Director of Information Security GRC

Posted on Dec 8, 2018 by Request Technology - Craig Johnson

Lake Forest, IL 60045
Information Technology
Immediate Start
Annual Salary
Full-Time

Prestigious Global Company is currently seeking a Director of Information Security.

Candidate will manage information risk to meet the business and compliance requirements of the organization, as well as protect sensitive information and maintain a strong corporate brand and reputation while ensuring Company meets all applicable regulatory and compliance demands at a Global level. Candidate will lead an Enterprise Security team that consists of one or more of the following: Security Architecture, Global Security Risk and Compliance, Security Engineering, Security Administration, Security Operations Center, IT Risk Management and Business Continuity.

Responsibilities:

Provide Team Members and Executive Leadership with research and guidance on risk assessments and appropriate mitigation strategies aligned with an Enterprise Risk Management Strategy.
Understands the enterprise strategy and influences the integration of security into business strategies and processes while ensuring that the results are documented and actionable, with clear ties to Enterprise Security frameworks
Align the security team scope, budget and staffing to the company level strategy, emerging technologies and changes in the threat landscape
Responsible for effectively executing specific ES Risk Management and Compliance activities, including management of Enterprise Systems Sarbanes-Oxley (SOX) controls with associated supporting processes, collaboration with process owners to ensure that risk mitigations are appropriate and to report on progress with respect to the designed plan, all in alignment with company Enterprise Risk Management (ERM) guidelines
Lead a functional Security team to manage information risk and availability to an acceptable level to meet the business and compliance requirements of the organization globally
Establish and manage the capability to identify, protect, detect, respond and recover from information incidents to minimize business impact. Analyzes and provides assessments of IT Security Incidents & trends and their impact on Companys Global business to Senior Management
Establish, monitor, evaluate and report key performance and key risk indicators (KPIs and KRIs) to provide leadership with accurate information regarding the effectiveness of the information risk & security strategy
Establishes and maintains relationships outside of Company to inform on strategy and best practices
Represents Company at security conferences and functions to understand and industry trends
Directs the assigned security functions of Enterprise Information Security as they relate to Security Architecture, Security Risk and Compliance, Security - Engineering, Security Administration, Security Operations, and IT Risk Management
Collaborates with all levels of management to raise security and IT risk awareness
Provides Information Security and IT Risk input to the EPS strategy and planning efforts
Communicates strategy with the security team and performs changes management as necessary
Works closely with external partners to ensure the security and integrity of Company data is not compromised and is available when needed
Ensures new development, major changes and improvements to applications and systems continue to provide necessary and appropriate security, IT risk and continuity, within all applicable environments. Manages the integration of new security technologies and services into the suite of applications and operating systems with minimal negative impact
Advises Contract and Legal Teams to ensure terms and conditions protect Company and comply with Company's risk profile
Build, develop and sustain a team structure that supports the progression of team members, builds a bench of resources and incorporates recruitment

Qualifications:

Minimum ten years of successful experience in an Information Security field
Current CISM and or CISSP certification preferred
Minimum five years of successful experience directly managing technical individual contributors, supervisors and managers
Balance of strong technical knowledge and strong managerial competencies
Ability to translate complex IT Security problems and issues into simple business terms & business impact
Experience in executing security programs in companies that have a Multi-Billion Dollar E-commerce Business, Brick & Mortar businesses, as well as External & Inside Sales
Demonstrated ability to motivate, mentor, coach and lead technical teams; must be able to work directly with individuals at all levels of the Company
Strong continuous improvement problem-solving and mentoring skills
Confident and effective negotiation skills
Strong verbal and written communication, facilitation, and interpersonal skills
Ability to manage vendor/supplier relationships, including contract negotiation, ongoing maintenance & support and problem-resolution
Ability to effectively manage annual budgets of $3M or higher and link team strategy to company performance

Reference: 600700168

Similar Jobs

Director of Information Security GRC

Lake Forest, IL

Request Technology

Director Information/GRC Security

Lake Forest, IL

Request Technology - Robyn Honquest

Director of IS/GRC

Lake Forest, IL

Request Technology - Kyle Honn

IAM Security Engineer

Lake Forest, IL

Request Technology - Kyle Honn