Director of Security and Compliance
$200,000–$225,000 year
On-siteNew York City, New York, United States or San Francisco, California, United States
Job Summary
Design and oversee cybersecurity, compliance, and privacy programs safeguarding digital assets while ensuring adherence to regulatory requirements and internal policies. Set the mission and strategy for technology risk management, implementing mitigation efforts that align with business objectives and product priorities. Direct enterprise-wide security architecture and operations across IT and OT environments, conducting comprehensive risk assessments and developing business continuity and incident response strategies. Lead cross-functional teams to foster an enterprise security culture through organization-wide training, manage the annual department budget, and negotiate with security service providers. Ensure compliance with regulations such as NIST 800-171, CMMC, and ISO 2700x, while maintaining digital archiving systems and collaborating with product managers to align services with data retention policies.
Required Qualifications
- Bachelor's or Master's degree in business administration or technology related field
- 15 or more years of experience in IT Operations, cybersecurity or business/industry
- 7 or more years of leadership responsibilities, including strategy, budgeting, and staffing
- 3 or more years of leadership responsibilities of an auditable compliance program (ex: NIST 800-171, CMMC, ISO 2700x, SOC 2, NERC-CIP, etc.)
- Exceptional leadership skills, with the ability to develop and communicate a vision that inspires and motivates staff and aligns with the IT and business strategy
- Effective influencing and negotiation skills and the ability to build consensus in complex environments where resources required for success may not be in direct control of this role
- Demonstrate collaboration skills across multiple teams including business operating groups, corporate departments and other IT teams
- Excellent analytical, strategic conceptual thinking, strategic planning, and execution skills
- Strong business acumen, including industry, domain-specific knowledge of the enterprise and its business units
- Developing staff including coaching, mentoring and performance management
- Deep understanding of current and emerging security technologies and practices, and how other enterprises are employing them
- Strong awareness of current and changing regulatory landscape
- Maintain awareness of emerging threats and incorporate appropriate mitigation measures
- Demonstrated ability to develop and execute a strategic staffing plan that ensures the right people are in the right roles at the right time, and employees are highly engaged and satisfied
- Third-party management, working closely with sourcing and vendor managers
- Security services - SaaS, on-premises, Managed Security Service Providers
- NIST 800-CSF, NIST 800-53
- Cloud & Network architecture
- Identity and access management
- Business continuity & disaster discovery
- Data management, classification and privacy
- Artificial Intelligence
- Microsoft
- AWS
Desired Qualifications
- Certified Information Systems Security Professional (CISSP)
- Certified Information Security Manager (CISM)
- Certified Information Systems Auditor (CISA)
- Certified in Risk and Information Systems Control (CRISC) or other similar credentials
- Cisco
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.