Omnissa
Director, Security Architecture, Vulnerability Management and Response
Remote - USA · Director
Sponsorship not specified$178k-$297kDetected 9 days ago
Cloud PlatformsCI/CDMachine LearningLLMsAgentic AICybersecurityNetwork SecurityComplianceNegotiationVendor ManagementCustomer SuccessZero TrustHIPAALeadershipCommunicationCollaborationCISSP
About the role
- If you're passionate about shaping the future of work, we'd love to hear from you.
- This role works in close partnership with Product Security and engineering leadership to align shared standards for secure development and vulnerability response, rather than operating as a separate or overlapping function.
- As Omnissa expands its use of AI across the enterprise, this role also carries responsibility for shaping the security and governance posture around emerging AI/GenAI technologies.
Responsibilities
- Lead, mentor, and grow a globally distributed team of senior security engineers and architects across AMER and APAC.
- Serve as the senior escalation point for design conflicts and remediation prioritization decisions, and for security incidents surfaced through the vulnerability response (PSIRT) process.
- Partner with all lines of business to establish security standards, perform architecture and design reviews, and embed security into every stage of design and implementation.
- Drive security framework development, hardening standards, and policy adherence across the enterprise.
- Partner closely with Product Security and engineering to define security architecture requirements across the SDLC and CI/CD ecosystem, including threat modeling, architecture standards, SAST, DAST, software composition analysis, secrets detection, and artifact/image signing, ensuring security controls are built into development and deployment workflows from design through release.
- Drive secure-by-design practices across the enterprise, reference architectures, secure design patterns, and paved-road templates that make the secure path the default path for engineering teams, reducing reliance on after-the-fact review.
- Oversee threat modeling for new architectures, major features, and significant changes, partnering with IT, Product Security, and Engineering, to identify design-stage risk before implementation begins.
- Define and maintain Omnissa's enterprise identity security strategy and standards, spanning workforce and non-human identities, including AI agents, and API-level access, authentication (SSO, MFA, phishing-resistant methods), authorization, privileged access, and identity governance, across on-premises and cloud environments, partnering with IT, who own and operate the underlying IAM tooling.
- Partner with IT and engineering to drive adoption of modern identity architecture (e.g., Zero Trust access principles, just-in-time/just-enough access, federation standards) that scales to AI-driven and non-human identity growth across enterprise and product-facing systems.
- Align security architecture, hardening standards, and control design with applicable frameworks: SOC 2, ISO 27001, NIST CSF/800-53, PCI, HIPAA, and FedRAMP; supporting control evidence and audit readiness in partnership with Compliance/GRC.
Requirements
- 10+ years in information security, including 5+ years leading technical security teams (engineering, architecture, and/or Exposure/Vulnerability Management), preferably at global SaaS companies.
- Working knowledge of data governance principles (classification, residency, retention) and major compliance/regulatory frameworks - including GDPR, CCPA, and CMMC alongside those listed above
- Experience with the full risk lifecycle: risk assessment, requirements gathering, control design, tool selection, vendor negotiation, and remediation oversight.
- Strong communication skills with the ability to influence executives and engineers alike.
- Practical experience with threat modeling methodologies and driving secure-by-design outcomes at the architecture stage, before code is written.
- Experience operating across a globally distributed team and supporting 24x7 service models.
Nice to have
- Background at a B2B SaaS/cloud company preferred, given the enterprise customer, contractual, and regulatory context this role operates in.
- Experience securing AI/GenAI technologies and establishing governance for their enterprise use.
- Familiarity with modern security tooling such as CrowdStrike, Wiz, Tenable, Seemplicity, Recorded Future, Cribl, and Palo Alto / Panorama.
- Relevant certifications (e.g., CISSP, CCSP, or equivalent).
- What Success Looks Like
- A clear, funded, multi-year strategy across all three pillars with measurable risk-reduction outcomes.
- A mature, metrics-driven Exposure Management program with SLAs consistently met.
- A defined and enforced AI governance posture that enables safe adoption at the pace the business needs.
Compensation
- The typical base salary for this role is between USD $178,000 – $296,700 per year and it may be eligible for participation in a corporate bonus program.
Company info
- The typical base salary for this role is between USD $178,000 - $296,700 per year and it may be eligible for participation in a corporate bonus program.
- Actual compensation offer may vary from posted hiring range based upon geographic location, work experience, education, skill level, or other relevant factors.
- In addition to competitive compensation, Omnissa offers a variety of benefits such as employee ownership, health insurance, 401k with matching contributions, disability insurance, paid-time off, growth opportunities, and more.
- All employment decisions at Omnissa are based on business needs, job requirements and individual qualifications, without regard to race, color, religion, ancestry, ethnicity, national, social or ethnic origin, sex (including pregnancy), age, physical, mental or sensory disability, HIV status, sexual orientation, gender identity and/or expression, marital, civil union or domestic partnership status, past, present, or prospective service in the uniformed services, family medical history or genetic information, family or parental status, veteran status, or any other status protected by applicable laws or reg
- Own the enterprise PSIRT strategy, partnering with the team on intake, triage, and coordinated response for vulnerabilities in Omnissa products and services, whether reported externally (researchers, customers, bug bounty) or discovered internally.
Apply directly at Omnissa →Create a free account for alerts like thisView Omnissa immigration profile
This listing is sourced directly from Omnissa's careers page and normalized into a canonical job model.