TripleLift
Senior Director, Security
New York, New York, United States · Director · Full-time
Sponsorship not specified$165k-$220kDetected 21 days ago
AWSCloud PlatformsTerraformCI/CDDevOpsCybersecurityPenetration TestingSIEMSOC OperationsDetection EngineeringIncident ResponseComplianceLeadershipCommunication
About the role
- The Director / Senior Director of Security plays a critical role in shaping and executing TripleLift's security strategy across our programmatic advertising platform, cloud infrastructure, and enterprise environment.
Responsibilities
- Lead, grow, and mentor a team of security engineers spanning cloud/infrastructure security, GRC, and security operations, fostering a collaborative and high-accountability culture.
- Own the enterprise security architecture across AWS cloud environments, CI/CD pipelines, and corporate infrastructure-ensuring systems are designed, deployed, and maintained according to security best practices.
- Drive the maturity of TripleLift's compliance and governance program, maintaining and expanding certifications and frameworks including SOC 2, PCI, NIST CSF, ISO 27001, and HITRUST.
- Partner with Engineering and DevOps to embed security into the SDLC-integrating automated security controls into CI/CD pipelines and promoting secure-coding standards across development teams.
- Lead vulnerability management and risk assessment programs, including regular audits, penetration testing, and remediation tracking across cloud and application environments.
- At TripleLift, we are committed to building a culture where people feel connected, supported, and empowered to do their best work.
- We want to ensure the best talent of every background, viewpoint, and experience has an opportunity to be hired, belong, and develop at TripleLift.
- Through our People, Culture, and Community initiatives, we aim to create an environment where everyone can thrive and feel a true sense of belonging.
Requirements
- Bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience.
Nice to have
- 8+ years of progressive experience in information security, with at least 3 years in a leadership or management role overseeing security engineers or analysts.
- Deep expertise in AWS cloud security-including IAM, VPC architecture, logging/monitoring, and cloud-native security tooling-with hands-on implementation experience.
- Experience embedding security into DevSecOps workflows, including IaC (Terraform, CloudFormation), CI/CD pipeline security controls, and secure-coding remediation programs.
- Proven ability to influence cross-functional stakeholders and communicate security risk in business terms to non-technical audiences including executive leadership.
- Experience in a fast-paced, cloud-native environment
- adtech, martech, or SaaS industry background a plus.
- Relevant security certifications strongly preferred: CISSP, CISM, CISA, or equivalent.
Compensation
- US Jobs: The base salary range represents the low and high end of the TripleLift US salary range for this position.
Benefits
- Medical, Dental & Vision Plans
Company info
- At TripleLift, we're a team of great people who like who they work with and want to make everyone around them better.
- Learn more about TripleLift and our culture by visiting our LinkedIn Life page.
- Brand and enterprise customers choose us because of our innovative solutions, premium formats, and supportive experts dedicated to maximizing their performance.
Apply directly at TripleLift →Create a free account for alerts like thisView TripleLift immigration profile
This listing is sourced directly from TripleLift's careers page and normalized into a canonical job model.