Jobs · Sales · Florida

VP, Cybersecurity & Information Risk

Jazwares, LLC · Plantation, FL · 4 days ago
On-siteSalesFull-time

About the role

In this executive role, you will report directly to the EVP of Global IT with a dotted line to the Audit Committee. You will establish and execute the enterprise information security strategy, protect critical global infrastructure, and ensure full compliance as a wholly-owned subsidiary of a public reporting entity. You will hold primary accountability for meeting SEC cybersecurity disclosure rules, SOX ITGC requirements, and global data privacy regulations.

Responsibilities

  • Develop and maintain the enterprise information security strategy and roadmap, aligned to the NIST Cybersecurity Framework (CSF 2.0), CIS, and the company’s risk appetite as defined by the Board.
  • Chair the Information Security Steering Committee, convening business unit leaders, Legal, Internal Audit, and Finance to govern cross-functional security decisions.
  • Conduct Risk assessment and maintain the enterprise security risk register; present risk posture and material risks to the Audit Committee and Risk Committee on a quarterly basis.
  • Establish and enforce the Information Security Policy framework, including acceptable use, data classification, third-party risk, and incident response policies.
  • Develop and manage an incident response plan, tabletops to swiftly and effectively respond to and recover from security incidents, minimizing the impact on the organization.
  • Establish disaster recovery and business continuity plans to ensure the availability and integrity of critical systems and data.
  • Own the cybersecurity budget, including capital planning, managed services contracts, and tooling rationalization.
  • Establish and own the enterprise AI security and acceptable use framework, covering employee GenAI tools, embedded AI in SaaS, and any custom AI/ML deployments.
  • Own the Incident Response Plan; serve as executive decision-maker for material security incidents, including coordination of external forensics, legal counsel, law enforcement, and public disclosure.
  • Lead tabletop exercises and red team/purple team programs; ensure findings drive measurable improvements to detection and response capability.
  • Manage the cyber threat intelligence program, ensuring actionable intelligence informs both operational response and strategic risk discussions.
  • Own the enterprise GRC program, including risk assessments, control mapping, exception management, and audit liaison.
  • Lead the annual SOX ITGC program in coordination with Internal Audit, ensuring timely completion, appropriate evidence, and effective remediation of control deficiencies.
  • Manage the TPRM program, covering vendors, 3PLs, carriers, and technology providers across the global supply chain.
  • Manage internal compliance activities such as Phishing Campaigns, Security Awareness Program (including AI-specific user education) and User Access reviews.
  • Own the IAM program, including Zero Trust architecture, privileged access management (PAM), identity governance, and multi-factor authentication across enterprise and OT/warehouse environments.
  • Maintain access controls meeting SOX segregation of duties requirements across ERP, WMS, and financial systems.
  • Oversee identity programs for complex workforce segments including warehouse floor workers, mobile/remote employees, and third-party logistics partners.
  • Own the enterprise vulnerability management program, including CVE tracking, risk-based patching SLAs, and penetration testing program.
  • Partner with the VP, Infrastructure and Technology Services to set the strategic direction and ensure secure architecture design and enhancement for networks and systems.
  • Oversee the execution of endpoint, network, and cloud security initiatives.

Requirements

15+ years of progressive information security experience, with a minimum of 5 years in a senior leadership role (CISO, Deputy CISO, or VP-level) at a company of comparable complexity. Demonstrated experience operating in or supporting a publicly reporting company, including direct engagement with SEC disclosure obligations, SOX ITGC programs, and external audit processes. Deep expertise across most of the core security domains: security operations and incident response, security engineering, GRC, IAM, vulnerability management, and data protection. Experience presenting to and advising Boards of Directors, Audit Committees, and C-suite executives on cybersecurity risk. Experience in incident response and crisis management, including proven track record of managing material security incidents requiring executive decision-making under pressure and coordination of external legal counsel and forensics. Experience operating in complex, multi-geography environments with IT and supply chain technology footprints. Proven success leading security programs in lean, accountable operating environments, delivering enterprise-grade outcomes through a combination of focused internal team, managed service partnerships, automation, and disciplined prioritization. Proven ability to articulate complex security topics to both technical and non-technical stakeholders. Bachelor’s degree in Computer Science, Information Security, or related field; advanced degree preferred. Industry certifications: CISSP. Familiarity with emerging AI security frameworks (NIST AI RMF, ISO 42001).

Qualifications

Extensive knowledge of legal issues related to organization liability and cybersecurity insurance trends. Experience in establishing cybersecurity and risk metrics for reporting. Strong Emotional Intelligence with demonstrated sustained leadership in a large organization involving multiple stakeholders. Demonstrated management skills regarding budget development and administration, policy development and implementation, personnel administration, and staff training and development. Demonstrated ability to work with diverse people, as well as effective oral and written communication skills.

Skills

  • Strong leadership and strategic planning skills.
  • Excellent communication and interpersonal skills.
  • Ability to work collaboratively with cross-functional teams.
  • Experience with security operations, incident response, and cybersecurity frameworks.
  • Knowledge of regulatory compliance requirements and risk management.
  • Experience with data protection and privacy regulations.
  • Ability to manage budgets and resources effectively.
  • Experience with AI security frameworks.
  • Experience with enterprise applications, data, and digital.
  • Experience with network security and secure architecture design.
  • Experience with vulnerability management and penetration testing.
  • Experience with IAM and identity governance.
  • Experience with SOX ITGC programs.
  • Experience with TPRM and supply chain security.
  • Experience with security awareness and training programs.
  • Experience with cybersecurity metrics and reporting.
  • Experience with cybersecurity insurance and risk management.

Benefits

Base salary may vary based on experience, role tenure, performance, industry, and location. Eligibility for the annual performance incentive may apply. Jazwares offers a comprehensive benefits package including basic medical insurance, employee basic life and AD&D insurance, a 401(K) retirement program with Jazwares matching, short and long-term disability, and tuition reimbursement. The work environment provides a flexible work schedule that includes a Monday through Thursday on-site, with an optional WFH on Fridays, up to 20 workdays fully remote each year, and Time Off for vacation and sick leave. Through Jazwares Cares, employees have the opportunity to volunteer for up to 16 hours a year on community service projects. Jazwares is an equal opportunity employer and does not discriminate in employment on the basis of race, color, sex, religion, national or ethnic origin, citizenship status, ancestry, disability, age, military status, marital status, sexual orientation, or any other characteristic protected by law.

Similar jobs