Director of Cyber Security (HYBRID) Bolingbrook - IL
S&S Activewear · Bolingbrook, IL · 2 mo ago
Information TechnologyFull-time
About the role
We are seeking a seasoned Chief Information Security & Privacy Officer (CISO/CPO) responsible for leading our enterprise-wide cybersecurity, data protection, and privacy programs. This role ensures the security of systems supporting high-volume B2B operations, including eCommerce platforms, ERP systems, technology integrations, and warehouse/logistics technologies—while establishing a practical, scalable privacy framework.
- Own the cybersecurity roadmap and guide the programs evolution over multiple years
- Translate business objectives and technology strategy into pragmatic security priorities
- Balance risk reduction, operational efficiency, and business agility in decision-making
- Establish and mature governance processes that are practical, scalable, and well-integrated into how the company operates
- Define and maintain security architecture principles and standards across on-prem, cloud, SaaS, and internally developed platforms (including the company’s ERP)
- Drive consistent control design rather than one-off solutions
- Ensure security is embedded early in technology and application decisions
- Privacy Leadership (Chief Privacy Officer Functions)
- In collaboration with the legal department, manage and advance the company’s data privacy program through its next level of maturity
- Serve as the organization's Data Protection Officer
- Ensure proper data governance, classification, retention, and protection practices
- Maintain a data inventory and data mapping of customer, vendor, employee, and logistics data flows
- Lead privacy impact assessments (PIAs/DPIAs) and embed privacy-by-design into systems and processes
- Manage data subject rights processes (access, deletion, correction requests)
- Oversee privacy practices related to employee data, including recruiting, payroll, benefits, and performance management
- Ensure compliance with applicable employment-related privacy obligations
- Provide guidance on monitoring technologies and workplace data, use
- Monitor evolving privacy regulations and assess impact on business operations
- Risk Management and Incident Response
- Lead security operations including threat detection, vulnerability management, endpoint security, and incident response
- Serve as incident lead during security events
- Own the incident response program and oversee breach notification processes in coordination with legal and communications
- Build repeatable, well-understood response processes rather than ad hoc execution
- Conduct post-incident reviews and implement continuous improvements
- Own Cyber Insurance Program
- Provide regular reporting to executive leadership on cyber risk posture, incidents, and remediation efforts
- AI Security and Emerging Technology Governance
- Partner with technology, legal, data, and business leaders to define a practical AI security and risk management approach
- Establish guardrails for the secure use of AI capabilities, including internally developed solutions and third-party AI features
- Identify and manage risks related to data exposure, model misuse, access control, and integrity
- Define policies and controls to enable responsible AI adoption to enable the business to deliver best in class solutions for our customers
- Evolve AI security practices as usage matures, focusing on sustainability rather than one-time controls
- Compliance and Audit Enablement
- Partner with IT, Legal, Compliance, and Finance to support PCI, SOX, and future assurance activities as well as regulatory inquiries and investigations
- Design controls that are operationally maintainable, not audit-only
- Promote calm, repeatable audit readiness rather than reactive compliance exercises
- Own and enforce maintenance and testing of business continuity and disaster recovery plans
- Team Leadership and Capability Building
- Lead and develop the internal security team across engineering, privacy, and compliance functions
- Set clear expectations, priorities, and development paths
- Make thoughtful, defensible cases for team growth or external augmentation when warranted
- Governance & Cross-Functional Leadership
- Establish strong security and privacy governance frameworks
- Collaborate with product, engineering, and business teams to enable secure and privacy-conscious innovation
- Lead security awareness and privacy training programs and policies across the organization
- Manage third-party/vendor risk, including security and privacy assessments
- Stakeholder Engagement
- Serve as the primary security partner to IT leadership and senior engineering leaders
- Communicate security risks and tradeoffs in clear business terms
- Build trust and alignment rather than relying on escalation or authority alone
Compensation & Schedule
Pay Range: $210,000.00 - $220,000.00 with bonus potential
Monday - Friday, Exempt, Full-Time Hybrid schedule (220, Remington Blvd, Bolingbrook, IL)