Sr. Director, Cybersecurity
Sr. Director, Cybersecurity

Sr. Director, Cybersecurity

Full-Time 72000 - 108000 £ / year (est.) No home office possible
Go Premium
Bugcrowd

At a Glance

  • Tasks: Lead and innovate in cybersecurity strategy, managing teams and enhancing security measures.
  • Company: Join Bugcrowd, a leader in cybersecurity with a dynamic and inclusive culture.
  • Benefits: Enjoy remote work, competitive salary, and opportunities for professional growth.
  • Other info: Flexible work environment with a focus on diversity and inclusion.
  • Why this job: Make a real impact in cybersecurity while working with elite professionals.
  • Qualifications: Proven experience in cybersecurity leadership and technical expertise required.

The predicted salary is between 72000 - 108000 £ per year.

We are Bugcrowd. Since 2012, we’ve been empowering organizations to take back control and stay ahead of threat actors by uniting the collective ingenuity and expertise of our customers and trusted alliance of elite hackers, with our patented data and AI-powered Security Knowledge Platform. We specifically seek a hands-on, technical security leader. You bring experience building security monitoring, reference architectures, deploying tools, integrating platforms, assessing modern cloud-native applications and infrastructure - and leading teams executing that mission successfully.

Program Leadership

  • Define the Cyber Security Strategy for Bugcrowd and identify areas of improvements to the threat landscape, internal risk tolerance objectives, and/or compliance objectives.
  • Ensure the technical aspects of vendor acquisitions and tools are safe for Bugcrowd’s use, in unison with the IT and compliance teams.
  • Assess corporate technology systems, determine strategy for changes, enhancement and improvements; recommend and implement the same, from the perspective of cyber security.
  • Carry out and fulfill the cyber security strategy of Bugcrowd, proactively improving the security posture with time.
  • Work with GRC to assist in designing, developing, implementing and coordinating areas of policies and procedures for compliance with SOC-2, NIST 800-53v4, ISO27001, ISO27018, and FedRAMP.
  • Represent Bugcrowd in the internal and external audits for SOC-2, ISO27001, and ISO27018.

AppSec and Product Security Leadership

  • Manage Bugcrowd’s bug bounty program, ensuring that clients have a standard to aspire to, when running their own bounty programs.
  • Analyze new features prior to development or launch, to ensure the security measures in place are sufficient for the project.
  • Manage the access controls for Bugcrowd’s production codebase (GitHub).
  • Approve and analyze authorisation requests to production data (AWS, GitHub, Tableau, etc.).
  • Perform regular audits of Bugcrowd’s cloud infrastructure, alongside helping with architecture of any cloud solutions from the security perspective.
  • Manage and audit all vulnerability scans (internal and external) for all of Bugcrowd’s systems (Qualys and Nessus).
  • Proactively test and identify issues within Pull Requests and production to find issues (code review & penetration testing).
  • Automate security tasks to proactively identify and fix security issues within Bugcrowd.
  • Perform configuration management upon all Bugcrowd systems (IT and cloud).
  • Perform code audits on new features, patches, etc.

Security Operations, Detection and Incident Response

  • Perform IR for all parts of the business (on-call 24x7) and perform root cause analysis upon the incidents to properly mitigate them in the future.
  • Perform threat intelligence to proactively find issues relating to Bugcrowd’s security posture.
  • Plan implementation of security controls, in unison with the required teams (infra, eng, secops, IT, compliance, Researcher Success (RS), etc.).
  • Monitor the security controls for all of Bugcrowd’s systems and build a team to do the same.
  • Perform malware analysis on any potential malware, should the forensic requirements arise during IR.
  • Coordinating red team engagements against Bugcrowd and implementing security controls to mitigate any issues found.
  • Develop security awareness materials for all roles within the Bugcrowd organisation.
  • Aid the Legal team with GDPR related issues from researchers and programs.

Management and Team Leadership

  • Perform table top exercises within the Bugcrowd organization to ensure the organization is prepared for future threats.
  • Aid with business continuity testing, since the internal cybersecurity team plays a major role within the process.
  • Present findings and observations to the ISMS committee.
  • Portray and represent the technical controls and engineering areas within the ISMS committee (requirement of ISO27001).

Supervisory Responsibility

  • Lead and manage a team of internal cybersecurity professionals.
  • Train and grow the security team with objectives that are defined, measured and monitored.
  • Support Security Leadership with delegated responsibilities, as requested.
  • Take a proactive, collaborative and respected leadership role in the Company to galvanize support of a robust, efficient and secure technology organization.
  • Manage a team of hungry and fast growing security professionals with both strong attack and defense skills.

Knowledge, Skills, and Abilities

  • Proven work experience leading Cyber Security (penetration testing, red teaming, GRC, IR, secure development, and security architecture) in a startup and growing with the organization.
  • Excellent knowledge of technical security controls, including cloud, web application, infrastructure, IT, and compliance.
  • Experience in data governance, data architecture, data flow and system architecture to optimize the same.
  • Hands-on experience with penetration testing, red teaming, and security patch bypass testing.
  • Ability to work independently and must have strong organizational and communication skills.
  • Systems / Software (detailed knowledge of the following stack): Mac OS, Python, JavaScript, Ruby, Golang, Java, Kotlin, Postgres, GSuite, Cisco Umbrella, Netskope, Crowdstrike, GitHub, AWS, Heroku, Cloudflare, DataDog, JAMF, etc.
  • Familiarity with Jira is a plus.
  • Experience related to and assistance with ISO27001, ISO27018, NIST 800-53v4, and SOC2 audits is compulsory.
  • Degree in Computer Science, cyber security, MIS or equivalent experience desirable but not required.
  • Experience in cyber security with demonstrations of responsibility and technical excellence.
  • Must be eager to work hard, to learn many new skills, solve problems, and integrate tightly with the rest of the team.
  • Willingness to support a global organization with limited staff via off hours activity while maintaining a healthy work-life balance.

Working Conditions and Physical Requirements

  • The ideal candidate must be able to complete all physical requirements of the job with or without reasonable accommodation.
  • Sitting and / or standing - Must be able to remain in a stationary position 50% of the time.
  • Carrying and / or lifting - Must be able to carry / move laptop as needed throughout the work day.
  • Environment - remote, work-from-home 100% of the time.

ADA Statement

Bugcrowd is committed to the full inclusion of all qualified individuals. In keeping with our commitment, Bugcrowd will take the steps to assure that people with disabilities are provided reasonable accommodations.

Culture

At Bugcrowd, we understand that diversity in the workplace is vital to a company’s success and growth. We strive to make sure that people are included and have a sense of being part of making Bugcrowd not only a great product but a great place to work.

Equal Employment Opportunity: Bugcrowd is EOE, Disability/Age Employer. Individuals seeking employment at Bugcrowd are considered without regards to race, color, religion, national origin, age, sex, marital status, ancestry, physical or mental disability, veteran status, gender identity, or sexual orientation.

Sr. Director, Cybersecurity employer: Bugcrowd

At Bugcrowd, we pride ourselves on fostering a dynamic and inclusive work culture that empowers our employees to thrive in the fast-paced world of cybersecurity. As a fully remote company, we offer unparalleled flexibility, competitive benefits, and opportunities for professional growth, ensuring that our team members can balance their personal and professional lives while contributing to meaningful projects that protect organisations from cyber threats.
Bugcrowd

Contact Detail:

Bugcrowd Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Sr. Director, Cybersecurity

✨Tip Number 1

Network like a pro! Reach out to folks in the cybersecurity field, especially those at Bugcrowd. Attend industry events or webinars, and don’t be shy about sliding into DMs on LinkedIn. You never know who might have the inside scoop on job openings!

✨Tip Number 2

Show off your skills! Create a portfolio that highlights your past projects, especially those related to security monitoring and incident response. This is your chance to demonstrate your hands-on experience and technical prowess, so make it shine!

✨Tip Number 3

Prepare for interviews by brushing up on common cybersecurity scenarios. Be ready to discuss how you’d handle specific incidents or improve security postures. Practising with a friend can help you articulate your thoughts clearly and confidently.

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in being part of the Bugcrowd team. Let’s get you that dream job!

We think you need these skills to ace Sr. Director, Cybersecurity

Cybersecurity Strategy Development
Security Monitoring
Cloud Security Assessment
Vendor Risk Management
Compliance with SOC-2, NIST 800-53v4, ISO27001, ISO27018, FedRAMP
Bug Bounty Program Management
Access Control Management
Vulnerability Scanning and Auditing
Incident Response and Root Cause Analysis
Threat Intelligence
Malware Analysis
Team Leadership and Management
Penetration Testing
Technical Security Controls Knowledge
Data Governance and Architecture

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the role of Sr. Director, Cybersecurity. Highlight your hands-on experience in building security monitoring and leading teams, as well as any relevant certifications or projects that align with Bugcrowd's mission.

Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your experience aligns with Bugcrowd's goals. Be sure to mention specific achievements that demonstrate your leadership and technical skills.

Showcase Your Technical Skills: In your application, don't shy away from showcasing your technical prowess. Mention your familiarity with tools like AWS, GitHub, and your experience with penetration testing and security audits. This will help us see how you can contribute to our team.

Apply Through Our Website: We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining the Bugcrowd family!

How to prepare for a job interview at Bugcrowd

✨Know Your Cybersecurity Stuff

Make sure you brush up on your technical knowledge, especially around cloud security, penetration testing, and compliance standards like ISO27001 and SOC-2. Be ready to discuss specific tools and frameworks you've used in the past, as this will show your hands-on experience.

✨Showcase Your Leadership Skills

As a Sr. Director, you'll need to lead a team effectively. Prepare examples of how you've successfully managed teams, driven cybersecurity strategies, and improved security postures in previous roles. Highlight your ability to train and grow talent within your team.

✨Understand Bugcrowd's Mission

Familiarise yourself with Bugcrowd’s approach to cybersecurity and their bug bounty program. Being able to articulate how your vision aligns with their mission will demonstrate your genuine interest in the role and the company.

✨Prepare for Scenario-Based Questions

Expect to face scenario-based questions that assess your problem-solving skills in real-world situations. Think about past incidents you've handled, how you approached them, and what the outcomes were. This will help you illustrate your critical thinking and incident response capabilities.

Sr. Director, Cybersecurity
Bugcrowd
Go Premium

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>