Infinity Constellation Logo

Infinity Constellation

Director, Security - Cosmos

Posted 10 Days Ago
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
The Director, Security will create and lead Cosmos's security strategy, overseeing compliance, risk management, and incident response processes.
The summary above was generated by AI
Director, Security at Cosmos

About Cosmos

Cosmos is a new Infinity Constellation venture poised to redefine managed IT services for mid-market companies. By fusing human expertise with advanced AI automation, we deliver faster, smarter, outcome-based IT support that frees customers to focus on their core business. If you join as the CEO you will be helping us to start this company from day 1, you will be joining as the first member of the team with capital and support to grow a team and a business with us.

Role Overview

Infinity is seeking a Director, Security to design and oversee the security strategy for Cosmos. This leader will establish Cosmos foundational security program, implement scalable processes and controls, and ensure our companies consistently meet and exceed client security and compliance expectations.

The role requires both strategic vision and hands-on execution. You’ll be responsible for building the frameworks that unify Cosmos security posture, while also diving deep into individual portfolio companies to stand up policies, remediate gaps, and directly support client/vendor diligence reviews. Over time, this function may evolve into a dedicated security services offering within Infinity’s shared services ecosystem.

Key Responsibilities
  • Security Program Leadership

    • Build Infinity’s portfolio-wide security policies, standards, and controls.

    • Own certification/compliance programs (SOC 2, ISO 27001, HIPAA GDPR/CCPA alignment, etc.).

    • Maintain a central library of security documentation to support sales and client diligence.

  • Governance, Risk & Compliance

    • Develop and oversee vendor/third-party risk management.

    • Implement data classification, retention, and destruction policies.

    • Ensure consistent incident response, access review, and audit cadences across companies.

  • Hands-On Company Engagement

    • Partner with engineering and leadership teams at portfolio companies to establish secure practices from day one.

    • Lead security diligence with client and vendor teams, ensuring successful outcomes.

    • Standardize secure development lifecycles, access management, and cloud security baselines.

  • Incident Response & Continuity

    • Implement an incident response framework with clear escalation paths.

    • Run tabletop exercises, penetration testing, and remediation tracking.

    • Build continuity/disaster recovery standards that scale across companies.

  • Enablement & Culture

    • Lead company-wide security training and awareness programs.

    • Build a “secure by default” culture that supports, not slows, innovation.

    • Serve as the trusted advisor to leadership on risk, compliance, and client security expectations.

Qualifications
  • 7+ years in security leadership roles, ideally spanning both startup and enterprise contexts.

  • Track record of building and running SOC 2, HIPAA, ISO 27001, or equivalent programs.

  • Experience in client facing roles interfacing directly with stakeholders and client security teams as a part of the sales process

  • Strong technical understanding of cloud security (AWS/GCP), encryption, identity and access management, and secure SDLC practices.

  • Experience successfully navigating client/vendor security diligence processes.

  • Ability to operate both strategically (designing systems for scale) and tactically (closing gaps in fast-moving environments).

What Success Looks LikeFirst 3 Months
  • High priority portfolio companies have established security programs

  • High priority portfolio companies have established security documentation for use by client sales teams

First 12 Months
  • A portfolio-wide security program is established and documented.

  • Core certifications (SOC 2 Type I/II or equivalent) underway or complete.

  • Centralized security documentation package (“deal room”) created and in use.

  • Client/vendor diligence reviews consistently passed with no material gaps.

  • Security becomes a competitive advantage across the Infinity portfolio.

Top Skills

Aws,Gcp,Soc 2,Iso 27001,Hipaa,Gdpr,Ccpa

Similar Jobs

An Hour Ago
Easy Apply
Remote or Hybrid
United States
Easy Apply
123K-198K Annually
Senior level
123K-198K Annually
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Lead a team of recruiters focused on scaling Samsara's R&D teams by developing sourcing strategies, influencing senior leaders, and adopting new recruiting tools to improve processes and outcomes.
Top Skills: Ai SolutionsRecruiting Tools
An Hour Ago
Remote or Hybrid
US
190K-190K
Senior level
190K-190K
Senior level
AdTech • Consumer Web • Digital Media • eCommerce • Marketing Tech
The Senior Software Engineer will collaborate to build and maintain User Registration and Management platforms, design and implement new services, and mentor team members while ensuring high-quality software services.
Top Skills: AWSAws DynamodbAws LambdaAws RdsDatadogDockerGoogle Cloud FunctionsGrafanaKafkaKibanaMemcachedRedisRestful ApisSplunk
An Hour Ago
Easy Apply
Remote
United States
Easy Apply
102K-160K Annually
Junior
102K-160K Annually
Junior
AdTech • Digital Media • Marketing Tech • Software • Automation
As a Data Engineer, you will enhance the developer experience by maintaining ETL pipelines, integrating data sources, automating processes, and ensuring code quality.
Top Skills: Ci/CdGitJavaPythonSnowflakeSQL

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account