Director, Information Security Risk Management; CISO
Listed on 2026-07-23
-
IT/Tech
Information Security & Data Protection, Cybersecurity, IT Project Manager, IT Consultant
This is a "hybrid" role. The selected candidate will work in Arlington, VA (Tuesdays-Thursdays) on a weekly basis.
The Director of Information Security Risk Management serves as the functional lead for NACD's enterprise information security program, operating with the scope and accountability of a Chief Information Security Officer within the organization. Reporting to the CIO, the Director owns the execution and ongoing maturation of NACD's security governance, risk management, compliance, and operations functions — including full ownership of the information security budget.
NACD's information security program is in its early stages of development. Many foundational capabilities are newly established, and several critical programs have yet to be built. This is a builder role. The Director will assess the current state of the program, prioritize investments, and systematically stand up the people, processes, and technologies required to mature NACD's security posture. This requires someone equally comfortable designing programs from the ground up as they are operating and improving what already exists.
The Director identifies, evaluates, and reports on legal, regulatory, and cybersecurity risk to information assets while supporting NACD's business objectives — partnering with the CIO, Legal/Privacy, senior leadership, and business units to define acceptable risk levels and ensure systems are maintained in a secure, functional, and compliant state.
Supervisory ResponsibilitiesThis position carries direct people management accountability. The Director manages a team of full-time employees and/or contractors supporting the information security risk and compliance function. Responsibilities include recruiting, hiring, onboarding, performance management, professional development, and annual reviews. The Director also manages contractor relationships — including scope oversight, performance expectations, and vendor coordination — in partnership with the vendor management office.
Essential Duties And Responsibilities Establish Governance and Build Knowledge- Leads the information security governance structure, including formation of a steering committee or advisory board, development and approval of security policies, and regular reporting to senior leadership and the board of directors on program status and risk posture.
- Directs a targeted security awareness training program for all employees, contractors, and system users; establishes metrics to measure effectiveness and ensures consistent application of policies and standards across all technology projects and services.
- Provides risk‑mitigating directives for IT-related projects, embeds cyber judgment across decentralized decision‑making, and works with the vendor management office to ensure security requirements are reflected in contracts and third‑party engagements.
- Leads the information security function across NACD, defining the operating model and approach in consultation with stakeholders and aligned to the organization’s risk management strategy.
- Manages a team of employees and contractors, with full accountability for hiring, onboarding, performance management, professional development, and contractor scope and quality oversight.
- Owns the Information Security Risk Management budget end‑to‑end — including annual planning, forecasting, and in‑year management across staffing, tools, services, and new program investments — and develops business cases to justify security expenditures aligned to risk priorities.
- Partners with the CIO and finance leadership to ensure the budget reflects the resource requirements of a maturing program, monitors variances throughout the year, and recommends adjustments as program needs evolve.
- Develops and monitors a comprehensive information security program ensuring confidentiality, integrity, availability, privacy, and recoverability of NACD’s information assets; assesses program gaps and leads a prioritized, phased buildout of capabilities needed to reach target maturity.
- Facilitates risk assessment and risk…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).