Director, Security

  • Pune
  • Avalara
What You'll Do Join us in building a secure platform supporting Avalara’s expanding business. In this leadership role you will have the opportunity to oversee Avalara’s regional security function in all capacities including but not limited to Security Operations, Security Engineering, Enterprise Risk, Resilience, Compliance, and Audit. You will be responsible for providing guidance and real-world mitigation steps to identified security risks. The successful candidate will be required to develop teams while determining mitigation strategies and drive fixes to resolution. A thorough understanding of corporate and product security, plus enterprise risk and audit will be valuable experience for the right candidate. Job Duties Manage, coach, develop a wide range of security teams and professionals. Partner with additional information security teams to improve operational capabilities and assurance; provide feedback to relevant stakeholders. Conduct regular assessments to improve the security posture and prevent regression. Design, collect, maintain, and report on metrics/telemetry across various security disciplines. Establish and maintain governance for security standards across the various the business. Help set a broad direction, put together a strategy, and implement tactical approaches to address business needs efficiently and effectively. What You'll Need to be Successful Qualifications 10+ years of experience as a security practitioner 8+ years of experience leading, managing & developing high performance teams. 3+ years of work experience securing public cloud environments. Proven expertise in developing and implementing processes, process integration and process changes. Excellent security engineering aptitude and the ability to provide technical mentorship and guidance. Expertise with one or more security concepts such as DFIR, Endpoint/Network Security, Cloud Security, Enterprise Risk, Audit, Application Security, penetration testing, etc. Ability to demonstrate strong written, verbal communication and presentation skills to all levels of seniority and disciplines within the organization. BA/BS in computer science, information security, related discipline, or equivalent work experience Preferred Qualifications Experience deploying a wide variety of security technologies in complex enterprise environments, particularly in a SaaS business. Familiarity with the security incident response lifecycle and handling of investigations Firsthand experience with the regulations or frameworks: SOC 1, SOC 2, ISO 27000 series, GDPR and relevant data privacy regulations, NIST, COBIT, PCI, Sarbanes-Oxley, HIPAA CISSP, SANS certifications, technology certifications and other security certifications is a plus. About Avalara We’re Avalara. We’re defining the relationship between tax and tech. We’ve already built an industry-leading cloud compliance platform, processing nearly 40 billion customer API calls and over 5 million tax returns a year. Last year, we became a billion-dollar business, and our tribe expanded by a cool thousand people - there’s nearly 5,000 of us now. Our growth is real, and we’re not slowing down - not until we’ve achieved our mission - to be part of every transaction in the world. We’re bright, innovative and disruptive, like the orange we love to wear. It captures our quirky spirit and optimistic mindset. It shows off the culture we’ve designed, that empowers our people to win. Ownership and achievement go hand in hand here. We instill passion in our people through the trust we place in them. We’ve been different from day one. Join us, and your career will be too. EEO Statement We’re an Equal Opportunity Employer. Supporting diversity and inclusion is a cornerstone of our company — we don’t want people to fit into our culture, but to enrich it. All qualified candidates will receive consideration for employment without regard to race, color, creed, religion, age, gender, national orientation, disability, sexual orientation, US Veteran status, or any other factor protected by law. If you require any reasonable adjustments during the recruitment process, please let us , coach, develop a wide range of security teams and professionals. Partner with additional information security teams to improve operational capabilities and assurance; provide feedback to relevant stakeholders. Conduct regular assessments to improve the security posture and prevent regression. Design, collect, maintain, and report on metrics/telemetry across various security disciplines. Establish and maintain governance for security standards across the various the business. Help set a broad direction, put together a strategy, and implement tactical approaches to address business needs efficiently and effectively.