GoodLeap logo

Senior Director, Information Security

🔍 Found ClimateTechList useful?

ClimateTechList is free for job seekers, no registration required, and I, Steven, run it by myself at cost part-time.

The site gets about 30,000-40,000 users a month. Help support this site and make it easier for other future climate job seekers!

You can buy me a coffee to support the site below. Thanks!

Job Description

About GoodLeap:

GoodLeap is a technology company delivering best-in-class financing and software products for sustainable solutions, from solar panels and batteries to energy-efficient HVAC, heat pumps, roofing, windows, and more. Over 1 million homeowners have benefited from our simple, fast, and frictionless technology that makes the adoption of these products more affordable, accessible, and easier to understand. Thousands of professionals deploying home efficiency and solar solutions rely on GoodLeap’s proprietary, AI-powered applications and developer tools to drive more transparent customer communication, deeper business intelligence, and streamlined payment and operations. Our platform has led to more than $27 billion in financing for sustainable solutions since 2018.

GoodLeap is also proud to support our award-winning nonprofit, GivePower, which is building and deploying life-saving water and clean electricity systems, changing the lives of more than 1.6 million people across Africa, Asia, and South America.


Position Summary

GoodLeap is seeking an experienced and dynamic Senior Director of Information Security to join our team. This role is critical in ensuring the security and integrity of our innovative financial solutions, safeguarding our customers, and maintaining the trust and credibility of our platform. As Senior Director of Information Security, you will lead and mentor a team of security professionals within application security, cloud security, and compliance; collaborate with cross-functional teams, and drive the development and implementation of robust security strategies.


Leadership and Strategy:

Develop and execute a comprehensive information security and application security strategy aligned with GoodLeap’s business goals and regulatory requirements.

Lead, mentor, and grow a high-performing team of security professionals.

Foster a culture of security awareness and best practices across the organization.

Collaborate with executive leadership to prioritize security initiatives and investments.

Security Operations:

Direct the implementation and management of security technologies and tools to protect the organization's assets.

Lead the team to monitor and respond to security incidents, vulnerabilities, and threats in a timely and effective manner.

Ensure regular security assessments, audits, and penetration testing to identify and mitigate risks are conducted.

Ensure compliance with relevant regulatory requirements and industry standards (e.g., GDPR, CCPA, PCI-DSS).

Application Security:

Direct efforts to develop and guide secure coding practices and application security standards.

Collaborate with engineering and product teams to integrate security into the software development lifecycle (SDLC).

Supervise code reviews and security testing used to identify and remediate vulnerabilities.

Direct the security training and awareness programs for developers and other stakeholders.

Cloud Security:

Develop and implement cloud security strategy and roadmap aligned with organizational goals and regulatory requirements.

Direct the design, implementation, and monitoring of cloud security controls to protect cloud environments from threats and vulnerabilities.

Ensure compliance with industry standards (e.g., ISO 27001, NIST) and regulatory requirements related to cloud security.

Oversee of our suite of security tools, including SAST, SCA, DIST, and IIST.

Risk Management:

Lead the identification, assessment, and prioritization of security risks to the organization’s assets and operations.

Develop and implement risk management strategies and mitigation plans.

Create and maintain security policies, procedures, and documentation.

Stay abreast of emerging security threats, trends, and technologies to proactively address potential risks.

Collaboration and Communication:

Partner with cross-functional teams, including IT, legal, compliance, and operations, to ensure cohesive security efforts.

Communicate security risks, strategies, and initiatives to executive leadership

Represent GoodLeap in industry forums, conferences, and working groups related to information security.

ClimateTechList.com logo

GoodLeap number of job openings over time by month

ClimateTechList is the web's largest aggregator of climate, clean tech, renewable energy & green jobs. Contact us if you'd like to use partner or use our current or historical jobs data in any way.

Apply to Job

👉 Please mention that you found the job on ClimateTechList, this helps us get more climate tech companies listed here, thanks!

Get a referral to GoodLeap

If possible, try to get a warm intro/referral to GoodLeap before applying! Do a LinkedIn search to see who you may know at the company. See this LinkedIn post from Steven for more details on this tactic.

All job openings from GoodLeap

Join ClimateTechList Talent Collective

Want to be matched with companies directly? Apply to the talent collective.

Here's how it works:

  1. You submit an application

  2. We'll share your profile with climate tech companies potentially interested in chatting with you

  3. We'll reach out if there's a company interested in talking to you.

Join ClimateTechList Talent Collective

Want to be matched with companies directly? Apply to the talent collective.

Here's how it works:

  1. You submit an application

  2. We'll share your profile with climate tech companies potentially interested in chatting with you

  3. We'll reach out if there's a company interested in talking to you.