VP, Cybersecurity & Information Risk
Listed on 2026-07-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection
As the Vice President of Cybersecurity & Information Risk (CISO), you will report directly to the EVP of Global IT with a dotted line to the Audit Committee. In this executive role, you are responsible for establishing and executing the enterprise information security strategy, protecting critical global infrastructure, and ensuring full compliance as a wholly‑owned subsidiary of a public reporting entity.
You will hold primary accountability for meeting SEC cybersecurity disclosure rules, SOX ITGC requirements, and global data privacy regulations. Additionally, you will lead the security governance of enterprise AI adoption—a rapidly evolving domain with material implications for data protection, regulatory compliance, and operational risk.
- Develop and maintain the enterprise information security strategy and roadmap, aligned to the NIST Cybersecurity Framework (CSF 2.0), CIS (and other industry relevant frameworks like ISO 27001, etc) and the company’s risk appetite as defined by the Board. Continuously evaluate and update the strategy to address emerging threats and technologies.
- Chair the Information Security Steering Committee, convening business unit leaders, Legal, Internal Audit, and Finance to govern cross‑functional security decisions
- Conduct risk assessment and maintain the enterprise security risk register; present risk posture and material risks to the Audit Committee and Risk Committee on a quarterly basis
- Establish and enforce the Information Security Policy framework, including acceptable use, data classification, third‑party risk, and incident response policies
- Develop and manage an incident response plan, tabletops to swiftly and effectively respond to and recover from security incidents, minimizing the impact on the organization.
- Establish disaster recovery and business continuity plans to ensure the availability and integrity of critical systems and data.
- Own the cybersecurity budget, including capital planning, managed services contracts, and tooling rationalization
- Establish and own the enterprise AI security and acceptable use framework, covering employee GenAI tools, embedded AI in SaaS, and any custom AI/ML deployments
- Oversee the 24/7 Security Operations Center (SOC), including hybrid internal/managed service delivery model, SIEM, EDR, and threat intelligence platforms
- Own and exercise the Incident Response Plan; serve as executive decision‑maker for material security incidents, including coordination of external forensics, legal counsel, law enforcement, and public disclosure
- Lead tabletop exercises and red team/purple team programs; ensure findings drive measurable improvements to detection and response capability
- Manage cyber threat intelligence program, ensuring actionable intelligence informs both operational response and strategic risk discussions
- Own the enterprise GRC program, including risk assessments, control mapping, exception management, and audit liaison
- Lead the annual SOX ITGC program in coordination with Internal Audit, ensuring timely completion, appropriate evidence, and effective remediation of control deficiencies
- Maintain and mature the Third‑Party Risk Management (TPRM) program, covering vendors, 3PLs, carriers, and technology providers across the global supply chain
- Manage internal compliance activities such as Phishing Campaigns, Security Awareness Program (including AI‑specific user education) and User Access reviews
- Set strategic direction for the IAM program, including Zero Trust architecture, privileged access management (PAM), identity governance, and multi‑factor authentication across enterprise and OT/warehouse environments
- Ensure access controls meet SOX segregation of duties requirements across ERP, WMS, and financial systems
- Oversee identity programs for complex workforce segments including warehouse floor workers, mobile/remote employees, and third‑party logistics partners
- Own the enterprise vulnerability management program, including CVE tracking, risk‑based patching SLAs, and penetration testing program
- Maintain a dotted‑line relationship with the SVP of Enterprise Applications, Data & Digital to embed security into the software…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).