Director of Security
Our Company
At Wysh, we’re not your average insurance company—we’re redefining financial protection for the modern world. Our purpose is to empower every person to live life to the fullest, with the confidence of financial protection. As an entrepreneurial team, we thrive on thinking outside the box, experimenting fearlessly, and delivering innovative solutions that challenge industry norms.
What sets us apart is our people: a dynamic mix of math nerd strategists, user-flow-obsessed designers, results-driven developers, and epic storytelling marketers. We love what we do and take work-life balance and professional development as seriously as our products.
At Wysh, we dream big, safeguard futures, and inspire everyone—our customers and team alike—to aim high. Ready to join a company that’s redefining financial protection and making dreams a reality? Join us on this exciting journey, and let’s make an impact, one Wysh at a time.
The Role
The Director of Security is the operational leader of our information security program, reporting to the CISO. This role will translate our security strategy into day-to-day programs, controls, and incident response capability — owning vulnerability management, security operations, compliance certification programs (SOC 2, NIST), third-party risk, and our security awareness program. As a licensed insurance carrier operating in 49 states, regulatory security compliance is mission-critical, and this leader ensures our program is robust, documented, and audit-ready at all times.
This is a full-time, remote position based in the U.S. (EST or CST time zones preferred). The base salary range for this role is $190K – $220K, with final compensation determined by experience, skill set, and region.
What You’ll Do:
- Lead the information security operations function: SIEM management, threat detection, vulnerability scanning, penetration testing program, and security incident response.
- Own and maintain the company's SOC 2 Type II compliance program — coordinating with auditors, managing evidence collection, and remediating findings.
- Participate in design and own operational management of the third-party/vendor risk management program — assessing security posture of technology vendors, reinsurers, and distribution partners.
- Continue to refine existing security awareness and training programs for all employees, with specialized modules for operations, engineering, and leadership teams.
- Manage the security configuration of cloud environments, identity systems (SSO, PAM), and endpoint security tools in partnership with the IT and Infrastructure teams.
- Assist with maintenance of the company's information security policies, standards, and procedures.
- Coordinate with the CISO, Chief Compliance Officer, and state insurance regulators on cybersecurity-related market conduct matters, including compliance with the NAIC Cybersecurity Model Law.
- Lead the security incident response plan — including tabletop exercises, breach notification readiness, and cyber insurance coordination.
- Track and report security KPIs to the CTO/CISO and executive team.
- Research and evaluate emerging security technologies — recommending investments that improve the company's security posture.
What You’ll Bring:
- 8+ years of information security experience, with at least 3 years in a security leadership or program management role.
- CISSP, CISM, or equivalent security certification required; additional certifications (CEH, CCSP, CRISC) preferred.
- Experience managing SOC 2 Type II programs and security compliance audits.
- Hands-on expertise with SIEM platforms (Elastic or equivalent), vulnerability scanners, and EDR/XDR tools.
- Strong knowledge of NIST Cybersecurity Framework, ISO 27001, and cloud security best practices.
- Experience with insurance industry cybersecurity requirements — NAIC Model #668, state-specific regulations preferred.
- Proven experience leading security incident response.
Diversity and Inclusion
Wysh is a proud equal opportunity employer that is committed to diversity and inclusion in and outside of the workplace. We strongly believe that everyone deserves a seat at the table and we support a culture where our people are empowered to be their authentic selves each and everyday.
We’re building a team that represents a variety of backgrounds, perspectives, and skills to reflect the world that we live in and the customers we serve. You are welcomed to apply for this role free of biases or discrimination regardless of your race, religion, color, sex, gender identity, sexual orientation, age, physical or mental disability, national origin, veteran status or any other basis covered by law.
Benefits
A Great Team – We focus on hiring people from diverse backgrounds who are easy to get along with and fantastic teammates.
Flexible Work Schedule – Remote work schedule. We’re interested in what you contribute more so than when you do it.
Work Life Balance – Unlimited PTO, Paid Holidays, along with Paid Summer Fridays and Paid parental leave.
Competitive Compensation – The base salary for this role is $190,000 to $220,000 annually. Exact compensation range is determined based on your region, years of experience, and specific skill set using aggregate market data from PayScale.
Health & Wellness – We offer 100% Medical Care Coverage for you and generous contributions for family, Dental and Vision Coverage, Commuter and Parking Reimbursement, 401k with a 4% Match, Health and Wellness Reimbursement, Free talkspace membership, Voluntary Long-term and Short-term Disability, Life Insurance and FSA/HSA.
Career Development – We believe in upskilling our teams, providing each employee a $1,000 annual training allowance.
Friendly office environments – Two modern offices; one in Dumbo, Brooklyn and the other in Durham, NC, offering a variety of working spaces for individual or team collaboration with free meals and snacks.
Social events – Monthly culture events, celebrations, team outings and social hours.
Apply for this job
*
indicates a required field