Director, Information Security
PubMatic · Redwood City, CA · 2 days ago
HybridInformation Technology$210k–$250k/yrFull-time
About The Role
PubMatic is seeking a Director of Information Security to lead and evolve our global security program across enterprise infrastructure, cloud platforms, products, corporate systems, and emerging AI technologies.
Executive Communication
- Strong command of board-level and executive presentation, including the judgment to lead with risk, business impact, or compliance depending on the audience.
- Ability to translate complex security concepts into clear, decision-ready narratives for leadership, auditors, and regulators.
Security Operations & User Impact
- Ability to design and roll out security controls that protect the organization without slowing people down.
- Must balance risk posture with operational velocity, plan phased implementations and manage change adoption across technical and non-technical teams.
AI & Automation
- Working knowledge of AI-powered security tooling (automation, threat detection, incident triage) and familiarity with emerging AI-specific risks such as LLM vulnerabilities, prompt injection, and data leakage through AI tools.
- Ability to shape organizational policy on safe AI adoption.
What You'll Do
Security Strategy & Leadership
- Define and execute PubMatic's enterprise information security strategy and multi-year roadmap.
- Lead Security Engineering, Security Operations, Governance, and Incident Response.
- Build a highly automated, AI-enabled security organization focused on excellence and operational efficiency.
- Establish executive security metrics, KPIs, and reporting for senior leadership and the Board.
- Manage a team of security engineers, security investments, vendor relationships, and strategic security initiatives.
Security Engineering & Operations
- Lead security architecture across cloud infrastructure, enterprise platforms, products, identity, networks, Kubernetes, endpoints, and data protection.
- Drive security automation, threat detection, vulnerability management, incident response, and continuous improvement.
- Partner with engineering teams to embed security by design throughout the software development lifecycle.
- Build reusable security platforms, self-service capabilities, APIs, and automation that enable developers while reducing operational overhead.
AI Security
- Develop and execute the company's AI security strategy and governance framework, with a security focus.
- Secure enterprise AI platforms, AI infrastructure, and AI-enabled applications.
- Leverage AI-powered technologies to improve threat detection, incident response, security operations, and overall operational efficiency.
- Guide the organization on secure adoption of Generative AI while addressing emerging risks such as prompt injection, data leakage, model abuse, and AI-specific attack vectors.
Governance & Business Partnership
- Maintain enterprise security governance in partnership with compliance and privacy teams, and third-party security programs.
- Partner with business leaders to balance security, regulatory requirements, employee productivity, and business agility.
- Lead security awareness initiatives that promote secure development and responsible AI adoption across the organization.
Who You Are
- Bachelor's degree or higher in Computer Science, Cybersecurity, Engineering, or related field. CISSP, CISM, CCSP, or equivalent certifications are preferred.
- 10+ years of progressive cybersecurity experience with at least 5 years leading enterprise security organizations.
- Strong expertise in cloud security, Security Engineering, Security Operations, IAM, Zero Trust, DevSecOps, Kubernetes, network security, and modern enterprise security architectures.
- Experience leading enterprise-wide security transformation and implementing automation to improve security operations.
- Working knowledge of AI-powered security technologies for automation, threat detection, incident triage, and operational efficiency.
- Strong understanding of AI security risks, including LLM security, prompt injection, AI governance, and secure enterprise AI adoption.
- Proven ability to design security programs that effectively balance risk reduction with employee productivity, developer experience, and business velocity.
- Demonstrated success leading large-scale security initiatives with thoughtful rollout strategies, change management, and user adoption planning.
- Exceptional executive presence with outstanding written, verbal, and presentation skills, including the ability to communicate effectively with executives, board members, customers, auditors, and regulators.
- Ability to translate complex technical and security topics into concise, business-focused, decision-ready recommendations tailored to different audiences.
- High attention to detail and a strong sense of executive communication quality and presentation excellence.
Schedule
- Return to Office: PubMatic employees throughout the globe have returned to our offices via a hybrid work schedule (3 days "in office" and 2 days "working remotely") that is intended to maximize collaboration, innovation, and productivity among teams and across functions.
Benefits
- Paid leave programs, paid holidays, healthcare, dental and vision insurance, disability and life insurance, commuter benefits, physical and financial wellness programs, unlimited DTO in the US (that we actually require you to use!), reimbursement for mobile and fully stocked pantries plus in-office catered lunches 5 days per week.
Pay
- Total Compensation Range: $210,000—$250,000 USD (includes base salary, bonus, restricted stock units, and competitive benefits package).