Neumo Logo

Neumo

Senior Director, Information Security (Remote)

Posted 20 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in TX, USA
Senior level
Remote
Hiring Remotely in TX, USA
Senior level
Own day-to-day execution of Neumo’s unified information security program across multiple business units and legacy environments. Lead GRC, AppSec, Cloud/Vulnerability, and SecOps teams; standardize tooling and processes; manage SOC 1, SOC 2, PCI DSS, FedRAMP High, and GovRAMP roadmaps; oversee audits, assessments, evidence collection, remediation, vendors, and authorization milestones; and report risks, status, and resourcing needs to the CISO.
The summary above was generated by AI


Job Summary:

Neumo is building a unified Information Security program across five lines of business and three legacy environments — Avenu, ITI, and GovOS. The CISO sets strategy and owns the board and executive relationship; the Senior Director, Information Security owns execution. This is a distinct, operational mandate: you run the program day to day, lead the four functional teams, make the working-level calls on tooling and process, and are personally accountable for the roadmap that gets us to SOC 1, SOC 2, PCI DSS, FedRAMP High, and GovRAMP.
 
This role exists because compliance commitments at this scale don't run on strategy alone — they run on someone who manages the leads, resolves the conflicts, and keeps evidence collection, scans, and assessments on schedule across three environments that don't yet operate the same way.


Duties and Responsibilities:

Team Leadership
  • Directly manage the four functional leads — GRC, AppSec, Cloud/Vulnerability, and SecOps — setting priorities, removing blockers, and holding them accountable to delivery.
  • Run the operating cadence for the team: weekly leads sync, sprint/quarter planning, and performance management for direct reports.
  • Build a consistent operating model across the four functions so GRC, AppSec, Cloud/Vuln, and SecOps work from shared priorities rather than in silos.
Cross-Entity Execution
  • Resolve tooling and process decisions at the working level across Avenu, ITI, and GovOS 
  • Own the standardization roadmap that brings three legacy environments onto common tooling, control sets, and operating procedures.
  • Act as the escalation point when legacy entities disagree on approach; make the call and move the work forward.
Compliance Program Operations
  • Own the operational roadmap behind SOC 1 and SOC 2: continuous evidence collection, control owners, and audit readiness ahead of annual audits.
  • Own PCI DSS operations: the annual assessment cycle plus quarterly scan cadence, remediation tracking, and scope management.
  • Drive the FedRAMP High authorization effort and the parallel GovRAMP pursuit — both multi-year, high-cost programs (FedRAMP High alone typically runs 12–24 months and $500K–$1M+) — translating authorization requirements into workstreams, milestones, and owners.
  • Maintain a single rolling roadmap across all frameworks so audit cycles, scan windows, and authorization milestones are sequenced, resourced, and visible — and don't collide.
  • Report program status, risks, and resourcing needs to the CISO with enough detail to support executive and board reporting.
Vendor & Audit Management
  • Serve as the day-to-day owner of external audit and assessment relationships (e.g., compliance advisory firms, QSAs, 3PAOs), keeping evidence requests, timelines, and findings moving.
  • Manage tooling vendors supporting GRC, vulnerability management, and security operations, including renewal and consolidation decisions across the three legacy stacks.


Education and Experience:
 

  • 10+ years in information security, with at least 4 years managing security teams or functional leads directly.
  • Direct experience operating through at least one SOC 2 or SOC 1 audit cycle and one PCI DSS assessment cycle as a control owner or program lead.
  • Experience with FedRAMP or GovRAMP authorization work — control implementation, SSP development, or 3PAO assessment support — strongly preferred.
  • Experience with vulnerability management platforms (e.g., Tenable) and WAF/cloud security tooling a plus


Knowledge, Skills and Abilities: 

  • Track record of standardizing security tooling or process across multiple business units, products, or post-merger environments.
  • Comfortable making and owning tooling/process decisions without escalating every call upward — this role is judged on throughput, not just judgment.
  • Working knowledge of NIST CSF 2.0 and how it maps to GRC, AppSec, Cloud/Vuln, and SecOps functions.


Work Environment:

  • Office setting with a moderate noise level.
  • The employee will work at an individual workstation, using a telephone and computer.


 Physical Demands
:

  • Must be able to remain seated for extended periods.
  • Regular use of a computer and other office machinery, such as printers and copy machines.
  • Occasional movement around the office.
  • Frequent communication via telephone.


Neumo Summary:

With the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.

Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.

Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.

Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.

Similar Jobs

11 Minutes Ago
In-Office or Remote
United States
155K-200K Annually
Senior level
155K-200K Annually
Senior level
Digital Media • Fintech • Information Technology • Machine Learning • Financial Services • Cybersecurity • Automation
Leads end-to-end marketing strategy and execution for Commercial and Corporate Banking, including client acquisition, retention, product adoption, digital campaigns, ABM, sales enablement, events, analytics, optimization, budgeting, and regulatory governance. Partners with senior banking, sales, data, and digital stakeholders to develop value propositions, integrated marketing plans, and measurable growth initiatives in a regulated B2B financial services environment.
Top Skills: Adobe AnalyticsDemandbaseMicrosoft CopilotExcelMicrosoft PowerpointMicrosoft WordPardotSalesforce
15 Minutes Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
81K-127K Annually
Mid level
81K-127K Annually
Mid level
Artificial Intelligence • Marketing Tech • Software
Lead technical client onboarding, migrations, solution design, integrations, data orchestration, troubleshooting, and project delivery for Movable Ink’s AI-powered personalization platform. Partner with clients and internal teams to implement custom workflows, APIs, webhooks, and data solutions. Conduct training and workshops, provide product expertise, advise on roadmap improvements, and support long-term client success across email and mobile marketing programs.
Top Skills: Adobe CampaignAdobe Journey OptimizerAIAirshipAPIsAttentiveBirdBloomreachBrazeCdpCheetah DigitalCordialCSSCustom AppsData LakesData WarehousesEpsilonETLHTMLIterableJavaScriptMachine LearningMovable Ink Da VinciMovable Ink StudioOracle ResponsysPythonSalesforce Marketing CloudSinchVibesWebhooksZeta
15 Minutes Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
66K-104K Annually
Junior
66K-104K Annually
Junior
Artificial Intelligence • Marketing Tech • Software
Manage end-to-end client implementations for Movable Ink’s Studio and Da Vinci platforms. Serve as the primary client and project contact, develop project plans, coordinate internal technical teams, configure and QA campaigns, provide platform training, resolve issues, and ensure launches meet client goals and KPIs. Partner with sales and solution architects to support retention and account expansion.
Top Skills: Adobe CampaignAdobe Journey OptimizerAirshipAPIsAttentiveBirdBloomreachBrazeCheetah DigitalCordialEpsilonHTMLIterableJavaScriptMovable Ink Da VinciMovable Ink StudioOracle ResponsysSalesforce Marketing CloudSinchVibesZeta

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account