Senior Director, IT Security
Listed on 2026-07-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Purpose
Access to affordable, reliable transportation is essential to leading productive work and personal lives, caring well for oneself, one’s family, and the needs of others. Through advanced analytics and technology, we can more accurately predict credit risk and provide more people with an affordable auto financing option for their next vehicle. That’s what GLS has done for over 10 years, helping more than half a million families meet and improve their transportation needs.
PeopleJoin a culture of over 1,000 employees who Care Deeply and Think Boldly, driving innovation in an adaptive and positive culture that celebrates successes. We empower and reward individuals and teams who make direct, positive impacts to the business and each other, who take pride in their work and are ever-raising the bar.
GrowthRecognized by Inc 5000 as one of the fastest-growing private companies in America. Join GLS to grow with us!
Benefits- Competitive base pay and performance bonuses, dependent on role
- Medical, dental, vision, telemedicine, supplemental insurance benefits, long-term and short-term disability
- 401K with employer match and 100% immediate vesting
- Paid Time Off (PTO) and paid company holidays to help you balance work and personal life
- Paid Volunteer Time Off (VTO) Annually
- Tuition Reimbursement
- Business casual work environment
The Senior Director, IT Security is responsible for the strategic leadership, governance, risk management, compliance, and operational execution of the enterprise information security program. This position provides oversight of cybersecurity operations, security architecture, technology risk management, regulatory compliance, third-party risk management, incident response, business continuity, disaster recovery, and emerging technology governance, including artificial intelligence initiatives. The role serves as a trusted advisor to executive leadership, regulators, auditors, and business stakeholders to ensure the confidentiality, integrity, and availability of company information assets while enabling business growth, innovation, and regulatory compliance.
Howwill you drive value within the organization as a Senior Director, IT Security?
- Develop and maintain the enterprise cybersecurity strategy, operating model, control framework, and multi-year security roadmap aligned to business objectives.
- Establish and maintain enterprise security governance processes, standards, policies, risk assessments, control evaluations, and remediation programs.
- Provide cybersecurity governance reporting, risk metrics, annual program updates, and material cyber-risk reporting to executive leadership, board committees, regulators, auditors, and external stakeholders.
- Lead enterprise cybersecurity incident response, crisis management, investigations, post-incident remediation, and coordination of third-party security events.
- Oversee vulnerability management, threat detection, threat intelligence, security monitoring, and security operations capabilities.
- Direct implementation and management of security technologies including SIEM, EDR, DLP, IAM, PAM, cloud security, and related cybersecurity platforms.
- Serve as the primary security liaison for regulatory examinations, external audits, compliance assessments, and cybersecurity reviews, including evidence collection, artifact management, response coordination, and remediation tracking.
- Maintain compliance with applicable regulatory and industry frameworks including GLBA, NYDFS, FTC Safeguards Rule, PCI DSS, NIST CSF, CIS Controls, and other applicable requirements.
- Oversee third-party cybersecurity risk management, vendor security assessments, critical service-provider monitoring, and regulatory vendor-risk reporting.
- Establish governance, security, approval, monitoring, and risk management requirements for artificial intelligence, automation platforms, integrations, and emerging technologies.
- Partner with infrastructure, cloud, data, and application development teams to integrate security-by-design principles into architecture, Dev Sec Ops , Infrastructure as Code, and technology modernization…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).