Director Information Security

IHG Hotels & Resorts

Atlanta (GA)

Hybrid

USD 180,000 - 240,000

Full time

16 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

IHG Hotels & Resorts is seeking a Director of Information Security to establish enterprise security controls, policy lifecycle, and AI governance. You will drive regulatory compliance (PCI DSS, IT SOX, SOC 1/2, SWIFT) and oversee policy management while guiding a blended onshore/offshore team through a manager-led model.

You will set guardrails for AI adoption, lead governance forums, and report to executive leadership on control health and risk themes, aligning with NIST AI RMF and ISO

Qualifications

  • Deep expertise in regulatory compliance programs (PCI DSS, SOX/SOC, SWIFT) and control frameworks (NIST CSF/AI RMF, ISO 27001, COBIT).
  • Proven ownership of enterprise policy lifecycle and governance forums with executive audiences.
  • Experience establishing AI governance, including risk tiering and guardrails.
  • Executive communication to VPs/SVPs and SteerCo bodies.
  • Experience leading blended onshore/offshore delivery models.

Responsibilities

  • Own enterprise regulatory compliance strategy across PCI DSS, IT SOX, SOC 1/2/SWIFT, including audit planning and remediation.
  • Maintain a unified control framework and expand the controls library as scope grows.
  • Drive continuous control monitoring and evidence automation through ServiceNow GRC.
  • Define control ownership and formalize executive accountability across functions.
  • Lead AI governance with risk tiering, guardrails, and responsible use guidance.

Skills

Security governance
Regulatory compliance
Executive communication
Team leadership
Blended delivery model

Education

Bachelor's degree in Information Systems/Business

Tools

ServiceNow GRC/IRM
Veza
Axonius

Job description

IHG Hotels & Resorts is hiring a Director of Information Security. In this role you will set the standards for enterprise security controls and compliance, security policy management, and AI governance programs. You’ll establish direction for regulatory compliance (PCI DSS, IT SOX, SOC 1, SOC 2, SWIFT), owns the security policy lifecycle, and establishes responsible AI guardrails.

Drives executive accountability for control health with VPs and SVPs, represents the function in strategic governance forums (Financial Controls SteerCo, AI Responsible Use SteerCo, AI Working Group), and runs a blended onshore/offshore team through a manager-led model.

Your Day to Day
  • Own enterprise regulatory compliance strategy and delivery across PCI DSS, IT SOX, SOC 1, SOC 2, and SWIFT, including scoping, audit planning, execution, and remediation.
  • Maintain a unified control framework mapped across regulations and expand the controls library as scope grows. Own auditor and assessor relationships and hold delivery to agreed milestones and quality standards.
  • Drive continuous control monitoring and evidence automation through ServiceNow GRC and control indicators to reduce recurring findings and audit burden.
  • Define control ownership and formalize executive accountability with VPs and SVPs across P&T and corporate functions.
  • Mature the Compliance Partner model and control health dashboards, reporting posture and risk themes to executive leadership.
  • Equip control owners with training, remediation guidance, and clear expectations for sustained control performance.
  • Represent the function in the Financial Controls SteerCo, AI Responsible Use SteerCo, and VP Working Groups
  • Set enterprise AI risk tolerance, guardrails, and escalation criteria aligned to NIST AI RMF, ISO/IEC standards, and the EU AI Act.
  • Own the AI governance operating model covering intake, risk tiering, review, approval, exceptions, and ongoing monitoring. Steward AI governance forums and prepare SteerCo-level decisions, risk positions, and executive recommendations.
  • Embed responsible use guidance and role-based enablement so AI adoption scales safely across the enterprise.
  • Own the Enterprise Technology and Security policy lifecycle, including annual refresh, SteerCo review, publication and ongoing communications.
  • Keep policies current and operationally feasible through regulatory mapping, gap analysis, and business consultation.
  • Own the policy exception process and drive awareness through roadshows and role-based training.
  • Align policies, standards, and controls so requirements are measurable, testable, and auditable.
  • Lead a blended onshore and offshore team through a manager-led model, delegating delivery accountability to managers.
  • Act as an advisor to managers and team members to help meet established schedules and/or resolve technical or operational problems.
  • Own workforce planning, sourcing mix, budget input, vendor performance, and talent development across the function.
  • Partner across Security, Legal, Privacy, Internal Audit, Finance, and P&T to embed compliance and governance into the business.
What We Need From You
  • Bachelor's degree in Information Systems, Business, or related field, or equivalent experience.
  • 10+ years in security governance, risk, compliance, audit, or technology risk, including 5+ years leading teams and managing through managers.
  • Deep expertise in regulatory compliance programs (PCI DSS, SOX/SOC, SWIFT) and control frameworks (NIST CSF/AI RMF, ISO 27001, COBIT).
  • Proven ownership of enterprise policy lifecycle and governance forums with executive audiences.
  • Experience establishing AI or emerging-technology governance, including risk tiering, guardrails, and responsible use enablement.
  • Demonstrated executive communication: able to distill complex risk into crisp decisions for VPs, SVPs, and SteerCos.
  • Experience leading blended onshore/offshore and managed-service delivery models.
Preferred Qualifications
  • GRC tooling depth (ServiceNow GRC/IRM, Veza, Axonius).
  • Experience in a highly regulated, global, or consumer/hospitality enterprise.
  • Certifications such as CISA, CISM, CRISC, CISSP, or AI governance credentials (e.g., AIGP).
  • Executive influence without authority; strategic thinking with operational rigor; change leadership; talent development; evidence-minded and audit-ready follow-through.
Travel

- limited 10%

Location

Our hybrid work structure is an expectation of three (3) days a week in the ATLANTA office. This expectation may be adjusted with the changing needs of the business.

Important information
  • The salary range listed is the lowest to highest pay scale we, in good faith, believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee’s pay position within the pay range will be based on several factors, including relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, sales or revenue-based metrics, and business or organizational needs.
  • No amount of pay is considered to be wages or compensation until it is earned, vested, and determinable. The amount and availability of any bonus, commission, or other form of compensation allocable to a particular employee remain in the Company’s sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.
  • EEO Is The Law - click here for more information about Equal Opportunity Employer Minorities/Women/Protected Veterans/Disabled/Sexual Orientation/Gender Identity.
  • If you require reasonable accommodation during the application process, please click here.
  • IHG does not accept applications, inquiries, or unsolicited CVs/resumes from staffing or recruiting agencies. Please click here for our agency policy.
  • If you are a resident of or applying to a job opening in the State of Washington, please click here to read about applicable benefits.
  • For roles or applicants in San Francisco only: Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director Information Security
Director Information Security

InterContinental Hotels Group • Atlanta (GA)

Hybrid
USD 180,000 - 240,000
Hybrid work model
Director of Information Security & AI Governance
Director of Information Security & AI Governance

InterContinental Hotels Group • Atlanta (GA)

Hybrid
USD 180,000 - 240,000
Hybrid work model
Director of Information Security & AI Governance
Director of Information Security & AI Governance

IHG Hotels & Resorts • Atlanta (GA)

Hybrid
USD 180,000 - 240,000
Head of App and Web Technology
Head of App and Web Technology

IHG Hotels & Resorts • Atlanta (GA)

Hybrid
USD 180,000 - 260,000
Manager, Product Marketing and Adoption, Change Experience & Insights
Manager, Product Marketing and Adoption, Change Experience & Insights

IHG Hotels & Resorts • Atlanta (GA)

Hybrid
USD 106,000 - 133,000
Specialist, Franchise Licensing and Compliance
Specialist, Franchise Licensing and Compliance

IHG Hotels & Resorts • Atlanta (GA)

Hybrid
USD 70,000 - 100,000
Hybrid work model
Director, Information & Cyber Security (32561)
Director, Information & Cyber Security (32561)

GI Alliance • Southlake (TX)

On-site
USD 180,000 - 260,000
Security Officer - Overnight
Security Officer - Overnight

IHG Hotels & Resorts • San Antonio (TX)

On-site
USD 36,000 - 42,000
Paid time off
Medical/dental/vision insurance
401k
Manager, Multi Brand Strategy & Reporting
Manager, Multi Brand Strategy & Reporting

IHG Hotels & Resorts • Atlanta (GA)

Hybrid
USD 105,000 - 110,000
Paid time off
Medical/dental/vision insurance
401K
+1
AI Security and Data Protection Governance and Controls VP
AI Security and Data Protection Governance and Controls VP

State Street • Clifton (NJ)

Hybrid
USD 120,000 - 203,000
401K with company match
Medical, dental, vision insurance
Paid time off