Vice President, Cloud & SaaS Security
The Vice President of Cloud & SaaS Security leads enterprise-wide cloud and SaaS security strategy, governance, and architecture to ensure regulatory compliance, data protection, and risk management across all environments. This role drives the design and operation of cloud-native security platforms, embeds “security by design” into modern architectures, and advances automation for continuous compliance. As a senior leader, the VP influences executive decisions, fosters cross-functional collaboration, and develops high-performing global teams to enable secure innovation at scale.
1.Cloud Security Compliance & Governance
- Lead the cloud security governance program ensuring alignment with regulatory, compliance, and risk management standards.
- Establish and drive cloud security policies, standards, and controls across all cloud environments.
- Partner with broader security domain teams to ensure requirements are met across security disciplines and tracked to closure for each primary cloud initiative
- Develop transparent reporting and metrics to inform executive decision-making and board-level visibility into cloud risk posture.
2. Cloud Security Architecture
- Define and oversee enterprise-wide cloud security architecture and reference models across public, private, and hybrid environments.
- Guide secure design principles for new technologies, ensuring resilient and scalable architectures that balance innovation with control.
- Collaborate closely with enterprise architecture, infrastructure, and application teams to embed security by design.
- Provide strategic direction for secure adoption of modern architectures
3. Cloud Security Engineering
- Lead the build and operation of cloud-native security platforms, tools, and automation that enable secure innovation at scale.
- Partner with DevOps and platform teams to enable “security as code” and integrate advanced automation for continuous compliance.
- Mentor technical leaders to strengthen engineering excellence and operational maturity across teams.
4. SaaS Security
- Own the enterprise SaaS security strategy, ensuring robust data protection, access control, and compliance across all SaaS applications.
- Establish a unified approach to SaaS risk management, integrating security reviews, vendor assessments, and ongoing monitoring.
- Drive automation and innovation in SaaS discovery, configuration management, and data governance.
Leadership & Behavioral Strengths
- Cross-Functional Leadership: Inspire and align teams across Cloud, Engineering, Risk, and Business Technology to drive a unified cloud security vision.
- Strategic Prioritization: Demonstrate strong program and platform management, balancing near-term deliverables with long-term enterprise outcomes.
- Relationship Management: Build deep partnerships across internal technology, business, and external cloud providers to influence and shape security outcomes.
- Collaboration & Inclusion: Foster a culture of trust, transparency, and shared accountability; bring others along by enabling, not obstructing.
- Influence Without Authority: Effectively communicate complex security concepts to executive and non-technical audiences to drive informed decisions.
- Talent Development: Champion the growth and empowerment of diverse teams through coaching, recognition, and opportunities for innovation.
- Education:
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical field.
- Experience:
- 15+ years of progressive experience in technology, including cloud security architecture, governance, and engineering.
- 5+ years in a senior leadership or executive role, leading large, cross-functional security or technology teams.
- Proven experience with major cloud platforms (AWS, Azure, GCP) and SaaS security management at enterprise scale.
- Technical Expertise:
- Deep knowledge of cloud security frameworks (CIS, NIST, ISO 27017/18, CSA).
- Strong understanding of DevSecOps, security automation, identity and access management, compliance, and data protection in cloud and SaaS environments.
- Hands-on familiarity with cloud-native security tools and security as code practices.
- Leadership & Communication:
- Demonstrated ability to influence executive stakeholders and align security with business strategy.
- Skilled in governance, risk management, and creating board-level reporting on cloud risk posture.
- Proven track record in mentoring senior technical leaders and fostering a culture of collaboration and inclusion.
- Certifications (preferred but not strictly required):
- CISSP, CCSP, CISM, or cloud provider certifications (e.g., AWS Certified Security – Specialty, Azure Security Engineer Associate).
Employment eligibility to work with American Express in the U.S is required as the company will not pursue visa sponsorship for these positions