Director, Cyber Security

Gogo Inc.

Broomfield (CO)

On-site

USD 180,000 - 225,000

Full time

13 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Medical, Dental & Vision
401k with employer match
PTO & Volunteer Time Off
Employee Stock Purchase Plan

Job summary

Gogo Inc. is seeking a Director of Cybersecurity to lead enterprise security operations, incident response, and governance, risk, and compliance programs.

You will guide a team of security professionals and translate strategic security objectives into operational initiatives protecting information assets and company reputation. The role reports to the security leadership team and collaborates with Legal, Privacy, IT, and executive stakeholders to mature the security program and ensure regulatory

Qualifications

  • 10+ years in cybersecurity, information security, or IT risk management including IR and GRC
  • 5+ years of people management experience
  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience
  • Demonstrated experience building or maturing incident response programs and leading responses to significant security events
  • Strong working knowledge of regulatory and compliance frameworks (NIST, ISO 27001, SOC 2, PCI DSS)

Responsibilities

  • Oversee incident response, SOC operations, and vulnerability management
  • Lead cross-functional incident coordination with Legal, Communications, IT, and leadership
  • Develop and maintain risk management framework and governance program
  • Manage third-party risk assessments and vendor security reviews
  • Present risk and program maturity to executives and the board

Skills

Incident response
GRC
Leadership
Regulatory compliance
Threat detection
IAM
EDR/XDR
Vendor risk
Communication
Security architecture

Education

Bachelor's degree in CS/InfoSec
Equivalent experience

Tools

SIEM
EDR/XDR
Vulnerability management
IAM
CSPM

Job description

Position Summary

The Director of Cybersecurity is responsible for leading the enterprise's cybersecurity operations, incident response, and governance, risk, and compliance (GRC) programs. This role serves as a key member of the security leadership team, translating strategic security objectives into operational programs that protect the organization's information assets, infrastructure, and reputation.

The Director will oversee a team of security professionals, manage the organization's security posture across threat detection, incident response, vulnerability management, and regulatory compliance, and serve as a trusted advisor to executive leadership on cyber risk.

Key Responsibilities
Incident Response & Security Operations
  • Own and continuously mature the enterprise incident response (IR) program, including playbooks, tabletop exercises, and post-incident reviews
  • Serve as incident commander for high-severity security incidents, coordinating cross-functional response efforts (Legal, Communications, IT, executive leadership)
  • Oversee Security Operations Center (SOC) functions, including threat detection, triage, containment, and remediation
  • Manage relationships with third-party incident response, digital forensics, and managed detection and response (MDR) providers
  • Lead root cause analysis and drive remediation of systemic vulnerabilities exposed by incidents
  • Establish and report on key incident metrics (MTTD, MTTR, containment time) to leadership and the board
Governance, Risk & Compliance (GRC)
  • Build and maintain the enterprise cybersecurity risk management framework, including risk registers, risk scoring methodologies, and treatment plans
  • Lead compliance efforts against applicable frameworks and regulations (e.g., NIST CSF/800-53, ISO 27001, SOC 2, PCI DSS, HIPAA, GDPR, FedRAMP, as applicable to the industry)
  • Manage internal and external audit engagements, including evidence collection, remediation tracking, and auditor liaison
  • Develop, implement, and maintain security policies, standards, and procedures
  • Oversee third-party/vendor risk management program, including security assessments and contract review
  • Partner with Legal and Privacy teams on regulatory obligations, breach notification requirements, and data protection matters
  • Present risk posture, compliance status, and program maturity to executive leadership, audit committee, and board of directors as needed
Technical Security Leadership
  • Direct vulnerability management program, including scanning, penetration testing coordination, and patch prioritization
  • Oversee identity and access management (IAM), endpoint detection and response (EDR), network security, and cloud security architecture in partnership with IT/engineering teams
  • Guide security architecture reviews for new systems, applications, and vendor integrations
  • Champion security awareness training and phishing simulation programs
  • Evaluate and recommend security tooling, technologies, and process improvements
  • Maintain threat intelligence awareness and translate emerging threats into actionable defensive measures
Leadership & Program Management
  • Build, mentor, and manage a high-performing cybersecurity team, including hiring, performance management, and professional development
  • Develop and manage departmental budget, including tooling, staffing, and professional services
  • Define and track KPIs/metrics demonstrating program effectiveness and maturity
  • Partner cross-functionally with IT, Legal, Privacy, Internal Audit, and business unit leaders to embed security into organizational processes
  • Support the CISO in developing and executing the enterprise security strategy and roadmap
Minimum Qualifications
  • 10+ years of progressive experience in cybersecurity, information security, or IT risk management, including demonstrated experience in incident response and GRC
  • 5+ years of people management or team leadership experience
  • Bachelor's degree in Computer Science, Information Security, or related field, or equivalent experience
  • Demonstrated experience building or maturing incident response programs and leading response to significant security events
  • Strong working knowledge of regulatory and compliance frameworks (NIST, ISO 27001, SOC 2, PCI DSS, and/or industry-specific regulations)
  • Hands-on familiarity with security technologies: SIEM, EDR/XDR, vulnerability management platforms, IAM, cloud security posture management (CSPM)
  • Experience managing third-party risk assessments and vendor security reviews
  • Excellent written and verbal communication skills, including experience presenting to executive leadership and boards
  • Proven ability to manage competing priorities in a fast-paced, evolving threat landscape
Preferred Qualifications
  • Master's degree (MBA, MS in Cybersecurity/Information Assurance, or related)
  • Relevant industry certifications: CISSP, CISM, CRISC, CISA, GCIH, GCFA, or equivalent
  • Experience in [industry-specific: aviation, financial services, healthcare, government contracting, etc.]
  • Experience with cloud security across AWS, Azure, and/or GCP
  • Familiarity with privacy regulations (GDPR, CCPA) and their intersection with security programs
  • Experience supporting SEC cybersecurity disclosure requirements (for public companies)
Core Competencies
  • Incident Command - Ability to lead cross-functional response under pressure with clear decision-making
  • Risk-Based Thinking - Translates technical risk into business impact for non-technical stakeholders
  • Regulatory Fluency - Deep understanding of applicable compliance obligations and audit processes
  • Technical Credibility - Sufficient depth to guide architecture and tooling decisions with engineering teams
  • Executive Communication - Comfortable briefing C-suite, audit committee, and board-level audiences
  • People Leadership - Builds, retains, and develops security talent
Physical/Work Requirements
  • Ability to participate in on-call rotation for incident response as needed
  • Occasional travel for audits, conferences, or cross-site coordination (typically <15%)
Equal Pay Disclosure(s)
  • Base Pay: 180,000.00 - 225,000.00 USD
  • Annual Target
  • Annual Short-Term Incentive: Bonus Plan at 20% (% of Annualized Base Pay)
  • Eligible for Incentive Stock Program: Yes
Benefits:
  • Gogo offers competitive benefits including medical, dental and vision coverage with plans that can fit each employee’s needs.
  • We offer an immediate vesting 401k plan, paid time off and volunteer time off.
  • Employees have the option to participate in an Employee Stock Purchase Plan.

Gogo is an Equal Opportunity and affirmative action employer, working in compliance with both federal and state laws.

We are committed to the concept of equal employment opportunity. Qualified candidates will be considered for employment regardless of race, color, religion, age, sex, national origin, marital status, medical condition, or disability.

The EEO is the law and is available here.

Gogo participates in E-Verify (English and Spanish).

Right to Work Statement (English and Spanish).

Here at Gogo, we lead with integrity first. We set the standard in our industry, leading with integrity; we strive to do what’s right, not just what is easy or expedient.

Customer excellence and mission – we build and deliver with the customers mission in mind, not just our roadmap.

On team – we collaborate across functions and business lines globally.

People power the network – technology moves fast, but people make the difference; we invest in their growth and treat them with respect.

Gogo is the only multi-orbit, multi-band in-flight connectivity provider offering connectivity technology purpose-built for business and military/government aviation.

Our industry-leading product portfolio offers best-in-class solutions for all aircraft types, from small to large and heavy jets and beyond.

The Gogo offering uniquely incorporates air-to-ground systems with high-speed satellite networks, to deliver consistent, global tip-to-tail connectivity through a sophisticated suite of software, hardware, and advanced infrastructure supported by a 24/7/365 in-person customer support team.

Gogo consistently strives to set new standards for reliability, security and innovation and is shaping the future of in-flight aviation to make it easier for every customer to stay connected beyond all expectations.

Connect with us at www.gogoair.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Cyber Security
Director, Cyber Security

Gogo • Denver (CO)

On-site
USD 180,000 - 225,000
Medical, dental, and vision coverage
401k with immediate vesting
Paid time off + volunteer time off
+1
Director, Cyber Security
Director, Cyber Security

Gogo • Broomfield (CO)

On-site
USD 180,000 - 225,000
Medical, dental, and vision insurance
401k with immediate vesting
Paid time off and volunteer time off
+1
DevSecOps Engineer
DevSecOps Engineer

Gogo Inc. • Broomfield (CO)

On-site
USD 116,000 - 145,000
Medical, dental and vision coverage
Immediate vesting 401k
Employee Stock Purchase Plan
Senior Product Support Engineer
Senior Product Support Engineer

Gogo Inc. • Broomfield (CO)

On-site
USD 96,000 - 120,000
Medical, dental, and vision coverage
401k with immediate vesting
Paid time off
+1
DevSecOps Engineer
DevSecOps Engineer

Gogo-Business-Aviation • Broomfield (CO)

On-site
USD 116,000 - 145,000
401k plan
Paid time off
Employee Stock Purchase Plan
Customer Program Manager
Customer Program Manager

Gogo Inc. • Broomfield (CO)

On-site
USD 92,000 - 115,000
Medical, dental and vision coverage
401k with immediate vesting
Paid time off and volunteer time off
+2
Customer Support Sales Specialist - Special Missions
Customer Support Sales Specialist - Special Missions

Gogo Inc. • Broomfield (CO)

On-site
USD 64,000 - 80,000
Medical, dental, vision coverage
401k with immediate vesting
PTO and volunteer time off
+1
Senior Buyer
Senior Buyer

Gogo Inc. • Broomfield (CO)

On-site
USD 76,000 - 95,000
Medical/Dental/Vision coverage
401k with immediate vesting
Paid time off & volunteer time off
+1
Material Handler IV
Material Handler IV

Gogo Inc. • Broomfield (CO)

On-site
USD 41,000 - 51,000
Medical, dental & vision
401k immediate vesting
Paid time off
+1
Salesforce Business Analyst
Salesforce Business Analyst

Gogo Inc. • Broomfield (CO)

On-site
USD 96,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+3