TripleLift

TripleLift

Senior Director, Security

New York, New York, United States · Director · Full-time

Sponsorship not specified$165k-$220kDetected 21 days ago
AWSCloud PlatformsTerraformCI/CDDevOpsCybersecurityPenetration TestingSIEMSOC OperationsDetection EngineeringIncident ResponseComplianceLeadershipCommunication

About the role

  • The Director / Senior Director of Security plays a critical role in shaping and executing TripleLift's security strategy across our programmatic advertising platform, cloud infrastructure, and enterprise environment.

Responsibilities

  • Lead, grow, and mentor a team of security engineers spanning cloud/infrastructure security, GRC, and security operations, fostering a collaborative and high-accountability culture.
  • Own the enterprise security architecture across AWS cloud environments, CI/CD pipelines, and corporate infrastructure-ensuring systems are designed, deployed, and maintained according to security best practices.
  • Drive the maturity of TripleLift's compliance and governance program, maintaining and expanding certifications and frameworks including SOC 2, PCI, NIST CSF, ISO 27001, and HITRUST.
  • Partner with Engineering and DevOps to embed security into the SDLC-integrating automated security controls into CI/CD pipelines and promoting secure-coding standards across development teams.
  • Lead vulnerability management and risk assessment programs, including regular audits, penetration testing, and remediation tracking across cloud and application environments.
  • At TripleLift, we are committed to building a culture where people feel connected, supported, and empowered to do their best work.
  • We want to ensure the best talent of every background, viewpoint, and experience has an opportunity to be hired, belong, and develop at TripleLift.
  • Through our People, Culture, and Community initiatives, we aim to create an environment where everyone can thrive and feel a true sense of belonging.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related technical field, or equivalent professional experience.

Nice to have

  • 8+ years of progressive experience in information security, with at least 3 years in a leadership or management role overseeing security engineers or analysts.
  • Deep expertise in AWS cloud security-including IAM, VPC architecture, logging/monitoring, and cloud-native security tooling-with hands-on implementation experience.
  • Experience embedding security into DevSecOps workflows, including IaC (Terraform, CloudFormation), CI/CD pipeline security controls, and secure-coding remediation programs.
  • Proven ability to influence cross-functional stakeholders and communicate security risk in business terms to non-technical audiences including executive leadership.
  • Experience in a fast-paced, cloud-native environment
  • adtech, martech, or SaaS industry background a plus.
  • Relevant security certifications strongly preferred: CISSP, CISM, CISA, or equivalent.

Compensation

  • US Jobs: The base salary range represents the low and high end of the TripleLift US salary range for this position.

Benefits

  • Medical, Dental & Vision Plans

Company info

  • At TripleLift, we're a team of great people who like who they work with and want to make everyone around them better.
  • Learn more about TripleLift and our culture by visiting our LinkedIn Life page.
  • Brand and enterprise customers choose us because of our innovative solutions, premium formats, and supportive experts dedicated to maximizing their performance.

This listing is sourced directly from TripleLift's careers page and normalized into a canonical job model.