Director, Information Security
Listed on 2026-02-23
-
IT/Tech
Information Security, Cybersecurity, IT Consultant, IT Project Manager
MAIN JOB RESPONSIBILITIES / COMPETENCIES
As the Director - Information Security within STAAR Surgical’s Information Technology team, this individual plays a critical role working closely with the business and across the Information Technology organization defining, delivering and supporting information security programs, procedures, technologies and supporting roadmaps. In summary, this position provides: leadership within the Information Security team; manages information security related budgets; works across the enterprise to identify, evaluate and resolve diverse and highly complex information security concerns;
selects frameworks, methods and techniques for identifying and advocating effective security risks and solutions; and develops and administers information security programs, schedules and performance criteria.
This role will be responsible for managing a team of information security professionals, including providing leadership, direction, guidance and mentoring to team members. In addition, this role will also have project management responsibilities.
- Directs the efforts of others in the achievement of the strategic and operational objectives of the group.
- Responsible for managing STAAR Surgical’s Information Security function, including:
- Works across the business and IT, at all levels of management, to define, establish, communicate and achieve strategic, tactical and operational objectives for the information security function.
- Defines, implements and monitors security strategies, policies, standards, guidelines and procedures, including:
General IT Use Policies; BYOD policies; and IT general and technical controls and procedures in support SOX compliance. - Defines, implements and supports best‑fit solutions for STAAR Surgical’s Information Security strategy.
- Effectively manages delivery of new Security technology through proper SDLC policies and procedures.
- Manages the hiring, staffing and maintaining of a diverse and effective workforce.
- Responsible for career development, planning and performance discussions of team members.
- Influences individuals within and outside the IT department.
- Prepares and presents reports to all levels of leadership and staff.
- Establishes and maintains budgets, operational plans and performance requirements.
- Manages periodic user access reviews of in‑scope SOX systems.
- Works with engineering and development teams to define and refine information security and systems management policies and settings.
- Works with Procurement and Internal Audit to develop a robust third‑party security risk management program.
- Monitors and assesses vendor and 3rd party information security reports/lists.
- Evaluates new and emerging products, technologies and make recommendations to leadership concerning introduction of new technologies.
- Coordinates, administers, manages and monitors the use of access control systems security tools and intrusion detection systems to identify anomalous events and security infractions that exploit system vulnerabilities, including dispositioning and reporting of events to relevant regulatory bodies in accordance with established policies and procedures.
- Integrates information security controls into an environment to identify and mitigate risks.
- Provides analysis of potential risk to information security and recommends solutions.
- Creates and maintains information security documentation.
- Communicates information security procedures to users.
- Reviews and recommends changes to information security policies, including STAAR Surgical IT use policies, Data Sensitivity, Privacy and Personally Identifiable Information Security Policies and procedures.
- Stays apprised of current and upcoming cybersecurity and privacy regulations to understand how it impacts STAAR, including mapping these requirements to current data security projects and policies.
- Leads cross‑functional teams that perform information security reviews and audits and review designs for information security issues.
- Acts as a subject matter expert and local leader for information security direction, training and guidance for less experience information security engineers.
- Instructs, directs, mentors, assigns and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).