Director Compliance and Security
Job Description
<p><strong>Director, Compliance & Security</strong></p> <p><strong>About Boingo Wireless</strong></p> <p>At Boingo, we simplify complex wireless challenges to connect people, businesses, and things—spanning airports, stadiums, military bases, transit hubs, and commercial properties.</p> <p>As our <strong>Director of Compliance & Security</strong>, you will lead strategy across all aspects of data integrity & security, as well as governance, risk & compliance. We are actively expanding beyond enterprise defense to build and deliver security as a product embedded into our DAS, Wi-Fi, and private network offerings. We are looking for an innovative leader to build an automation-first security organization that eliminates manual, ticket-driven friction and scales seamlessly across enterprise and commercial product architectures.</p> <p><strong>What You’ll Do</strong></p> <ul> <li><strong>Security, GRC & Compliance Leadership:</strong> Oversee the Security Compliance / GRC Cybersecurity. Own and mature Boingo's GRC program - including risk register management, control mapping, evidence collection, audit readiness for NIST and SOC 2.</li> <li><strong>Enterprise Operations & Policy:</strong> Partner cross-functionally with IT, Legal, HR, Finance, and Engineering on policy development, vendor security, incident response, and risk acceptance. Ensure security architecture, IAM / PAM, vulnerability management, logging, monitoring, and endpoint security programs operate effectively across the enterprise.</li> <li><strong>Venue Security Product & Network Security:</strong> Partner with Product, Engineering, and Network Operations to embed security controls into network designs (DAS, private networks, Wi-Fi) and support the go-to-market readiness of Boingo’s venue security products. Serve as a senior security voice in cross-functional discussions involving network architecture and product roadmaps.</li> <li><strong>Strategy & Automation:</strong> Define the annual Security strategy, roadmap, and budget. Drive the unification of IT operations and security into a single control plane for identity, devices, and access to reduce manual touchpoints across the enterprise.</li> <li><strong>Escalation & Governance:</strong> Serve as the core escalation point for major incidents, audit findings, control gaps, and operational outages. Represent Security in internal forums, audit activities, and customer security reviews.</li> </ul> <p><strong>What You Bring</strong></p> <ul> <li><strong>Security Leadership:</strong> 5+ years in information technology, security, or infrastructure leadership, with 3+ years directly managing teams across GRC and information security.</li> <li><strong>Automation-First Mindset:</strong> Proven history of replacing manual, ticket-heavy processes with automated compliance, logging, and security workflows.</li> <li><strong>Technical Architecture:</strong> Hands-on experience securing a multi-platform enterprise environment, including Microsoft 365/Entra ID, Google Workspace, multi-OS MDM (Mac, Windows), and Zero Trust access architectures.</li> <li><strong>Framework Mastery:</strong> Deep working experience with NIST cybersecurity frameworks, GRC program operation, including the successful completion of NIST & SOC 2 audits.</li> <li><strong>Product & Commercial Experience:</strong> Experience applying security controls, IAM, and compliance frameworks to commercially available products or multi-tenant venue networks (SaaS, NaaS, or telecom preferred).</li> <li><strong>Cross-Functional Infl