Wysh Logo

Wysh

Director of Security

Posted 20 Minutes Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
190K-220K Annually
Senior level
Remote
Hiring Remotely in United States
190K-220K Annually
Senior level
Leads the company’s information security operations and reports to the CISO. Oversees SIEM, threat detection, vulnerability management, penetration testing, incident response, SOC 2 Type II compliance, third-party risk, security awareness, cloud and endpoint security, and regulatory cybersecurity coordination. Manages security policies, breach readiness, tabletop exercises, KPIs, audits, and emerging technology evaluations while partnering with IT, infrastructure, compliance, regulators, and executive leadership.
The summary above was generated by AI

Our Company

At Wysh, we’re not your average insurance company—we’re redefining financial protection for the modern world. Our purpose is to empower every person to live life to the fullest, with the confidence of financial protection. As an entrepreneurial team, we thrive on thinking outside the box, experimenting fearlessly, and delivering innovative solutions that challenge industry norms.

What sets us apart is our people: a dynamic mix of math nerd strategists, user-flow-obsessed designers, results-driven developers, and epic storytelling marketers. We love what we do and take work-life balance and professional development as seriously as our products.

At Wysh, we dream big, safeguard futures, and inspire everyone—our customers and team alike—to aim high. Ready to join a company that’s redefining financial protection and making dreams a reality? Join us on this exciting journey, and let’s make an impact, one Wysh at a time.

The Role

The Director of Security is the operational leader of our information security program, reporting to the CISO. This role will translate our security strategy into day-to-day programs, controls, and incident response capability — owning vulnerability management, security operations, compliance certification programs (SOC 2, NIST), third-party risk, and our security awareness program. As a licensed insurance carrier operating in 49 states, regulatory security compliance is mission-critical, and this leader ensures our program is robust, documented, and audit-ready at all times.

This is a full-time, remote position based in the U.S. (EST or CST time zones preferred). The base salary range for this role is $190K – $220K, with final compensation determined by experience, skill set, and region.

What You’ll Do:

  • Lead the information security operations function: SIEM management, threat detection, vulnerability scanning, penetration testing program, and security incident response.
  • Own and maintain the company's SOC 2 Type II compliance program — coordinating with auditors, managing evidence collection, and remediating findings.
  • Participate in design and own operational management of the third-party/vendor risk management program — assessing security posture of technology vendors, reinsurers, and distribution partners.
  • Continue to refine existing security awareness and training programs for all employees, with specialized modules for operations, engineering, and leadership teams.
  • Manage the security configuration of cloud environments, identity systems (SSO, PAM), and endpoint security tools in partnership with the IT and Infrastructure teams.
  • Assist with maintenance of the company's information security policies, standards, and procedures.
  • Coordinate with the CISO, Chief Compliance Officer, and state insurance regulators on cybersecurity-related market conduct matters, including compliance with the NAIC Cybersecurity Model Law.
  • Lead the security incident response plan — including tabletop exercises, breach notification readiness, and cyber insurance coordination.
  • Track and report security KPIs to the CTO/CISO and executive team.
  • Research and evaluate emerging security technologies — recommending investments that improve the company's security posture.

What You’ll Bring:

  • 8+ years of information security experience, with at least 3 years in a security leadership or program management role.
  • CISSP, CISM, or equivalent security certification required; additional certifications (CEH, CCSP, CRISC) preferred.
  • Experience managing SOC 2 Type II programs and security compliance audits.
  • Hands-on expertise with SIEM platforms (Elastic or equivalent), vulnerability scanners, and EDR/XDR tools.
  • Strong knowledge of NIST Cybersecurity Framework, ISO 27001, and cloud security best practices.
  • Experience with insurance industry cybersecurity requirements — NAIC Model #668, state-specific regulations preferred.
  • Proven experience leading security incident response.

Diversity and Inclusion

Wysh is a proud equal opportunity employer that is committed to diversity and inclusion in and outside of the workplace. We strongly believe that everyone deserves a seat at the table and we support a culture where our people are empowered to be their authentic selves each and everyday.

We’re building a team that represents a variety of backgrounds, perspectives, and skills to reflect the world that we live in and the customers we serve. You are welcomed to apply for this role free of biases or discrimination regardless of your race, religion, color, sex, gender identity, sexual orientation, age, physical or mental disability, national origin, veteran status or any other basis covered by law.

Benefits

A Great Team – We focus on hiring people from diverse backgrounds who are easy to get along with and fantastic teammates.

Flexible Work Schedule – Remote work schedule. We’re interested in what you contribute more so than when you do it.

Work Life Balance – Unlimited PTO, Paid Holidays, along with Paid Summer Fridays and Paid parental leave.

Competitive Compensation – The base salary for this role is $190,000 to $220,000 annually.  Exact compensation range is determined based on your region, years of experience, and specific skill set using aggregate market data from PayScale.

Health & Wellness – We offer 100% Medical Care Coverage for you and generous contributions for family, Dental and Visio​​n Coverage, Commuter and Parking Reimbursement, 401k with a 4% Match, Health and Wellness Reimbursement, Free talkspace membership, Voluntary Long-term and Short-term Disability, Life Insurance and FSA/HSA.

Career Development – We believe in upskilling our teams, providing each employee a $1,000 annual training allowance.

Friendly office environments – Two modern offices; one in Dumbo, Brooklyn and the other in Durham, NC, offering a variety of working spaces for individual or team collaboration with free meals and snacks.

Social events – Monthly culture events, celebrations, team outings and social hours.

Similar Jobs

10 Days Ago
Remote or Hybrid
Expert/Leader
Expert/Leader
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Leads Security and Risk Services delivery across the Americas, managing senior consultants and business process consultants. Drives customer implementations, services revenue, strategic transformation, AI-powered automation adoption, delivery quality, executive relationships, partner collaboration, and practice growth. Develops business plans, expands the ServiceNow Security and Risk footprint, mentors consulting teams, and represents the company with industry and regulatory communities. Travel up to 40% annually.
Top Skills: Ai-Powered AutomationCloud ComputingSaaSServicenow Platform
14 Days Ago
Remote
United States
250K-300K Annually
Expert/Leader
250K-300K Annually
Expert/Leader
Artificial Intelligence • Blockchain • Professional Services • Security • Consulting • Cybersecurity • Defense
Leads a 12-person application security practice conducting code audits, vulnerability research, and secure design reviews. Oversees technical delivery, client relationships, project staffing, utilization, profitability, recruiting, and team development. Provides hands-on technical direction across source-code security work, determines investments in tooling and methodologies, and integrates AI-assisted auditing and research into team workflows. The role also owns practice P&L and supports engineers’ conference, publication, and open-source contributions.
Top Skills: Ai Analysis ToolsAi Coding ToolsC/C++FuzzingGoJavascript/TypescriptPythonRustSolidityStatic Analysis
14 Days Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
275K-315K Annually
Expert/Leader
275K-315K Annually
Expert/Leader
AdTech • Artificial Intelligence • Marketing Tech • Software • Analytics
Lead Zeta’s AI-native Application Security function by defining strategy, building the team, embedding security agents and policy-as-code into IDEs, pull requests, CI/CD, and AI/ML pipelines, and overseeing continuous threat modeling and validation. Own security for AI systems, models, prompts, and agents, including adversarial testing for prompt injection, model abuse, and data leakage. Mentor engineers and promote automated, secure software development practices.
Top Skills: AIAi/MlApi SecurityCi/CdCloud-Native SystemsDevsecopsIdesOwaspPolicy-As-CodeThreat Modeling

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account