Companies you'll love to work for

BBG Ventures
BBG Ventures

Director of Information Security



Posted on Sunday, May 26, 2024

Who we are

HopSkipDrive’s mission is to create opportunity for all through mobility. Our innovative, supplemental school transportation solutions are used by over 600 school districts, charter schools, nonprofits, government agencies, as well as busy families to safely and reliably get kids where they need to go.

Student transportation is the largest mass transit system in the U.S. The way kids get to and from school has a direct impact on our kids, families, schools and communities. While school districts spend $28 billion annually on transportation, only 30% of kids get to school on a bus. The current system can no longer meet all the transportation needs of our districts, schools and families — and its shortcomings are causing inequities in educational access that are affecting the welfare of millions of kids each day.

HopSkipDrive is taking a different approach to arranging safe, reliable school transportation that meets needs that aren’t being addressed by the current system, helping to fill gaps and supplement the student transportation options available. We create personalized transportation solutions for the one to the many, and everything in between.

We’re a company with heart

Our partnerships with school districts, child welfare agencies and nonprofits ensure equitable educational access for the most vulnerable populations, including youth in foster care, children experiencing homelessness and students with disabilities.

We understand that the difference between struggle and success can sometimes be as simple as the ability to show up, which is why we’re on a mission to use innovative technology — coupled with operational expertise and new ways of thinking — to help kids reach their full potential by providing a safe, dependable way to get them where they are going.

We’re an awesome place to work

Our company culture has been well-recognized — HopSkipDrive has been named to Fast Company’s Most Innovative Companies list, as well as Best Places to Work lists from Built In LA, Comparably, Inc., and the Los Angeles Business Journal. Comparably also named us a Best Company for Professional Development, as well as to its Best CEO and Best CEOs for Women lists.

We’re growing rapidly

Founded by three moms as a solution to their own transportation challenges, we now operate across over 13 states across the country. We continue to expand at a rapid pace, making the Inc. 5000 list four times, as well as the Deloitte 500 Fast-Growing Technology list. HopSkipDrive has raised $100M in funding to date.

Who you are

As a Director of Information Security, you will be at the forefront of safeguarding our company's digital assets and ensuring compliance with critical industry standards. You will lead initiatives to enhance our security posture, manage compliance efforts, and communicate security risks effectively to various stakeholders. Your role will encompass both strategic and operational responsibilities, ensuring our security practices align with business goals and regulatory requirements.

You will collaborate closely with Product, Engineering, People Ops, IT, Legal, and other departments to maintain compliance with frameworks such as SOC 2 and HIPAA. Your expertise will guide the company through the complexities of security risk management, incident response, and vulnerability management. Additionally, you will be responsible for proposing and implementing a cybersecurity roadmap, managing security training programs, and ensuring our technology stack, including logging, SIEM, and AWS, remains secure and up-to-date. You are a hands-on individual comfortable functioning as an individual contributor, while you have the leadership skills to build a team as we scale. You will report directly to the Chief Product Officer.

What you'll do:

Compliance and Governance

  • Maintain SOC 2 compliance for the company, ensuring timely collection of evidence from engineering, People Ops, and IT.
  • Review legal documents, such as vendor contracts, data processing agreements, and RFPs, to ensure our company's security practices align with contractual requirements.
  • Familiarity with compliance frameworks such as SOC 2 and HIPAA.

Risk Management and Communication

  • Proactively identify areas to improve security across our applications.
  • Communicate security risks to business owners and stakeholders effectively.

Security Operations

  • End-to-end management of annual penetration tests, including vetting vendors, communicating with pen test companies, triaging findings, and delegating remediation to the engineering team.
  • Manage cybersecurity metrics, tracking and reporting on the effectiveness of security measures.

Strategic Planning and Training

  • Propose and implement a quarterly cybersecurity roadmap to address evolving security challenges.
  • Manage cybersecurity training programs, including phishing training and specialized security training for engineers.

Incident Response and Vulnerability Management

  • Own incident response, translating suspected issues into security risks and managing the end-to-end investigation and triage process.
  • Own the vulnerability management program, ensuring timely identification and remediation of vulnerabilities.

Technical Expertise

  • Proficiency in technologies such as log analysis, SIEM, and AWS to support security initiatives.
  • Knowledge of security automation tools and scripting languages to enhance security operations is a plus.

Additional Responsibilities

  • Stay current with the latest security trends, threats, and technology advancements to continuously improve the company's security posture.
  • Collaborate with cross-functional teams to integrate security best practices into all aspects of the business.
  • Advocate for a security-first culture within the organization, promoting awareness and proactive risk management.

What you bring to the role

Education and Experience

  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • Minimum of 5 years of experience in a security-related role, preferably within a technology company.
  • Proven track record of maintaining SOC 2 compliance and managing other compliance frameworks such as HIPAA.
  • Relevant security certifications such as CISSP, CISM, or CISA are highly desirable.

Technical Skills:

  • Deep understanding of security technologies, including log analysis, Security Information and Event Management (SIEM), and cloud security (AWS).
  • Experience with security automation tools and scripting languages (e.g., Python, Bash).
  • Proficiency in vulnerability management tools and processes.

Analytical and Problem-Solving Skills

  • Strong analytical skills to identify security risks and develop effective mitigation strategies.
  • Proven ability to manage and respond to security incidents effectively.

Communication and Interpersonal Skills

  • Excellent communication skills to articulate security risks and recommendations to both technical and non-technical stakeholders.
  • Ability to collaborate with cross-functional teams and influence without authority.

Organizational and Project Management Skills

  • Strong project management skills with the ability to manage multiple initiatives simultaneously.
  • Experience in developing and implementing strategic security roadmaps.

Personal Attributes

  • Highly motivated and proactive with a passion for staying current on the latest security trends and technologies.
  • Strong ethical standards and a commitment to maintaining the highest levels of confidentiality and integrity.

** This role will be fully remote in one of the following states AZ, CA, CO, DC, FL, IL, IN, KS, MD, MI, MO, NC, NJ, NM, NV, NY, OK, OR, SC, TN, TX, UT, VA, WA, WI**

What you will get

We want you to be an owner in our company and share in executing our vision, so every full-time employee has equity. In addition, we offer competitive market comp, flexible vacation, FSA, medical, dental and vision, 401(k), and an opportunity to work for a uniquely positioned, VC-backed company in a hugely attractive space with significant upside potential. HopSkipDrive is committed to fair and equitable compensation practices. The salary range for this role is 130,000 to 170,000. Final compensation for this role will be determined by several factors such as a candidate’s relevant work experience, skill set and specific work location. The total compensation package for this role also includes equity stock options.

Equal Opportunity Employer

HopSkipDrive is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other protected class. HopSkipDrive is also proud to operate as a drug-free workplace.