Logo for Wysh

Director of Security

Role overview

Qualifications

  • 8+ years of information security experience
  • At least 3 years in a security leadership or program management role
  • CISSP, CISM, or equivalent security certification required
  • Experience managing SOC 2 Type II programs and security compliance audits

Responsibilities

  • Lead the information security operations function
  • Own and maintain the company's SOC 2 Type II compliance program
  • Participate in design and operational management of the third-party/vendor risk management program
  • Continue to refine existing security awareness and training programs for all employees

About the company

Wysh logo

Wysh

At Wysh, we're all about fostering dreams, safeguarding futures, and cementing lasting legacies. We support and encourage our customers and employees to dream big and aim high. We believe that every dream deserves a partner, and we're here to be just that. So, whether you're looking to protect your family's future or you’re a creative mind with dreams of working somewhere special, Wysh is here. So come join us on this exciting journey, and let's make dreams come true, one Wysh at a time. Our Mission: We believe that everyone should feel the confidence and peace of mind that comes from obtaining the financial protection they need in their lives.

Company details

Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Our Company

At Wysh, we’re not your average insurance company—we’re redefining financial protection for the modern world. Our purpose is to empower every person to live life to the fullest, with the confidence of financial protection. As an entrepreneurial team, we thrive on thinking outside the box, experimenting fearlessly, and delivering innovative solutions that challenge industry norms.

What sets us apart is our people: a dynamic mix of math nerd strategists, user-flow-obsessed designers, results-driven developers, and epic storytelling marketers. We love what we do and take work-life balance and professional development as seriously as our products.

At Wysh, we dream big, safeguard futures, and inspire everyone—our customers and team alike—to aim high. Ready to join a company that’s redefining financial protection and making dreams a reality? Join us on this exciting journey, and let’s make an impact, one Wysh at a time.

The Role

The Director of Security is the operational leader of our information security program, reporting to the CISO. This role will translate our security strategy into day-to-day programs, controls, and incident response capability — owning vulnerability management, security operations, compliance certification programs (SOC 2, NIST), third-party risk, and our security awareness program. As a licensed insurance carrier operating in 49 states, regulatory security compliance is mission-critical, and this leader ensures our program is robust, documented, and audit-ready at all times.

This is a full-time, remote position based in the U.S. (EST or CST time zones preferred). The base salary range for this role is $190K – $220K, with final compensation determined by experience, skill set, and region.

What You’ll Do:

  • Lead the information security operations function: SIEM management, threat detection, vulnerability scanning, penetration testing program, and security incident response.
  • Own and maintain the company's SOC 2 Type II compliance program — coordinating with auditors, managing evidence collection, and remediating findings.
  • Participate in design and own operational management of the third-party/vendor risk management program — assessing security posture of technology vendors, reinsurers, and distribution partners.
  • Continue to refine existing security awareness and training programs for all employees, with specialized modules for operations, engineering, and leadership teams.
  • Manage the security configuration of cloud environments, identity systems (SSO, PAM), and endpoint security tools in partnership with the IT and Infrastructure teams.
  • Assist with maintenance of the company's information security policies, standards, and procedures.
  • Coordinate with the CISO, Chief Compliance Officer, and state insurance regulators on cybersecurity-related market conduct matters, including compliance with the NAIC Cybersecurity Model Law.
  • Lead the security incident response plan — including tabletop exercises, breach notification readiness, and cyber insurance coordination.
  • Track and report security KPIs to the CTO/CISO and executive team.
  • Research and evaluate emerging security technologies — recommending investments that improve the company's security posture.

What You’ll Bring:

  • 8+ years of information security experience, with at least 3 years in a security leadership or program management role.
  • CISSP, CISM, or equivalent security certification required; additional certifications (CEH, CCSP, CRISC) preferred.
  • Experience managing SOC 2 Type II programs and security compliance audits.
  • Hands-on expertise with SIEM platforms (Elastic or equivalent), vulnerability scanners, and EDR/XDR tools.
  • Strong knowledge of NIST Cybersecurity Framework, ISO 27001, and cloud security best practices.
  • Experience with insurance industry cybersecurity requirements — NAIC Model #668, state-specific regulations preferred.
  • Proven experience leading security incident response.

Diversity and Inclusion

Wysh is a proud equal opportunity employer that is committed to diversity and inclusion in and outside of the workplace. We strongly believe that everyone deserves a seat at the table and we support a culture where our people are empowered to be their authentic selves each and everyday.

We’re building a team that represents a variety of backgrounds, perspectives, and skills to reflect the world that we live in and the customers we serve. You are welcomed to apply for this role free of biases or discrimination regardless of your race, religion, color, sex, gender identity, sexual orientation, age, physical or mental disability, national origin, veteran status or any other basis covered by law.

Benefits

A Great Team – We focus on hiring people from diverse backgrounds who are easy to get along with and fantastic teammates.

Flexible Work Schedule – Remote work schedule. We’re interested in what you contribute more so than when you do it.

Work Life Balance – Unlimited PTO, Paid Holidays, along with Paid Summer Fridays and Paid parental leave.

Competitive Compensation – The base salary for this role is $190,000 to $220,000 annually.  Exact compensation range is determined based on your region, years of experience, and specific skill set using aggregate market data from PayScale.

Health & Wellness – We offer 100% Medical Care Coverage for you and generous contributions for family, Dental and Visio​​n Coverage, Commuter and Parking Reimbursement, 401k with a 4% Match, Health and Wellness Reimbursement, Free talkspace membership, Voluntary Long-term and Short-term Disability, Life Insurance and FSA/HSA.

Career Development – We believe in upskilling our teams, providing each employee a $1,000 annual training allowance.

Friendly office environments – Two modern offices; one in Dumbo, Brooklyn and the other in Durham, NC, offering a variety of working spaces for individual or team collaboration with free meals and snacks.

Social events – Monthly culture events, celebrations, team outings and social hours.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Wysh

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.