Director of Enterprise Cybersecurity
Listed on 2026-05-30
-
IT/Tech
Cybersecurity, IT Project Manager
Job Purpose
The Director of Enterprise Cybersecurity is responsible for the strategy, governance, and risk management of Sloan's cybersecurity program. The role sets the multi-year security roadmap, defines control frameworks, and establishes the governance structures that guide how cybersecurity risk is identified, measured, and treated across the enterprise. Reporting to the Chief Information Officer, the Director serves as the primary representative of the cybersecurity program to executive leadership and the broader organization, translating technical risk into business terms, delivering regular reporting on program maturity and risk posture, and informing executive decision‑making on security investments, incidents, and strategic direction.
The Director leads a team consisting of the Manager of Enterprise Cybersecurity, a Security Analyst, and oversight of Sloan's Managed Security Service Provider (MSSP). The manager owns day‑to‑day operations while the Director retains accountability for strategy, governance, compliance posture, and budget. The role protects Sloan's IT and OT environments across a global manufacturing footprint, balancing risk reduction with operational uptime, evaluating emerging threats, and building the security program required to support Sloan’s growth and technology modernization agenda.
- Develop and maintain a multi‑year enterprise cybersecurity strategy and roadmap aligned to business objectives, threat landscape, and Sloan's technology direction. Translate strategy into funded, sequenced programs with measurable outcomes.
- Establish and maintain a formal cybersecurity KPI and metrics program. Report program performance, risk posture, and maturity to the CIO and the Enterprise Risk Management Committee on a regular cadence.
- Own the enterprise cybersecurity risk management program. Define risk appetite with executive leadership, maintain the enterprise risk register, and drive risk treatment decisions. Report risk posture and program maturity to the CIO and executive leadership on a regular cadence.
- Represent cybersecurity on the Sloan Enterprise Risk Management (ERM) Committee. Establish and lead other internal IT cybersecurity committees at the Director's discretion.
- Lead compliance programs for applicable frameworks and regulations including NIST CSF, CIS Controls, PCI‑DSS, and data privacy requirements across global jurisdictions. Own audit readiness, evidence management, and regulator or customer response.
- Own the cybersecurity budget including capital and operating plans. Lead vendor selection, contract negotiation, and performance management for security technology partners and the MSSP. Optimize spend against risk reduction and control coverage. Maintain governance and oversight of the MSSP relationship.
- Extend the security program to cover manufacturing operational technology (OT) and industrial control systems (ICS) at Sloan production sites. Partner with engineering and operations to apply appropriate controls for converged IT and OT environments without disrupting production.
- Establish and govern the enterprise incident response and cyber resilience program. Lead executive response during material incidents, conduct tabletop exercises, and provide security input and consulting on enterprise business continuity and disaster recovery planning owned by other IT functions.
- Set architectural standards for identity, network segmentation, cloud, endpoint, email, and data protection. Govern security configuration baselines, patching cadence, and exception management. Review major IT and business technology initiatives for security alignment.
- Own the enterprise data protection program including data loss prevention, classification, encryption, and retention controls. Set standards.
- Serve as an active stakeholder in enterprise AI and machine learning governance from a security perspective. Offer guidance and consult on acceptable use policies for AI tools, and lead security review of enterprise AI initiatives.
- Own the cybersecurity testing program including penetration testing and red team engagements. Use results to drive remediation priorities and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).