Director of IT & Information Security

location_onRamat Gan, Tel Aviv Districtscheduleלפני 7 שעות
sync_altסגנון עבודה:היברידי
trending_upרמת ניסיון:מנהלים
historyמינימום ניסיון:10+ שנים

תיאור התפקיד

Who are we?

Checkmarx is the AI-powered application security leader helping the world’s most security-conscious enterprises secure the software that powers modern life. For more than two decades, our unified platform and services have helped organizations protect human- and AI-generated code from the first line through runtime, reducing risk across applications, cloud, and the software supply chain without slowing innovation.

We’re trusted by 1,600+ customers in 70+ countries, including some of the largest enterprises and governments in the world. Guided by research-led innovation and a developer-first mindset, we help every developer, security team, and enterprise build software that is risk-free by design.

What are we looking for?

Checkmarx is seeking a Strategic Director, IT & Information Security to own and scale our global corporate IT function and enterprise security program. This is a Director level leadership role, carrying full accountability for a significant IT and security budget, a global team, and the systems, projects, and controls that keep the company running securely at scale. You will own the delivery of IT services and infrastructure projects company-wide, while directing the design, implementation, and continuous improvement of our corporate security program — including security systems, threat modeling, and offensive security testing. You will partner closely with the Directors of GRC and DevSecOps, and report directly into the CIO/CISO, to ensure IT, security, compliance, and product security efforts are aligned, resourced, and mutually reinforcing. Given the scope and budget accountability of this role, it is positioned and compensated at the upper end of our Director/senior-leadership band

How will you make an impact?

·Own the global IT & Security strategy, P&L, budgets, roadmap, and operating model, balancing reliable day-to-day operations with modernization, automation, and digital transformation.

·Lead the global IT organization and core technology services, including infrastructure, networks, systems, service desk, end-user computing, IAM, and collaboration platforms; establish SLAs/KPIs and drive service quality, efficiency, and employee experience.

·Lead major technology programs and transformations, including infrastructure modernization, migrations, workplace technology, M&A integrations, and other cross-functional initiatives, ensuring delivery on scope, time, and budget.

·Build and scale a high-performing global IT organization while managing strategic vendors, contracts, commercial negotiations, and technology costs.

·Lead corporate security operations and strategy across endpoint, network, email, identity, SIEM/SOC, vulnerability management, cloud environments, security architecture, and security awareness.

· Own security risk and testing programs, including threat modeling, penetration testing, red-team engagements, vulnerability remediation, and security monitoring.

·Lead security incident response and crisis management, including detection, containment, root-cause analysis, post-incident reviews, business continuity, and disaster recovery.

·Partner with GRC and DevSecOps leadership to align IT and security operations with enterprise risk, compliance, and application security requirements, including SOC 2, ISO 27001, and GDPR.

·Provide executive and Board/Audit Committee visibility into IT and security posture, risks, budgets, and strategic priorities, and lead IT & Security due diligence for M&A, partnerships, and major vendors.

Requirements

What is needed to succeed?

• 10+ years of progressive experience across IT operations/infrastructure and information security, including 4+ years leading teams at a Director level or above, ideally with ownership of budgets in the multiple millions of dollars.

• Demonstrated experience owning and managing a significant IT/security budget end-to-end — planning, forecasting, vendor negotiation, and board/executive-level reporting on spend and ROI.

• Proven track record leading large-scale, global enterprise IT programs end-to-end, from scoping through delivery and adoption, including programs with multi-million-dollar budgets.

• Deep, hands-on knowledge of corporate security systems (EDR/XDR, SIEM, IAM/SSO, network security, DLP, email security) and modern security operations practices.

• Demonstrated experience running or directing threat modeling programs (e.g., STRIDE, PASTA, or equivalent frameworks) and penetration testing / red-team engagements at enterprise scale.

• Strong understanding of security frameworks and regulatory requirements relevant to a global SaaS/software company (SOC 2, ISO 27001, NIST, GDPR, or similar), and the ability to translate them into operational practice alongside a GRC function.

• Executive-level communication and stakeholder management skills

• Relevant certifications are a plus: CISSP, CISM, OSCP, GPEN, or equivalent.

What we have to offer

Checkmarx offers a great work environment, professional development, challenging careers, competitive compensation, great work-life balance, as well as great benefits and perks throughout the year.

Checkmarx is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, or other characteristics protected by law.

מיומנויות שהוזכרו


Cybersecurity, Enterprise Software, Financial Services, Software Development, Technology Consulting
Ramat Gan, Tel Aviv District

Securing the Applications Driving Our World - Checkmarx is the leader in application security, ensuring that enterprises worldwide can secure their application development from code to cloud. Our consolidated platform and services address the needs of enterprises by improving security and reducing TCO, while simultaneously building trust between AppSec, developers, and CISOs. We help you see and manage application risk across your entire application footprint, supporting your digital transformation and business growth. We are honored to serve more than 1,800 customers, including 40 percent of all Fortune 100 companies, such as Siemens, Airbus, Salesforce, Stellantis, Adidas, Walmart, and Sanofi. Our unified platform integrates and automates multiple AppSec capabilities within your software development lifecycle (SDLC) and simplifies management processes. Through our innovations, like Checkmarx One, we provide every capability necessary to secure application development, employing advanced techniques in vulnerability detection, prioritization, and remediation that enhance developer productivity. By consolidating application security on a single platform and seamlessly integrating into existing workflows, we empower teams to effectively collaborate and deliver secure software products without sacrificing speed or effectiveness.

הגש מועמדות למשרה זו

Use the application link supplied with this listing to apply to Checkmarx. Check the destination before entering personal information.