Director, Information Security & Compliance
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Project Manager
Director, Information Security & Compliance (Finance)
The Director of Information Security and Compliance provides strategic and operational leadership for Information Security and IT Risk Compliance efforts. The role manages and coordinates core aspects of security administration, identity and access management, audit response, and vulnerability assessments within the boundaries of acceptable risk. The director will conduct audits/assessments for IT Compliance, IT Security and Data Privacy. New implementations and operational maintenance of existing business-critical applications will be examined.
The role extends to any part of the business that has risk associated with information assets. The Director of Enterprise Security and Compliance reports directly to the Chief Information Officer.
- Bachelor's Degree in Business, Accounting, Information Technology, or other quantitative discipline.
- 10+ years of broad privacy and data protection, compliance or legal experience
- 5+ years of audit/assessment experience with PCI or SOX
- 3+ years leading a team of auditors or compliance analysts
- Sound understanding of security principles including logical access controls, change control, least privilege, segregation of duties, computer operations, network security, vulnerability management, and secure coding.
- Broad technical understanding of data management platforms (e.g., IBM DB2, Oracle, Microsoft SQL Server, etc.) and associated data security controls.
- Strong technology acumen and the ability to assess data privacy gaps in products/services design.
- Expert understanding of data classification, data protection, and data retention standards and practices.
- Familiarity with common enterprise and web application technologies.
- Experience with management and oversight of ERP security and role-based access management.
- Experience with project management best practices and collaborating with PMO.
- Experience with common information security management frameworks, such as International Organization for Standardization (ISO) 2700x, ITIL, CSC
20, COBIT and National Institute of Standards and Technology (NIST) frameworks. - Expert understanding of data protection regulations and standards (e.g., PCI, Safe Harbor, EU Data Protection Directive, etc.).
- Strong analytical and time management skills
- Ability to maintain a high degree of confidentiality
- Experience with Oracle's eBusiness Suite and Identity Management products
- Certified Information Security Auditor (CISA)
- PMI Project Management Professional (PMP)
- Payment Card Industry (PCI) Internal Security Assessor (ISA)
- Certified Information Privacy Professional (CIPP) or Certified Information Privacy Manager (CIPM)
- Industry Standard Security certifications including: SANS/GIAC GSNA, ISACA CISM, ISC2 CISSP, and ISC2 CSSLP.
- Serve as advisor to executive leadership on information security risks, IT compliance issues, and industry trends that will require prioritization, funding, and/or implementation support.
- Oversee all information security related technologies and third-party vendor relationships.
- Partner with Infrastructure, Operations and development teams to drive adoption and implementation of information security policies, procedures, standards, and incident handling processes.
- Serve as liaison with leadership, legal, and internal audit, to analyze new requirements, standards, and capabilities and to determine feasibility and timing of implementation of new programs and capabilities.
- Conduct assessments/audits to confirm operational effectiveness of IT general controls and identify risk.
- Manage development and assignment of access roles for all users across ERP platforms.
- Provide risk metrics to management regarding audit performance and findings.
- Assist control owners with root cause analysis and track risk management action plan progress.
- Guide efforts to create common control framework and uniform compliance reporting standard.
- Planning and reviewing annual review of compliance requirements influencing operations and initiatives in information security, privacy, and IT risk management.
- Performing examination of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).