaaS based platform enables enterprises to instantly rate & understand the security risk of companies, non-intrusively & from an outside-in perspective. We use an A-F rating scale. Companies with a C, D or F rating are 5 times more likely to be breached or face compliance penalties than companies with an A or B rating.
Our platform is used by hundreds of customers for use-cases including self monitoring, vendor risk management, cyber insurance, board reporting, & M&A. Headquartered in New York City, we are funded by top investors like Sequoia Capital, Google Ventures, NGP, Moodys, Intel, & others. Our vision is to create a new language for companies & their partners to communicate, understand, & improve each others security posture.
SecurityScorecard was founded in 2013 by two former security leaders, Dr. Aleksandr Yampolskiy & Sam Kassoumeh, who were respectively, the CISO & Head of Security & Compliance at a large e-commerce retailer, Gilt Groupe. Dr. Yampolskiy, who has a PhD in cryptography, was also the CTO of BlogTalkRadio/Cinchcast & has held lead technology & security roles at Goldman Sachs, Oracle, & Microsoft. Mr. Kassoumeh also led Global Security at Federal-Mogul & has over ten years of cybersecurity experience. Together they were perplexed at the lack of visibility into risks involved in both their own environment & those who they needed to trust with sensitive information in order to conduct business. They wanted to find a way to see what hackers see.