Director, Cyber Security
Position Summary
The Director of Cybersecurity is responsible for leading the enterprise's cybersecurity operations, incident response, and governance, risk, and compliance (GRC) programs. This role serves as a key member of the security leadership team, translating strategic security objectives into operational programs that protect the organization's information assets, infrastructure, and reputation. The Director will oversee a team of security professionals, manage the organization's security posture across threat detection, incident response, vulnerability management, and regulatory compliance, and serve as a trusted advisor to executive leadership on cyber risk.
Key Responsibilities
Own and continuously mature the enterprise incident response (IR) program, including playbooks, tabletop exercises, and post-incident reviews
Serve as incident commander for high-severity security incidents, coordinating cross-functional response efforts (Legal, Communications, IT, executive leadership)
Oversee Security Operations Center (SOC) functions, including threat detection, triage, containment, and remediation
Lead relationships with third-party incident response, digital forensics, and managed detection and response (MDR) providers
Lead root cause analysis and drive remediation of systemic vulnerabilities exposed by incidents
Establish and report on key incident metrics (MTTD, MTTR, containment time) to leadership and the board
Build and maintain the enterprise cybersecurity risk management framework, including risk registers, risk scoring methodologies, and treatment plans
Lead compliance efforts against applicable frameworks and regulations (e.g., NIST CSF/800-53, ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, FedRAMP, as applicable to the industry)
Manage internal and external audit engagements, including evidence collection, remediation tracking, and auditor liaison
Develop, implement, and maintain security policies, standards, and procedures
Oversee third-party/vendor risk management program, including security assessments and contract review
Partner with Legal and Privacy teams on regulatory obligations, breach notification requirements, and data protection matters
Present risk posture, compliance status, and program maturity to executive leadership, audit committee, and board of directors as needed
Direct vulnerability management program, including scanning, penetration testing coordination, and patch prioritization
Oversee identity and access management (IAM), endpoint detection and response (EDR), network security, and cloud security architecture in partnership with IT/engineering teams
Guide security architecture reviews for new systems, applications, and vendor integrations
Champion security awareness training and phishing simulation programs
Evaluate and recommend security tooling, technologies, and process improvements
Maintain threat intelligence awareness and translate emerging threats into actionable defensive measures
Minimum Qualifications
10+ years of progressive experience in cybersecurity, information security, or IT risk management, including demonstrated experience in incident response and GRC
5+ years of people management or team leadership experience
Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience
Demonstrated experience building or maturing incident response programs and leading response to significant security events
Strong working knowledge of regulatory and compliance frameworks (NIST, ISO 27001, SOC 2, PCI DSS, and/or industry-specific regulations)
Hands-on familiarity with security technologies: SIEM, EDR/XDR, vulnerability management platforms, IAM, cloud security posture management (CSPM)
Experience managing third-party risk assessments and vendor security reviews
Excellent written and verbal communication skills, including experience presenting to executive leadership and boards
Proven ability to manage competing priorities in a fast-paced, evolving threat landscape
Preferred Qualifications
Master's degree (MBA, MS in Cybersecurity/Information Assurance, or related)
Relevant industry certifications: CISSP, CISM, CRISC, CISA, GCIH, GCFA, or equivalent
Experience in [industry-specific: aviation, financial services, healthcare, government contracting, etc.],
Familiarity with privacy regulations (GDPR, CCPA) and their intersection with security programs
Experience supporting SEC cybersecurity disclosure requirements (for public companies)
Core Competencies
Incident Command: Ability to lead cross-functional response under pressure with clear decision-making
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders
Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders