Senior Director, Secure MA&D

Jobtailor

Missouri

On-site

USD 180,000 - 280,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Jobtailor seeks a senior cybersecurity professional to own and evolve the Secure M&A strategy, overseeing due diligence, integration planning, and risk governance across acquisitions, divestitures, and joint ventures.

You will lead a global team, set security standards, and coordinate with executives to translate technical findings into business impact, timelines, and budget considerations.

Qualifications

  • 15+ years of progressive experience in cybersecurity, technology risk, or security consulting.

Responsibilities

  • Lead cybersecurity due diligence and integration across multiple completed transactions.

Skills

Cybersecurity
Technology Risk
Identity and Access Management
Cloud Security
Network Security
Data Protection
Application Security
Security Operations
Incident Response
Vulnerability Management

Education

Bachelor's degree
Advanced degree preferred

Tools

NIST CSF
ISO 27001
CIS Controls
HITRUST
GRC

Job description

  • Own and evolve the enterprise Secure MA&D strategy, operating model, and capability roadmap for acquisitions, divestitures, carve-outs, joint ventures, and minority investments
  • Establish governance, decision rights, risk thresholds, and escalation criteria for deal-impacting cyber findings
  • Set standards for diligence playbooks, cost models, integration blueprints, Day 1 control baselines, and executive reporting
  • Own the annual plan, budget, tooling, third-party bench, and program effectiveness metrics
  • Lead, coach, and develop a global team of Secure MA&D principals and analysts
  • Direct third-party diligence and integration partners, including selection, scoping, commercial terms, quality assurance, and performance management
  • Direct pre-close cybersecurity due diligence and calibrate diligence to deal type, size, and thesis
  • Quantify and defend remediation, integration, tooling, licensing, labor, and run-rate cost estimates
  • Ensure cyber findings are reflected in deal documents and protections
  • Define security requirements and exit criteria for TSAs and reverse TSAs; direct divestiture separation planning
  • Direct Day 1 readiness, including minimum viable controls, identity and network interconnection, endpoint and email protections, logging and monitoring, and incident response coverage
  • Own the handoff from diligence to delivery with tracked risks, owners, and funded remediation plans
  • Lead security response for active or historical compromises at targets
  • Establish risk acceptance and exception frameworks for inherited risks
  • Ensure regulatory exposure is addressed across diligence and integration
  • Aggregate inherited cyber risk into the enterprise risk register and report trends to executive risk committees
  • Oversee third-party and fourth-party risk from acquired vendor ecosystems
  • Align practices to NIST CSF, NIST SP 800-53, ISO 27001, CIS Controls, and HITRUST
  • Serve as the security voice in deal committees, investment committees, and Board-level materials
  • Translate technical findings into valuation, timing, compliance, and operational impact
  • Brief security owners, business leaders, and acquired-company executives
  • Lead organizational change, stakeholder engagement, training, communication, talent assessment, and tooling migration during integration
  • Institutionalize lessons learned after each close
Requirements
  • Bachelor's degree required; advanced degree in business or a technical discipline preferred
  • 15+ years of progressive experience in cybersecurity, technology risk, or security consulting
  • 5+ years leading teams and enterprise-scale programs
  • Experience leading cybersecurity due diligence and integration across multiple completed transactions
  • At least one carve-out, divestiture, or separation experience
  • Working fluency in deal mechanics and terminology, including letters of intent, data-room and clean-team protocols, SPA and TSA constructs, purchase price adjustments, escrow and indemnity, and representations and warranties insurance
  • Financial acumen to build, defend, and negotiate multi-year remediation and run-rate cost estimates
  • Breadth and depth across identity and access management, cloud and network security, endpoint, data protection, application security, security operations and incident response, vulnerability management, GRC, and third-party risk
  • Experience in a highly regulated industry; healthcare, pharmaceutical distribution, life sciences, or medical technology strongly preferred
  • Working knowledge of HIPAA, GxP, DSCSA, SOX, PCI DSS, and GDPR
  • Familiarity with NIST CSF, NIST SP 800-53 and 800-171, ISO 27001, CIS Controls, and HITRUST
  • Proven vendor management and budget ownership
  • Ability to influence and align executive stakeholders without direct authority across global business units and geographies
  • Exceptional written and verbal communication skills, including Board and deal-committee materials
  • Proven discretion in handling material non-public information and simultaneous confidential transactions
  • Willingness to travel and support compressed transaction timelines, including nonstandard hours and multiple time zones
  • Relevant certifications such as CISSP, CISM, CRISC, CISA, CCSP, or PMP preferred
Core Competencies

Demonstrates expertise in cybersecurity due diligence, integration, and risk management, with a strong focus on leading teams and managing enterprise-scale programs. Proficient in aligning security practices with regulatory standards and effectively communicating with executive stakeholders.

Highest-signal resume keywords
  • Cybersecurity Due Diligence
  • Enterprise Risk Management
  • Team Leadership
  • Regulatory Compliance
  • Vendor Management
Hard Skills
  • Cybersecurity
  • Technology Risk
  • Identity and Access Management
  • Cloud Security
  • Network Security
  • Data Protection
  • Application Security
  • Security Operations
  • Incident Response
  • Vulnerability Management
Soft Skills
  • Exceptional Communication Skills
  • Influencing Stakeholders
  • Discretion in Handling Confidential Information
Certifications & Qualifications
  • CISSP
  • CISM
  • CRISC
  • CISA
  • CCSP
  • PMP
Industry Keywords
  • Healthcare
  • Pharmaceutical Distribution
  • Life Sciences
  • Medical Technology
  • HIPAA
  • GxP
  • DSCSA
  • SOX
  • PCI DSS
  • GDPR
Tools & Technologies
  • NIST CSF
  • ISO 27001
  • CIS Controls
  • HITRUST
  • GRC
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP & Chief Information Security Officer – Global Industrial
VP & Chief Information Security Officer – Global Industrial

Jobtailor • Birmingham (AL)

On-site
USD 180,000 - 350,000
Cybersecurity Manager
Cybersecurity Manager

Jobtailor • Illinois

On-site
USD 140,000 - 200,000
Cybersecurity Manager I
Cybersecurity Manager I

Jobtailor • Colorado

On-site
USD 150,000 - 210,000
Manager – Cyber Security
Manager – Cyber Security

Jobtailor • Los Angeles (CA)

On-site
USD 140,000 - 190,000
Senior Manager – Product Cybersecurity
Senior Manager – Product Cybersecurity

Jobtailor • Chicago (IL)

On-site
USD 150,000 - 230,000
Senior Cybersecurity Consultant, Financial Services
Senior Cybersecurity Consultant, Financial Services

Jobtailor • California (MO)

On-site
USD 120,000 - 180,000
Director of Cyber Security
Director of Cyber Security

Jobtailor • Concord (MA)

Hybrid
USD 180,000 - 260,000
Senior Director, Secure MA&D
Senior Director, Secure MA&D

myhrabc • Conshohocken

On-site
USD 180,000 - 250,000
Senior Manager, GRC
Senior Manager, GRC

Jobtailor • California (MO)

On-site
USD 130,000 - 165,000
Vulnerability Management Technical Lead
Vulnerability Management Technical Lead

Jobtailor • San Francisco (CA)

On-site
USD 180,000 - 230,000