Back to positions

VP, Information Security, Risk and Compliance

Remote role Full-time Open position

About Direct Travel 

We are a global travel management and services company operating at the intersection of travel, technology, finance, and customer experience.  As we modernize our technology stack and build our own data-driven products, we are making significant investments in security, compliance, and governance to serve our customers. Our future is centered on AI innovation to reduce operational costs and deliver personalized, intelligent experiences for customers worldwide. 

 

Role Overview

The Vice President of Information Security & Compliance is a strategic executive leader responsible for overseeing global information security, data protection, governance, and compliance programs. This leader will ensure that our products, infrastructure, and operations meet international standards—specifically targeting ISO 42001 (AI Management System) certification and PCI-QSA compliance within the next 18 months. 

This position demands a forward-looking leader who blends deep technical expertise, regulatory insight, and operational pragmatism to protect customer trust while enabling innovation. 

Reporting to: Chief Information Officer 

Key Responsibilities

  • Security & Compliance Strategy: Develop and execute a global security and compliance roadmap aligned with corporate goals, focusing on ISO 27001 and SOC2, and expanding to ISO 42001, PCI-DSS, GDPR, CCPA, and other emerging data privacy frameworks. 
  • AI Governance: Establish robust policies and risk models for secure and ethical AI adoption across products and platforms, ensuring adherence to future AI regulatory standards. 
  • Data Privacy & Protection: Lead initiatives to design privacy-first architectures supporting international data residency, cross-border transfer compliance, and encryption standards. 
  • DevSecOps Maturity:  Partner with engineering and DevOps teams to build security into the product development lifecycle—deploy secure pipelines, automate compliance checks, and continuously monitor infrastructure health. 
  • Risk, Audit & Incident Response: Maintain enterprise risk management processes, lead internal audits, coordinate external assessments, and oversee incident response and recovery workflows. 
  • Team Leadership: Build, mentor, and scale a global security & compliance organization with capabilities spanning application security, cloud security, GRC, and data protection. 
  • Stakeholder Collaboration: Work cross-functionally with Sales, Product, Legal, Finance, and IT to align organizational practices and ensure security and compliance enable business growth—not constrain it. 

 

Qualifications

  • 12+ years of experience in information security or compliance, with at least 5 years in senior leadership driving enterprise-wide programs. 
  • Proven track record leading PCI-DSS, ISO, or SOC 2 compliance initiatives in a SaaS or financial/merchant-of-record context. 
  • Deep understanding of cloud architectures (AWS, Azure, or GCP), security platforms, secure software development, and modern DevSecOps tools and practices. 
  • Experience establishing AI governance, risk management, or model assurance frameworks preferred. 
  • Strong familiarity with data privacy regulations across EU, US, and APAC jurisdictions.
  • Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), or equivalent credentials highly desirable.
  • Exceptional communication, leadership, and change management skills. 

 

Success in the Role

  • Integration of the security team, processes and systems in our ATPI business unit 
  • ISO 27001 and 42001 certification achieved within 18 months. 
  • PCI-QSA compliance achieved within 18 months.
  • Embedded security-by-design across the product lifecycle. 
  • Demonstrable improvement in operational resilience and customer trust.
Apply To This Job

Further positions

Junior Angular Developer (Bogota, CO)

Remote role Full-time

Embedded Software Engineer Entry (Remote anywhere in México) (Guadalajara, MX)

Remote role Full-time

Junior Java Developer (Bogota, CO)

Remote role Full-time

Bilingual DataOps Engineer (Bogota, CO)

Remote role Full-time

Software Engineer III - RMX Dispatch

Remote role Full-time

Disability and Leave Management Claims Specialist (Disability Claims Experience Required) (REMOTE)

Remote role Full-time

Creative Director – Design, Enterprise Marketing (Remote) in Utah, United States

Remote role Full-time

Senior Customer Support Engineer

Remote role Full-time

Associate General Counsel

Remote role Full-time

Forward Deployed Solutions Engineer [Commercial]

Remote role Full-time

Remote Sales Associate (No Experience Needed)

Remote role Full-time

Immediate Hiring: Provide Customer Service for Leading Home Repair Company at arenaflex

Remote role Full-time

Senior Software Quality Assurance Engineer (Low Code, No Code; C, C++)

Remote role Full-time

Experienced Customer Service - Event Expert

Remote role Full-time

Coding Compliance Auditor - Physician Practice job at Shirley Ryan AbilityLab in US National

Remote role Full-time

Freelance Kazakh Language Specialist (Remote)

Remote role Full-time

Experienced Data Entry Office Administrator – In-Person Role in Alpharetta, GA

Remote role Full-time

Clearwater Cove - Seasonal Guest Services Specialist - Waterfront

Remote role Full-time

Full Stack Developer

Remote role Full-time

Part-Time Data Entry Specialist – Remote Position | Flexible Hours & Competitive Pay at arenaflex

Remote role Full-time