Director, Information Security

Centric Brands

Greensboro (NC)

Hybrid

USD 150,000 - 230,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, vision benefits
401(k) matching
Summer Fridays
Generous PTO
Merchandise discounts
Career development opportunities

Job summary

Centric Brands is seeking a Director of Information Security to lead our global cybersecurity program, incl. governance, incident response, and compliance.

Based in Greensboro, NC, this role combines strategic leadership with hands-on collaboration across IT and business units in a hybrid in-office/remote setup. The ideal candidate has a bachelor’s in a related field, 10+ years in information security with 5+ in leadership, and strong communication to executive leadership.

Qualifications

  • Bachelor’s degree in Information Systems, Computer Science, or related field required.
  • CISSP or CISM certification strongly preferred.
  • Minimum of 10 years’ experience in information security, including 5+ years leading security teams or programs.
  • Experience presenting security posture, risk, and program metrics to executive leadership.
  • Experience leading global security programs; retail, consumer goods, or manufacturing experience a plus.
  • Excellent communication skills - both written and verbal.
  • Ability to travel as needed; once per quarter.

Responsibilities

  • Provide strategic leadership for a company-wide information security program and governance.
  • Mentor and coach the Information Security Office team and partners across IT units.
  • Lead security policies, compliance, audits, and regulatory program management.
  • Develop security awareness, training programs, and phishing/identity protection initiatives.
  • Oversee incident response planning, tabletop exercises, and breach notification actions.
  • Establish security risk management, third-party risk, and vendor assessments.
  • Oversee security operations, including MDR/EDR, vulnerability management, and cloud security posture.

Skills

Security leadership
Executive reporting
Security certifications
Cloud security
Incident response
Communication skills

Education

Bachelor’s degree in Information Systems, Computer Science, or related field

Tools

Fortinet/FortiGate
Crowdstrike MDR/EDR
BitLocker
MS Defender
Azure Security

Job description

About Us

Centric Brands is a leading lifestyle brand collective that designs, sources, markets and sells high quality products in multiple segments, including women’s, men’s and kid’s apparel, accessories, entertainment and beauty. Centric Brands is focused on our customers and our brands that will drive the company’s future growth. We are defined by innovation as we seize new opportunities and thrive in an environment informed by creativity and thinking that is both analytical and outside the box. Centric Brands reflects a team built on respect, for others and for the hard work it takes to achieve our goals and build our bright future together.

Position Overview

The Director of Information Security is responsible for developing and executing Centric Brands' enterprise cybersecurity strategy, protecting company information assets, and reducing cyber risk across the global business. This role leads security operations, governance, compliance, incident response, and emerging technology security programs while partnering with business and technology leaders to enable secure growth. The position is based in Greensboro, NC and follows a hybrid work schedule of Monday‑Thursday in office with Friday remote work.

Responsibilities
Strategy, Governance, and Executive Leadership
  • Provide strategic leadership for, and develop, implement, and operate, a company-wide information security program.
  • Advise senior leadership on security program direction and resource investment.
  • Develop and manage the information security budget, aligning investments with risk priorities.
  • Report regularly to executive leadership on security posture, risk reduction, incident readiness, and program maturity against defined KPIs.
  • Manage and facilitate global information security governance processes.
  • Establish annual and long‑range security and compliance goals, define security strategies, metrics, reporting mechanisms and program services; and create maturity models and a roadmap for continual program improvements.
  • Stay abreast of information security issues and regulatory changes affecting consumer goods, retail and trade at the state, national and global levels, participate in policy and practice discussions, and communicate to leadership on a regular basis about those topics.
  • Engage in professional development to maintain continual growth in professional skills and knowledge essential to the position.
Team Leadership
  • Mentor/Coach the Information Security Office team members and implement professional development plans for team members. Communicate clear goals and objectives.
  • Partner with infrastructure, network, cloud, application, and end‑user computing teams to implement and maintain enterprise security standards and controls.
Policy, Compliance, and Audit
  • Lead the development and implementation of effective and reasonable policies and practices to secure protected and sensitive data and ensure information security and compliance with relevant legislation and legal interpretation.
  • Coordinate and track all information technology and security related audits including scope of audits, timelines, auditing agencies and outcomes. Work with auditors as appropriate to keep audit focus in scope, maintain excellent relationships with audit entities and provide a consistent perspective that continually puts the company in its best light.
  • Provide guidance, evaluation and advocacy on audit responses.
  • Work with leadership and relevant responsible compliance department leadership to build cohesive security and compliance programs for the company to effectively address global statutory and regulatory requirements.
  • Develop a strategy for dealing with increasing number of audits, compliance checks and external assessment processes for internal/external auditors, PCI, CCPA, and GDPR.
  • Support Legal Discovery requests when required.
Security Awareness and Training
  • Work closely with IT leaders, technical experts and various leaders on a wide variety of security issues that require an in‑depth understanding of the IT environment in their units.
  • Create education and awareness programs and advise operating units at all levels on security issues, best practices, and vulnerabilities.
  • Pursue employee‑focused security initiatives addressing phishing, social engineering, and identity protection.
Incident Response and Resilience
  • Keep abreast of security incidents and act as primary control point during significant information security incidents. Convene a Security Incident Response Team (SIRT) as needed or requested in addressing and investigating security incidents that arise.
  • Own and maintain the company’s incident response plan, including playbooks and regular tabletop exercises with business stakeholders.
  • Convene Ad hoc Security Committee as appropriate and provide leadership for breach response and notification actions for the company.
  • Partner with IT and business leaders to develop and test business continuity, disaster recovery, and cyber resilience plans.
Risk Management and Third‑Party Risk
  • Establish and oversee a third‑party risk management program, including security assessments of vendors, licensing partners, and key service providers.
  • Provide leadership, direction and guidance in assessing and evaluating information security risks and monitor compliance with security standards and appropriate policies.
  • Support cyber insurance renewals, security questionnaires, and claims coordination.
Security Operations and Engineering
  • Develop, implement and administer technical security standards, as well as a suite of security services and tools to address and mitigate security risk.
  • Establish and oversee a vulnerability management program, including scanning, penetration testing, and remediation tracking.
  • Oversee day‑to‑day security operations, including MDR/SOC partner management, security monitoring and detection, threat intelligence, and endpoint and email security.
  • Set direction for cloud security posture and zero‑trust architecture in partnership with infrastructure and application teams.
  • Establish governance for identity and access management, including privileged access controls and periodic access reviews.
  • Examine impacts of new technologies on the company’s overall information security. Establish processes to review implementation of new technologies to ensure security compliance.
  • Establish governance, risk management, and security standards for artificial intelligence (AI), generative AI, machine learning, and automation technologies. Partner with business and technology leaders to enable responsible and secure adoption of AI solutions across the enterprise.
Our Best Fit Candidate Would Have
Skills And Requirements
  • Bachelor’s degree in Information Systems, Computer Science, or related field required.
  • CISSP, CISM, or equivalent security certification strongly preferred.
  • Minimum of 10 years’ experience in information security, including 5+ years leading security teams or programs.
  • Experience presenting security posture, risk, and program metrics to executive leadership.
  • Experience leading global security programs; retail, consumer goods, or manufacturing industry experience a plus.
  • Excellent communication skills - both written and verbal.
  • Exceptional, hands‑on leader with a style that is engaging, innovative, and collaborative.
  • Ability to be flexible, work under pressure and tight deadlines.
  • Ability to travel as needed; once per quarter.
  • Ability and availability to work occasional nights and weekends.
  • Experience with Fortinet/FortiGate/Forticlient, Crowdstrike MDR/EDR, BitLocker, File Vault, MS Defender, and Azure Security services is a plus.

In return, we provide an industry‑competitive salary, along with a comprehensive benefits plan (medical, dental, vision) that includes a matching 401(k), Summer Fridays, generous PTO, merchandise discounts, excellent career development opportunities, and a work environment that reflects our industry leadership. Our social impact program, Centric Cares, focuses on volunteerism to make a difference in communities we live and work in and our D&I committee is shaping the future of diversity, equity and inclusion at Centric Brands through workshops, resources and inspiring conversation.

Centric Brands is an Equal Opportunity Employer

Please note that Centric Brands will only reach out to interview, make an offer of employment or conduct onboarding activities for candidates who have applied through our careers site. When interviewing for a position, the candidate experience will include live interaction, such as a video conference or telephone call, with a Recruiter and/or company employee(s). We will never ask for any money or payments from applicants at any point in the recruitment process. Be aware of suspicious recruitment activity. If you think you are a victim of an employment scam, you may contact your local law enforcement agency and/or visit the Federal Trade Commission website here: https://consumer.ftc.gov/articles/job-scams.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Information Security
Director, Information Security

Centric Brands Inc. • Greensboro (NC)

Hybrid
USD 180,000 - 240,000
Medical and dental benefits
401(k) with company match
PTO and Summer Fridays
+1
Vice President, Information Systems & Chief Information Security Officer (CISO)
Vice President, Information Systems & Chief Information Security Officer (CISO)

Centric Software • Campbell (CA)

On-site
USD 250,000 - 420,000
Associate, Global Compliance
Associate, Global Compliance

Centric Brands Inc. • Greensboro (NC)

Hybrid
USD 65,000 - 95,000
401(k) match
Medical, dental, vision
Summer Fridays
+3
Senior Manager, Finance
Senior Manager, Finance

Centric Brands Inc. • City of Niagara Falls (NY)

On-site
USD 131,000 - 150,000
Medical, dental, vision benefits
401(k) with company match
Summer Fridays
+3
On-site Fall 2026 Internship - IT, Business Analyst (Greensboro, NC)
On-site Fall 2026 Internship - IT, Business Analyst (Greensboro, NC)

Centric Brands • Greensboro (NC)

On-site
Manager, Product Development- Gap Licensing
Manager, Product Development- Gap Licensing

Centric Brands Inc. • City of Niagara Falls (NY)

On-site
USD 90,000 - 100,000
401(k) matching
Summer Fridays
Generous PTO
+3
Manager, Finance
Manager, Finance

Centric Brands Inc. • City of Niagara Falls (NY)

On-site
USD 95,000 - 125,000
Medical, dental, vision
401(k) matching
Summer Fridays
+3
Director, Planning
Director, Planning

Centric Brands Inc. • New York (NY)

On-site
USD 145,000 - 165,000
Medical, dental, vision benefits
401(k) matching
Generous PTO
+1
Director, Planning
Director, Planning

Centric Brands Inc. • City of Niagara Falls (NY)

On-site
USD 145,000 - 165,000
Comprehensive benefits (medical, dental, vision)
Matching 401(k)
Generous PTO
+3
Manager, Finance
Manager, Finance

Centric Brands Inc. • New York (NY)

On-site
USD 95,000 - 125,000