Jobs · Information Technology · Colorado

Director, Cyber Security

Gogo · Denver Metropolitan Area · 2 days ago
On-siteInformation TechnologyFull-time

Position Summary

The Director of Cybersecurity is responsible for leading the enterprise's cybersecurity operations, incident response, and governance, risk, and compliance (GRC) programs. This role serves as a key member of the security leadership team, translating strategic security objectives into operational programs that protect the organization's information assets, infrastructure, and reputation. The Director will oversee a team of security professionals, manage the organization's security posture across threat detection, incident response, vulnerability management, and regulatory compliance, and serve as a trusted advisor to executive leadership on cyber risk.

Key Responsibilities

  • Own and continuously mature the enterprise incident response (IR) program, including playbooks, tabletop exercises, and post-incident reviews

  • Serve as incident commander for high-severity security incidents, coordinating cross-functional response efforts (Legal, Communications, IT, executive leadership)

  • Oversee Security Operations Center (SOC) functions, including threat detection, triage, containment, and remediation

  • Lead relationships with third-party incident response, digital forensics, and managed detection and response (MDR) providers

  • Lead root cause analysis and drive remediation of systemic vulnerabilities exposed by incidents

  • Establish and report on key incident metrics (MTTD, MTTR, containment time) to leadership and the board

  • Build and maintain the enterprise cybersecurity risk management framework, including risk registers, risk scoring methodologies, and treatment plans

  • Lead compliance efforts against applicable frameworks and regulations (e.g., NIST CSF/800-53, ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, FedRAMP, as applicable to the industry)

  • Manage internal and external audit engagements, including evidence collection, remediation tracking, and auditor liaison

  • Develop, implement, and maintain security policies, standards, and procedures

  • Oversee third-party/vendor risk management program, including security assessments and contract review

  • Partner with Legal and Privacy teams on regulatory obligations, breach notification requirements, and data protection matters

  • Present risk posture, compliance status, and program maturity to executive leadership, audit committee, and board of directors as needed

  • Direct vulnerability management program, including scanning, penetration testing coordination, and patch prioritization

  • Oversee identity and access management (IAM), endpoint detection and response (EDR), network security, and cloud security architecture in partnership with IT/engineering teams

  • Guide security architecture reviews for new systems, applications, and vendor integrations

  • Champion security awareness training and phishing simulation programs

  • Evaluate and recommend security tooling, technologies, and process improvements

  • Maintain threat intelligence awareness and translate emerging threats into actionable defensive measures

Minimum Qualifications

  • 10+ years of progressive experience in cybersecurity, information security, or IT risk management, including demonstrated experience in incident response and GRC

  • 5+ years of people management or team leadership experience

  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience

  • Demonstrated experience building or maturing incident response programs and leading response to significant security events

  • Strong working knowledge of regulatory and compliance frameworks (NIST, ISO 27001, SOC 2, PCI DSS, and/or industry-specific regulations)

  • Hands-on familiarity with security technologies: SIEM, EDR/XDR, vulnerability management platforms, IAM, cloud security posture management (CSPM)

  • Experience managing third-party risk assessments and vendor security reviews

  • Excellent written and verbal communication skills, including experience presenting to executive leadership and boards

  • Proven ability to manage competing priorities in a fast-paced, evolving threat landscape

Preferred Qualifications

  • Master's degree (MBA, MS in Cybersecurity/Information Assurance, or related)

  • Relevant industry certifications: CISSP, CISM, CRISC, CISA, GCIH, GCFA, or equivalent

  • Experience in [industry-specific: aviation, financial services, healthcare, government contracting, etc.],

  • Familiarity with privacy regulations (GDPR, CCPA) and their intersection with security programs

  • Experience supporting SEC cybersecurity disclosure requirements (for public companies)

Core Competencies

  • Incident Command: Ability to lead cross-functional response under pressure with clear decision-making

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

  • Risk-Based Thinking: Translates technical risk into business impact for non-technical stakeholders

Similar jobs

Director, Cybersecurity

FTI ConsultingChicago, IL· 3 days ago
OTHR$145k/yrapply on fticonsulting.wd108.myworkdayjobs.com

Director, Cybersecurity

FTI ConsultingNew York, NY· 3 days ago
OTHR$145k/yrapply on fticonsulting.wd108.myworkdayjobs.com

Director, Cybersecurity

Ensemble Health PartnersUnited States· 1 mo ago
RemoteOTHR$148k–$268k/yrapply on ensemblehp.wd5.myworkdayjobs.com