Director, Information Security
Centric Brands is a leading lifestyle brand collective that designs, sources, markets and sells high-quality products in multiple segments, including women’s, men’s and kid’s apparel, accessories, entertainment and beauty. We are defined by innovation, seizing new opportunities, and thriving in an environment informed by creativity and analytical thinking.
About the role
The Director of Information Security is responsible for developing and executing Centric Brands' enterprise cybersecurity strategy, protecting company information assets, and reducing cyber risk across the global business. This role leads security operations, governance, compliance, incident response, and emerging technology security programs while partnering with business and technology leaders to enable secure growth.
This position will be based in Greensboro, NC and follows a hybrid work schedule: Monday–Thursday in office, Friday remote. The schedule is subject to change based on business needs.
Responsibilities
- Provide strategic leadership for, and develop, implement, and operate, a company-wide information security program.
- Advise senior leadership on security program direction and resource investment; develop and manage the information security budget, aligning investments with risk priorities.
- Report regularly to executive leadership on security posture, risk reduction, incident readiness, and program maturity against defined KPIs.
- Manage and facilitate global information security governance processes; establish annual and long-range security and compliance goals, define security strategies, metrics, reporting mechanisms, and program services.
- Stay abreast of information security issues and regulatory changes affecting consumer goods, retail, and trade at state, national, and global levels; communicate updates to leadership.
- Mentor and coach the Information Security Office team, implementing professional development plans.
- Partner with infrastructure, network, cloud, application, and end-user computing teams to implement and maintain enterprise security standards and controls.
- Lead the development and implementation of effective and reasonable policies and practices to secure protected and sensitive data, ensuring compliance with relevant legislation.
- Coordinate and track all information technology and security-related audits, including scope, timelines, auditing agencies, and outcomes.
- Work with auditors to maintain audit focus, build cohesive security and compliance programs, and address global statutory and regulatory requirements (e.g., PCI, CCPA, GDPR).
- Support Legal Discovery requests as required.
- Create education and awareness programs on security issues, best practices, and vulnerabilities; advise operating units at all levels.
- Pursue employee-focused security initiatives addressing phishing, social engineering, and identity protection.
- Act as the primary control point during significant information security incidents; convene a Security Incident Response Team (SIRT) as needed.
- Own and maintain the company’s incident response plan, including playbooks and regular tabletop exercises with business stakeholders.
- Convene Ad Hoc Security Committee for breach response and notification actions.
- Partner with IT and business leaders to develop and test business continuity, disaster recovery, and cyber resilience plans.
- Establish and oversee a third-party risk management program, including security assessments of vendors, licensing partners, and key service providers.
- Provide leadership, direction, and guidance in assessing and evaluating information security risks; monitor compliance with security standards and policies.
- Support cyber insurance renewals, security questionnaires, and claims coordination.
- Develop, implement, and administer technical security standards and tools to address and mitigate security risk.
- Establish and oversee a vulnerability management program, including scanning, penetration testing, and remediation tracking.
- Oversee day-to-day security operations, including MDR/SOC partner management, security monitoring and detection, threat intelligence, and endpoint and email security.
- Set direction for cloud security posture and zero-trust architecture in partnership with infrastructure and application teams.
- Establish governance for identity and access management, including privileged access controls and periodic access reviews.
- Examine impacts of new technologies on the company’s overall information security; establish processes to review implementation of new technologies for security compliance.
- Establish governance, risk management, and security standards for artificial intelligence (AI), generative AI, machine learning, and automation technologies.
- Partner with business and technology leaders to enable responsible and secure adoption of AI solutions across the enterprise.
Requirements
- Bachelor’s degree in Information Systems, Computer Science, or related field required.
- CISSP, CISM, or equivalent security certification strongly preferred.
- Minimum of 10 years’ experience in information security, including 5+ years leading security teams or programs.
- Experience presenting security posture, risk, and program metrics to executive leadership.
- Experience leading global security programs; retail, consumer goods, or manufacturing industry experience a plus.
- Excellent written and verbal communication skills.
- Exceptional, hands-on leadership with an engaging, innovative, and collaborative style.
- Ability to work under pressure and tight deadlines; flexibility to travel as needed (approximately once per quarter).
- Availability to work occasional nights and weekends.
- Experience with Fortinet/FortiGate/Forticlient, Crowdstrike MDR/EDR, BitLocker, File Vault, MS Defender, and Azure Security services is a plus.
Benefits
- Industry-competitive salary and comprehensive benefits plan (medical, dental, vision).
- Matching 401(k) and generous PTO.
- Summer Fridays and merchandise discounts.
- Excellent career development opportunities.
- Social impact program (Centric Cares) focused on volunteerism in communities.
- Diversity, equity, and inclusion initiatives, including workshops and resources.
Pay
Job postings include an annual base salary range tailored to the selected candidate’s experience, industry knowledge, location, technical and communication skills, and other relevant factors. Base salary is part of a total compensation package, which may also include commission earnings, annual bonus, and other Centric Brands-sponsored benefit programs.