Director- Cybersecurity Privacy and Risk
The Director, Cybersecurity and Privacy Risk will oversee the advancement of Information Security Governance and Risk functions, ensuring alignment with the organization's Information Security Policy. This role involves developing, maintaining, and enhancing policies, standards, processes, and procedures. A critical aspect of the position includes fostering collaboration, building relationships, and coordinating efforts across departments such as Privacy, IT, and the Office of General Counsel for the organization. This is a remote role but candidates must live in : NYC, Chicago, Washington DC, or Atlanta.
Key Responsibilities
- Oversee and coordinate Information Security Governance and Risk initiatives, ensuring prioritization of critical activities.
- Develop and formalize cyber risk controls within established frameworks (e.g., ISO standards, NIST controls) and integrate these controls into the Information Security Policy.
- Lead efforts to maintain and refine standards, policies, and controls to meet compliance requirements and support ongoing monitoring, reporting, and metrics.
- Act as a facilitator between governance and risk management processes, connecting information security activities with IT controls.
- Establish a repository of processes and procedures mapped to specific controls, adapting these controls to identified risks.
- Set objectives and implement strategies to enhance Information Security Governance and Risk services using effective delivery and management techniques.
Core Competencies
- Proven ability to address complex IT risk management challenges with innovative solutions.
- Expertise in developing and overseeing cybersecurity policies, processes, and procedures.
- Proficiency in utilizing tools and technology to deliver data analytics and insights on cyber threats, risks, and vulnerabilities.
- Strong document preparation skills using Microsoft Office to deliver concise and accurate project outputs.
- Demonstrated leadership in managing and guiding cross-functional teams and business functions.
- Exceptional communication skills, with a focus on fostering collaboration and building strong partnerships across teams.
Qualifications
- Extensive experience in a comparable leadership role preferably coming from a Law firm or Large consulting firm.
- A minimum of 15 years of experience in the Information Technology or Information Security field.
- At least 8 years of experience in a professional services or legal environment (preferred).
- A minimum of 10 years in supervisory roles.