×
Register Here to Apply for Jobs or Post Jobs. X

Senior Director, Identity, Cybersecurity Governance & Risk

Job in Linthicum, Anne Arundel County, Maryland, USA
Listing for: Sunbelt Beverage Company, LLC
Full Time position
Listed on 2026-09-07
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Project Manager
Salary/Wage Range or Industry Benchmark: 180000 - 200000 USD Yearly USD 180000.00 200000.00 YEAR
Job Description & How to Apply Below

Time Type:
Full time Remote Type:
Job Family Group:
Information Technology

Job Description Summary

The Senior Director Identity, Cybersecurity Governance & Risk is a senior cybersecurity leader responsible for enterprise Identity and Access Management (IAM), cybersecurity governance, cyber risk management, third-party risk management, compliance, and security performance measurement. This role owns strategy, implementation, operations, and continuous improvement of IAM capabilities while establishing the governance, policies, controls, risk processes, and metrics required to manage cybersecurity risk effectively across the enterprise.

The position partners closely with the IT Vendor Management Function, Enterprise Architecture, Audit, Legal, Compliance, Human Resources, Operations, IT functions, and business leadership. The successful candidate will combine strategic leadership, security program management, technical credibility, operational discipline, and the ability to communicate cybersecurity risk in clear business terms.

Job Responsibilities Identity and Access Management (IAM)
  • Define and execute a multi-year IAM strategy, roadmap, architecture, operating model, and governance framework that aligns with business priorities, improved operational efficiencies, and technology transformation initiatives.
  • Oversee implementation and ongoing operations of IAM capabilities including IGA, IVIP, SSO, MFA, PAM, access provisioning, recertification, and identity lifecycle management.
  • Establish enterprise standards for authentication, authorization, least privilege, role-based access, privileged access, and joiner/mover/leaver processes.
  • Drive automation and modernization of access administration to improve security, user experience, and operational efficiency.
  • Oversee IAM imitative performance, service levels, application onboarding, policy exceptions, and remediation of excessive, dormant, orphaned, or inappropriate access.
  • Manage IAM technology vendors, implementation partners, and managed service providers.
Cybersecurity Governance, Risk Management & Executive Reporting
  • Establish and maintain the enterprise cybersecurity governance and risk management framework.
  • Develop and maintain cybersecurity policies, standards, control requirements, exception processes, and accountability models.
  • Partner with Enterprise Risk Management and executive leadership to align cybersecurity risk with enterprise risk appetite and tolerance.
  • Maintain the cybersecurity risk register and ensure risks have clear owners, supported remediation plans, and appropriate executive visibility.
  • Lead cybersecurity risk assessments across applications, infrastructure, cloud services, business processes, and major technology initiatives.
  • Translate technical risk into business impact, including financial, operational, regulatory, reputational, and business partner considerations.
  • Establish processes for risk treatment, residual risk assessment, formal risk acceptance, and escalation.
  • Establish a cybersecurity measurement framework focused on risk reduction, control effectiveness, operational performance, and program maturity.
  • Define KPIs, KRIs, service metrics, thresholds, and escalation criteria.
  • Develop executive dashboards and Board reporting on cybersecurity risks, trends, program performance, and priorities.
  • Use trend analysis and leading indicators to identify deteriorating performance or emerging risks.
  • Benchmark cybersecurity maturity and performance against industry standards and peer organizations.
Third-Party Cybersecurity Risk Management
  • Lead the cybersecurity component of the organization’s third-party risk management program.
  • Establish risk-based due diligence and assessment requirements based on vendor criticality, platform tiering, data classifications, connectivity, and business impact.
  • Oversee cybersecurity reviews during vendor selection, contracting, onboarding, periodic reassessment, renewal, and termination.
  • Partner with IT Vendor Management and Legal to establish appropriate cybersecurity contractual requirements.
  • Ensure significant vendor risks have documented remediation plans, compensating controls, or formally approved risk…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary