Skip to main content

Director of Information Security

Job DescriptionJob Description

This is an in office position at our UT HQ

We are seeking an experienced Director of Information Security to lead our comprehensive security program across our diverse technology portfolio. This role requires a strategic leader capable of managing security and compliance initiatives across cloud environments, on-premises data centers, unified communications platforms, and customer-deployed solutions. The ideal candidate will bring deep expertise in regulatory compliance frameworks and emerging AI governance while building and maintaining a security culture that enables business growth. This position will report to the Vice President of Operations & Security.

Key Responsibilities

Strategic Security Leadership

  • Develop and execute a comprehensive information security strategy that addresses the unique requirements of cloud-based services, on-premises infrastructure, and customer-deployed solutions
  • Establish security governance frameworks that scale across multiple deployment models while maintaining consistent security posture
  • Partner with executive leadership to align security initiatives with business objectives and risk tolerance
  • Lead security architecture reviews for new products and features across all platforms

Multi-Environment Security Management

  • Oversee security operations across hybrid cloud environments and proprietary data centers
  • Implement and maintain security controls for unified communications platforms, including softphone applications and mobile/desktop clients
  • Design security frameworks for products deployed within customer premises that balance security requirements with customer autonomy
  • Manage vulnerability assessment and remediation programs across all infrastructure types

Compliance and Risk Management

  • Maintain and expand compliance certifications including SOC 2 Type 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, and so on
  • Lead annual audits and assessments, coordinating with internal teams and external auditors
  • Develop and maintain comprehensive risk registers and treatment plans
  • Ensure compliance with industry-specific regulations relevant to our diverse customer base
  • Establish and maintain AI governance policies and ethical use frameworks for AI-enabled features

Security Operations and Incident Response

  • Develop incident response plans that address the unique challenges of distributed architectures
  • Coordinate security incident response across cloud, on-premises, and customer-deployed environments
  • Establish threat intelligence programs to proactively identify and mitigate emerging risks

Team Development and Collaboration

  • Guide, mentor, and retain a high-performing security team
  • Foster security awareness and best practices across the organization through training and communication programs
  • Collaborate with engineering, product, and operations teams to embed security into development lifecycles
  • Serve as the primary security liaison with customers, partners, and regulatory bodies

Required Qualifications

Experience

  • 5+ years of progressive experience in information security, with at least 2 years in a senior leadership role
  • Proven track record managing security for organizations with hybrid cloud/on-premises architectures
  • Direct experience securing unified communications platforms, VoIP systems, or similar real-time communication technologies
  • Demonstrated success achieving and maintaining SOC 2 Type 2 and ISO 27001 certifications
  • Experience developing and implementing AI governance policies and responsible AI frameworks
  • Background in securing multi-tenant SaaS platforms and customer-deployed enterprise software

Technical Expertise

  • Deep understanding of cloud security architectures (AWS, Azure, GCP)
  • Expertise in network security, and access management, and data protection
  • Knowledge of secure software development practices and DevSecOps methodologies
  • Familiarity with telecommunications security standards and unified communications protocols
  • Understanding of zero-trust architectures and modern security frameworks

Leadership and Communication

  • Exceptional ability to communicate complex security concepts to technical and non-technical stakeholders
  • Experience presenting to boards, executive committees, and external auditors
  • Proven ability to influence and drive security initiatives across diverse teams
  • Track record of building collaborative relationships with engineering and product organizations

Qualifications

  • Advanced degree in Computer Science, Information Security, or related field
  • Professional certifications such as CISSP, CISM, or CRISC
  • Experience with privacy regulations including GDPR, CCPA, and HIPAA
  • Background in telecommunications or unified communications industry
  • Experience with FedRAMP or other government compliance frameworks
  • Knowledge of container security and microservices architectures

Director of Information Security

Pleasant Grove, UT
Full time

Published on 09/30/2025

Share this job now