Director of Enterprise Security
Graebel Companies, Inc. · United States · 3 wk ago
RemoteRemoteInformation Technology$140k–$195k/yrFull-time
About the role
This role can be based remotely in the United States. We help global brands place their exceptional people anywhere in the world through People-first Mobility—grounded in truth, love, and integrity. The Director of Enterprise Security leads the organization’s information security function, owning two core areas:
- Directing the operations of the organization’s security solutions through leadership of the Information Security team, including hiring, development, and performance management.
- Driving the enterprise security strategy through policy, architecture, and training programs, translating it into enterprise-wide priorities, standards, and budget.
The Director partners with leaders across the organization to shape the corporate security vision and build engagement in achieving higher levels of enterprise security.
Responsibilities
- Lead execution of the organization’s security strategy, including security architecture design, security awareness training, security documents (policies, standards, baselines, guidelines, and procedures), Third Party Risk Program, and Disaster Recovery Plan.
- Lead the Information Security team, including hiring, coaching, performance management, and succession planning for security analysts and staff.
- Support development of a multi-year cybersecurity strategy and maturity roadmap aligned with business growth objectives, technology modernization initiatives, and emerging threats.
- Maintain up-to-date knowledge of the Information Security industry, including new or revised security solutions, improved processes, and emerging threats.
- Build the business case for security investments; select and acquire additional security solutions or enhancements to improve overall enterprise security.
- Oversee the deployment, integration, and initial configuration of all new security solutions and enhancements in accordance with best practices and enterprise security documents.
- Ensure the confidentiality, integrity, and availability of enterprise data and enforce security policies; report on the organization’s security and risk posture to senior leadership.
- Drive the organization’s AI governance and security program, including policies and controls for secure and responsible AI use, oversight of AI-related risk, and partnership with legal, privacy, and business stakeholders.
- Direct investigations into problematic activity and own communication with management; design and execute vulnerability assessments, penetration tests, and security audits.
- Serve as the executive sponsor for the security awareness training program to ensure compliance with enterprise security policies and foster cooperation across business groups.
- Own third-party relationships (e.g., MSSPs), including contract negotiation and strategic vendor management.
- Represent enterprise security with business unit leaders, shaping the corporate security vision and securing engagement in achieving security goals and risk mitigation plans.
- Perform any other related duties as required or assigned.
Requirements
- Four-year college degree preferred, or equivalent experience in information security, computer science, or business administration; a degree is not required with strong, demonstrated relevant experience.
- 7–10 years of related experience and/or training, including at least 3 years leading or managing a security team.
- Extensive experience in enterprise security architecture design and enterprise security document creation.
- Proven experience directly leading and managing a security team, including hiring, coaching, and performance management.
- Strong knowledge of the Microsoft security stack (e.g., Microsoft Entra ID, Defender, Sentinel, Purview) and Windows/enterprise network environments.
- Hands-on cloud security experience across AWS and Azure, including securing cloud-native applications and infrastructure (e.g., containers, serverless, IAM, and cloud workload protection).
- Experience developing AI governance and security programs, including policies for secure and responsible AI use and management of AI-related risk.
- Experience designing and delivering employee security awareness training.
- Experience developing Business Continuity Plans and Disaster Recovery Plans.
- Experience leading incident response and management for security events, including detection, containment, root-cause analysis, and post-incident reporting.
Preferred Qualifications
- GIAC Security Essentials Certification
- GIAC Security Leadership Certification
- ISACA Certified Information Security Manager
- (ISC)² SCCP
- (ISC)² CISSP
- (ISC)² ISSAP
Skills
- Advanced: Database
- Basic: Alphanumeric Data Entry
- Presentation/PowerPoint
- Programming Languages
- Spreadsheet
- Word Processing/Typing
Pay
Salary bands are transparent and dependent on market/geographic location, ranging from $140,000 to $195,000 USD.
Benefits
- 401(k) plan
- Comprehensive health insurance (medical, dental, and vision)
- Employee Assistance Program
- Paid time off that grows with years of service
- Paid holidays
- Volunteer paid time off
- Life insurance and disability coverage