Jobs · Information Technology · Arizona

Director of Information Security & Compliance

DBM Global Inc. · Phoenix, AZ · 1 wk ago
Information TechnologyFull-time

About the Role

The Director of Information Security & Compliance is responsible for establishing and maintaining the information security program to ensure that information assets and associated technology, applications, systems, infrastructure, and processes are adequately protected. This position identifies, evaluates, and reports on legal and regulatory, IT, and cybersecurity risk to information assets while supporting and advancing business objectives. The role also maintains IT General Controls for Sarbanes Oxley (SOX) compliance and collaborates across the business to reduce risk and enhance the effectiveness of the information security program.

Responsibilities

  • Facilitate an information security governance structure through the implementation of a hierarchical governance program, including the formation of an information security steering committee or advisory board.
  • Provide regular reporting on the current status of the information security program to enterprise risk teams and senior business leaders as part of a strategic enterprise risk management program.
  • Work with vendors to ensure information security requirements are included in contracts by liaising with business leaders throughout the organization.
  • Create and manage a targeted information security awareness training program for all employees, contractors, and approved system users, and establish metrics to measure its effectiveness.
  • Understand and interact with related disciplines through committees to ensure consistent application of policies and standards across all technology projects, systems, and services, including privacy, risk management, compliance, and business continuity management.
  • Provide clear risk-mitigating directives for projects with IT components, including the mandatory application of controls.
  • Work with internal and external audit firms to ensure compliance with Sarbanes Oxley and other requirements, ensuring IT General Controls are effective and operating successfully.

Additional duties and responsibilities may be assigned as needed.

Qualifications

  • Core Competencies:
    • Informing: Provides timely and necessary information to team members to support decision-making and job performance.
    • Comfort Around Higher Management: Effectively engages with senior managers, presenting confidently and aligning approaches to their needs.
    • Integrity and Trust: Demonstrates honesty, keeps confidences, and presents truth in a constructive manner.
    • Conflict Management: Addresses conflicts proactively, facilitating equitable resolutions and cooperation.
    • Problem Solving: Uses rigorous logic to solve complex problems, identifying hidden issues and analyzing thoroughly.
    • Perspective: Considers broad implications of issues, anticipates future scenarios, and thinks globally.
    • Functional/Technical Skills: Possesses deep functional and technical expertise to perform the role at a high level.
    • Planning: Accurately scopes tasks and projects, sets objectives, and develops actionable plans and schedules.
    • Priority Setting: Focuses on high-impact tasks, eliminating distractions and roadblocks to achieve goals.
    • Standing Alone: Takes ownership of responsibilities, champions ideas, and works effectively in challenging situations.
  • Work Experience: 5-10 years in an information security or cybersecurity role.
  • Education/Training: Bachelor’s degree in Computer Science or related field, or equivalent experience.
  • Certifications: Current CISSP certification required; candidates without it must obtain it.

Skills

  • Proficiency in MS Windows 7/10, MS Word, MS Excel, MS PowerPoint, and MS Outlook.

Work Environment

Work is generally performed in a climate-controlled office environment. The role involves:

  • Constant walking, sitting, and standing for 8-10 hours per day.
  • Frequent use of hands and fingers for keyboard and computer work.
  • Occasional lifting and carrying of computer equipment.

Reasonable accommodations may be made for qualified individuals with disabilities under the Americans with Disabilities Act.

Similar jobs

Director of Information Security

IDEA Public SchoolsTexas, United States· 1 mo ago
RemoteInformation Technology$108k–$129k/yrapply on careers.ideapublicschools.org