×
Register Here to Apply for Jobs or Post Jobs. X

Director, Information Security

Job in Indianapolis, Hamilton County, Indiana, 46262, USA
Listing for: TriMedx, LLC
Full Time position
Listed on 2026-06-17
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below
Location: Indianapolis

TRIMEDX is seeking a Director of Information Security, a senior leadership role with full programmatic authority over the organization’s security posture. The Director will build, mature, and operate a comprehensive security program organized across five pillars:
Governance, Risk and Compliance;
Threat and Vulnerability Management;
Identity and Access Management;
Application and Cloud Security; and Resilience and Incident Response.

Responsibilities Accountabilities
  • Owns the organizational risk register as a living management tool that reflects current exposure and drives resource decisions.
  • Defines what security success looks like for the organization; develops and tracks KPIs that provide senior leadership a transparent, actionable view of risk posture and program ROI.
  • Leads, develops, and grows the security team across five operational pillars; establishes clear ownership, career paths, and accountability structures.
  • Shifts the security function from reactive, task-driven operations to a proactive, process-driven culture.
  • Serves as the organization’s primary security authority; makes risk-based decisions independently within agreed organizational risk appetite.
  • Serves as operational lead during and after security incidents – triage, resource coordination, retrospective and escalation to legal counsel and senior leadership per established protocols.
Governance, Risk & Compliance (Pillar
1)
  • Oversees execution of ISO 27001 and SOC 2 Type II compliance programs as a unified control framework; leads audit readiness, evidence collection, and control testing.
  • Governs vendor risk management, including third‑party security assessments and ongoing vendor performance against security requirements.
  • Establishes guardrails for AI/LLM adoption, referencing emerging standards such as ISO/IEC 42001.
  • Serves as a cross‑functional risk consultant to managers and directors, helping them recognize and articulate risk within their own domains.
  • Standardizes and streamlines response processes for customer security inquiries; develops a library of repeatable, high‑quality responses.
Threat & Vulnerability Management (Pillar
2)
  • Directs vulnerability management operations – scanning, prioritization, remediation tracking, and closure verification.
  • Owns the external threat intelligence program, ensuring continuous monitoring of the threat landscape relevant to the organization’s industry.
  • Oversees penetration testing engagements, including scope definition, vendor selection, and findings remediation.
Identity & Access Management (Pillar
3)
  • Sets IAM strategy and governance, including role‑based access design, MFA enforcement, privileged access management, and periodic access review cadence.
  • Ensures IAM operates within a defined governance structure with clear strategic direction.
Application & Cloud Security (Pillar
4)
  • Defines and maintains security baselines for cloud infrastructure (Azure), Dev Ops pipelines, and application development.
  • Embeds security guardrails into the development lifecycle as a natural part of engineering – not a gate or afterthought.
  • Owns API security standards and cloud security posture management.
  • Partners with engineering and architecture to ensure new systems are designed with a security‑first approach.
Resilience & Incident Response (Pillar
5)
  • Owns DR and BCP strategy, annual testing, and tabletop exercises; ensures recovery objectives align with business needs.
  • Ensures incident response plans are tested and current before they are needed.
Decision Making / Autonomy
  • Operates with full programmatic authority within organizational risk appetite – makes security decisions independently.
  • Escalates and provides recommendations to senior leadership on issues requiring executive or legal engagement.
Communications / Interactions
  • Briefs VP of IT and executive leadership using BLUF communication – clear context, current posture, and recommended action.
  • Represents the security program during M&A due diligence and new customer onboarding, providing accurate and credible security posture assessments.
  • Translates technical risk into business language that non‑technical stakeholders can act on without translation.
Leadership
  • Provides…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary