Associate Director - Security Strategy & Analytics (Hybrid
Listed on 2026-08-08
-
IT/Tech
Information Security & Data Protection, Cybersecurity
Company Description
About Abb Vie
Abb Vie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about Abb Vie, please visit us Follow @abbvie onLinked
In,Facebook,Instagram,Xand You Tube .
The Associate Director, Information Security Strategy & Analytics is a senior people leader who partners with the ISRM leadership team and CISO todefine and document the function's strategic direction while leadingtheteam responsible forsecurityreporting and analytics. This role translates business priorities, risk insights, andhard security dataintoinsights that drivestrategic decisions,while owning the platforms and reporting capabilities that make those strategies measurable.
This role hasthreedefining requirements: seasoned security practitioner depth, the ability to communicate strategy and data clearly and credibly to executive audiences,anda proven trackrecordleading technical or analytical teams.
Responsibilities:
- Lead the metrics and reporting team, including hiring, performance management, talent development, and defining the team's portfolio, processes, and ways of working.
- Partner with security domain leaders to developimpactfulcross-functional reporting that gives leadership clear insight into security posture, operational health, and program value.
- Collaborate with ISRMleadership and portfolio management to define ISRM's strategic direction, including strategic priorities, target state, and multi-year roadmap, grounded in threat and risk insights, key metrics, business priorities, and delivery realities.
- Own ISRM's strategic narrativebydeveloping andmaintainingstrategy documentation, executive communications, and leadership presentations that clearly articulate direction and valueto stakeholders and partners.
- Lead the process of translating ISRM's strategic priorities into annual planning inputs, including LRP and capital planning submissions, ensuring investment rationale is clearly tied to execution roadmaps.
- Own and mature ISRM's data lake and reporting platforms, ensuring they deliver consistent,accurate, andtimelydata to support leadership decision-making.
- Own and mature thesemi-annualcyber business review process, delivering periodic cybersecurity performance reporting to business executives.
- Track ISRM's security maturity progress against frameworks such as NIST CSF, ensuring assessmentresultsare reflected in strategic priorities, roadmap inputs, and remediation planning.
Required:
- Bachelor's Degree and 9 years of experience;
ORMaster's Degree and 8 years of experience;
ORPhD and 4 years of experience. - Respective years of relevant technical security roles (e.g., security architecture, security engineering, cyber defense).
- 4+ years of leadership experience, including direct management ofseniorindividual contributors in technical or analytical functions.
- Demonstrated experience in information security strategy, security program leadership, or security transformation within a large, complex organization.
- Strong experience developing and/ormaintainingcomplex, cross-functional reporting targeted at executive leadership.
- Exceptional executive communication and stakeholder engagement skills, with demonstratedability to present and influence at the CISO and senior leadership level.
- Exceptional written communication skills, withdemonstratedexperience producing both executive-level security reporting and strategic documents (roadmaps, decision papers, governance narratives) that inform and influence senior leadership.
- Strong working knowledge of corporate security domains (e.g., security architecture, App Sec, security operations, GRC, TPRM) and the ability to build trust withtheleaders of those programs.
- Experience with security maturity frameworks such as NIST CSF, including translating findings into strategic priorities and remediation plans.
Preferred:
- 6+ years in…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).