Director or Cybersecurity
Listed on 2026-08-28
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations
Director of Cybersecurity
The Director of Cybersecurity executes the security program strategy defined by the VP of Digital Innovation & Cybersecurity, and owns the day-to-day health and continuous evolution of the company's security environment — from risk identification through mitigation. This role is the operating arm of the security strategy: it maintains the risk register, owns threat modeling and security architecture, runs the security review cadence for new initiatives, leads incident response, and drives the program's evolution as the threat environment changes and the cost to exploit decreases.
The Director partners with the Senior Director of IT Operations on the operational execution of security controls (SIEM, vulnerability management, IAM, endpoint hygiene), with the Director of Solutions Delivery on secure development and AI safety, and with the Director of Digital Innovation on building security into solution design from the start. The ideal candidate brings strong security depth, current familiarity with the AI-era threat landscape, and the program leadership skills to evolve the security posture continuously rather than annually.
Accountabilities
Risk Management & Threat Modeling
- Maintain the enterprise security risk register — identification, assessment, and tracking of mitigation — across infrastructure, applications, data, manufacturing operations, and third-party dependencies.
- Own the threat modeling practice for the company, ensuring new initiatives, new platforms, and significant architecture changes go through appropriate threat assessment before release.
- Continuously evolve the threat model to account for changes in adversary capabilities, the decreasing cost to exploit, and the AI-era threat landscape.
Security Architecture & Engineering
- Own the security architecture for the enterprise — identity and access, network segmentation, data protection, application security, and the security layer for AI and agentic systems.
- Partner with the Director of Solutions Delivery on secure development practices, with particular attention to the guardrails and circuit breakers required for agentic systems.
- Maintain security standards, reference architectures, and design patterns that the rest of the organization can use without requiring direct involvement from the security team for routine decisions.
Incident Response & Continuous Posture
- Lead enterprise incident response — detection through resolution and post-incident review — in tight partnership with the Senior Director of IT Operations on operational execution.
- Drive the shift from an annual security posture to a continuous one: continuous control validation, continuous risk assessment, and continuous improvement of the program's response capability.
- Maintain the incident response plan, run regular tabletop exercises, and ensure both the security team and broader leadership are practiced and ready.
Governance, Compliance, and Third-Party Risk
- Maintain alignment with the NIST Cybersecurity Framework and ensure compliance with applicable regulatory, contractual, and customer security requirements.
- Own third-party risk management — security review of vendors, contractual security commitments, and ongoing monitoring of critical third-party dependencies.
- Maintain the security policy framework and ensure policies are practical, current, and actually followed across the organization.
Security Operations Partnership
- Partner with the Senior Director of IT Operations and the Security Operations team on the day-to-day operational execution of security controls — SIEM, vulnerability management, IAM, endpoint, and patch cadence.
- Own the definition of operational security objectives and the review of operational performance against them, while the execution of those controls lives within IT Operations.
Awareness, Culture, and Program Evolution
- Lead the security awareness program for the broader workforce, with particular attention to the AI-era phishing, social engineering, and data-handling risks that traditional training misses.
- Continuously evolve the security program itself — tooling, staffing, practices — to keep pace with a threat…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).